diff options
author | Lukas Slebodnik <lslebodn@redhat.com> | 2014-11-07 13:34:50 +0100 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2014-11-10 10:50:26 +0100 |
commit | c6a7cf7be85539ea0460d9f07182b8b666efe412 (patch) | |
tree | 63e0b28a9a9164cfbb5b3155f72df2523f7d26be | |
parent | f070a93e7dd6b594d8652718e513a18ec389fc2c (diff) | |
download | sssd-c6a7cf7be85539ea0460d9f07182b8b666efe412.tar.gz sssd-c6a7cf7be85539ea0460d9f07182b8b666efe412.tar.xz sssd-c6a7cf7be85539ea0460d9f07182b8b666efe412.zip |
Revert "LDAP: Change defaults for ldap_user/group_objectsid"
This reverts commit 29e5b5d17d9700022958bf1f59bb861cdf68bb57.
OpenLDAP server cannot dereference unknown attributes. The attribute objectSID
isn't in any standard objectclass on OpenLDAP server. This is a reason why
objectSID cannot be set by default in rfc2307 map and rfc2307bis map.
It is the same problem as using non standard attribute "nsUniqueId"
in ticket https://fedorahosted.org/sssd/ticket/2383
Reviewed-by: Michal Židek <mzidek@redhat.com>
-rw-r--r-- | src/man/sssd-ldap.5.xml | 4 | ||||
-rw-r--r-- | src/providers/ldap/ldap_opts.h | 8 |
2 files changed, 6 insertions, 6 deletions
diff --git a/src/man/sssd-ldap.5.xml b/src/man/sssd-ldap.5.xml index c952e9539..ecbf2f54c 100644 --- a/src/man/sssd-ldap.5.xml +++ b/src/man/sssd-ldap.5.xml @@ -346,7 +346,7 @@ necessary for ActiveDirectory servers. </para> <para> - Default: ipaNTSecurityIdentifier for IPA, objectSID + Default: objectSid for ActiveDirectory, not set for other servers. </para> </listitem> @@ -851,7 +851,7 @@ necessary for ActiveDirectory servers. </para> <para> - Default: ipaNTSecurityIdentifier for IPA, objectSID + Default: objectSid for ActiveDirectory, not set for other servers. </para> </listitem> diff --git a/src/providers/ldap/ldap_opts.h b/src/providers/ldap/ldap_opts.h index 39654ac1e..82d46e75d 100644 --- a/src/providers/ldap/ldap_opts.h +++ b/src/providers/ldap/ldap_opts.h @@ -153,7 +153,7 @@ struct sdap_attr_map rfc2307_user_map[] = { { "ldap_user_principal", "krbPrincipalName", SYSDB_UPN, NULL }, { "ldap_user_fullname", "cn", SYSDB_FULLNAME, NULL }, { "ldap_user_member_of", NULL, SYSDB_MEMBEROF, NULL }, - { "ldap_user_objectsid", "objectSID", SYSDB_SID, NULL }, + { "ldap_user_objectsid", NULL, SYSDB_SID, NULL }, { "ldap_user_primary_group", NULL, SYSDB_PRIMARY_GROUP, NULL }, { "ldap_user_modify_timestamp", "modifyTimestamp", SYSDB_ORIG_MODSTAMP, NULL }, { "ldap_user_entry_usn", NULL, SYSDB_USN, NULL }, @@ -186,7 +186,7 @@ struct sdap_attr_map rfc2307_group_map[] = { { "ldap_group_pwd", "userPassword", SYSDB_PWD, NULL }, { "ldap_group_gid_number", "gidNumber", SYSDB_GIDNUM, NULL }, { "ldap_group_member", "memberuid", SYSDB_MEMBER, NULL }, - { "ldap_group_objectsid", "objectSID", SYSDB_SID, NULL }, + { "ldap_group_objectsid", NULL, SYSDB_SID, NULL }, { "ldap_group_modify_timestamp", "modifyTimestamp", SYSDB_ORIG_MODSTAMP, NULL }, { "ldap_group_entry_usn", NULL, SYSDB_USN, NULL }, { "ldap_group_type", NULL, SYSDB_GROUP_TYPE, NULL }, @@ -205,7 +205,7 @@ struct sdap_attr_map rfc2307bis_user_map[] = { { "ldap_user_principal", "krbPrincipalName", SYSDB_UPN, NULL }, { "ldap_user_fullname", "cn", SYSDB_FULLNAME, NULL }, { "ldap_user_member_of", "memberOf", SYSDB_MEMBEROF, NULL }, - { "ldap_user_objectsid", "objectSID", SYSDB_SID, NULL }, + { "ldap_user_objectsid", NULL, SYSDB_SID, NULL }, { "ldap_user_primary_group", NULL, SYSDB_PRIMARY_GROUP, NULL }, { "ldap_user_modify_timestamp", "modifyTimestamp", SYSDB_ORIG_MODSTAMP, NULL }, { "ldap_user_entry_usn", NULL, SYSDB_USN, NULL }, @@ -238,7 +238,7 @@ struct sdap_attr_map rfc2307bis_group_map[] = { { "ldap_group_pwd", "userPassword", SYSDB_PWD, NULL }, { "ldap_group_gid_number", "gidNumber", SYSDB_GIDNUM, NULL }, { "ldap_group_member", "member", SYSDB_MEMBER, NULL }, - { "ldap_group_objectsid", "objectSID", SYSDB_SID, NULL }, + { "ldap_group_objectsid", NULL, SYSDB_SID, NULL }, { "ldap_group_modify_timestamp", "modifyTimestamp", SYSDB_ORIG_MODSTAMP, NULL }, { "ldap_group_entry_usn", NULL, SYSDB_USN, NULL }, { "ldap_group_type", NULL, SYSDB_GROUP_TYPE, NULL }, |