diff options
author | Stephen Gallagher <sgallagh@redhat.com> | 2015-07-20 09:29:19 -0400 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2015-07-26 20:33:07 +0200 |
commit | 7c18b65dbdeb584a946c055f2db3814544b17232 (patch) | |
tree | 573c92f4ba51963f5c5d4acf3b56403e15392998 /src/tests/sysdb-tests.c | |
parent | eabc1732ef91548616a699b7e9f8d30e5e7b8dd3 (diff) | |
download | sssd-7c18b65dbdeb584a946c055f2db3814544b17232.tar.gz sssd-7c18b65dbdeb584a946c055f2db3814544b17232.tar.xz sssd-7c18b65dbdeb584a946c055f2db3814544b17232.zip |
AD: Handle cases where no GPOs apply
It is possible to have a machine where none of the GPOs associated with
it include access-control rules. Currently, this results in a
denial-by-system-error.
We need to treat this case as allowing the user (see the test cases in
https://fedorahosted.org/sssd/wiki/DesignDocs/ActiveDirectoryGPOIntegration
We also need to delete the result object from the cache to ensure that
offline operation will also grant access.
Resolves:
https://fedorahosted.org/sssd/ticket/2713
Reviewed-by: Lukáš Slebodník <lslebodn@redhat.com>
Diffstat (limited to 'src/tests/sysdb-tests.c')
0 files changed, 0 insertions, 0 deletions