Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | LDAP: Handle very large Active Directory groups | Stephen Gallagher | 2012-05-10 | 1 | -17/+37 |
| | | | | | | | | | | | | | Active Directory 2008R2 allows only 1500 group members to be retrieved in a single lookup. However, when we hit such a situation, we can take advantage of the ASQ lookups, which are not similarly limited. With this patch, we will add any members found by ASQ that were not found by the initial lookup so we will end with a complete group listing. https://fedorahosted.org/sssd/ticket/783 | ||||
* | LDAP: Add attr_count return value to build_attrs_from_map() | Stephen Gallagher | 2012-05-10 | 1 | -6/+8 |
| | | | | | | | This is necessary because in several places in the code, we are appending to the attrs returned from this value, and if we relied on the map size macro, we would be appending after the NULL terminator if one or more attributes were defined as NULL. | ||||
* | LDAP: Add helper function to map IDs | Stephen Gallagher | 2012-05-03 | 1 | -46/+2 |
| | | | | | This function will also auto-create a new ID map if the domain has not been seen previously. | ||||
* | LDAP: Do not remove uidNumber and gidNumber attributes when saving id-mapped ↵ | Stephen Gallagher | 2012-05-03 | 1 | -0/+5 |
| | | | | entries | ||||
* | LDAP: Add helper routine to convert LDAP blob to SID string | Stephen Gallagher | 2012-05-03 | 1 | -20/+4 |
| | |||||
* | LDAP: Allow looking up ID-mapped groups by name | Stephen Gallagher | 2012-05-03 | 1 | -18/+105 |
| | |||||
* | LDAP: check return value of sysdb_attrs_get_el | Jakub Hrozek | 2012-05-02 | 1 | -0/+7 |
| | |||||
* | Fixed minor memory leak in ldap provider | Jan Zeleny | 2012-04-18 | 1 | -0/+1 |
| | |||||
* | Fixed memory context in sdap_fill_memberships() | Jan Zeleny | 2012-04-18 | 1 | -1/+1 |
| | |||||
* | Removed unused block of code is sdap_fill_memberships() | Jan Zeleny | 2012-04-18 | 1 | -57/+29 |
| | |||||
* | Removed a block of dead code in sdap_async_groups.c | Jan Zeleny | 2012-04-18 | 1 | -20/+1 |
| | |||||
* | Modifications to simplify list_missing_attrs | Jan Zeleny | 2012-02-24 | 1 | -1/+1 |
| | |||||
* | LDAP: Only use paging control on requests for multiple entries | Stephen Gallagher | 2012-02-24 | 1 | -5/+10 |
| | | | | | | | | | | The paging control can cause issues on servers that put limits on how many paging controls can be active at one time (on some servers, it is limited to one per connection). We need to reduce our usage so that we only activate the paging control when making a request that may return an arbitrary number of results. https://fedorahosted.org/sssd/ticket/1202 phase one | ||||
* | LDAP: Ignore group member users that do not have name attributes | Stephen Gallagher | 2012-02-17 | 1 | -2/+2 |
| | | | | | | | | Instead of failing the group lookup, just skip them. This was impacting some users of ActiveDirectory where not all users had the appropriate attributes. https://fedorahosted.org/sssd/ticket/1169 | ||||
* | Fix memory hierarchy when processing nested group memberships | Jakub Hrozek | 2012-02-14 | 1 | -2/+2 |
| | | | | https://fedorahosted.org/sssd/ticket/1186 | ||||
* | NSS: Add individual timeouts for entry types | Stephen Gallagher | 2012-02-04 | 1 | -7/+7 |
| | | | | https://fedorahosted.org/sssd/ticket/1016 | ||||
* | LDAP: Fix incorrect search timeouts | Stephen Gallagher | 2012-02-04 | 1 | -1/+1 |
| | |||||
* | LDAP: Do not fail if RootDSE check cannot determine search bases | Stephen Gallagher | 2012-02-04 | 1 | -0/+9 |
| | | | | https://fedorahosted.org/sssd/ticket/1152 | ||||
* | Logically dead code in sdap_nested_group_lookup_group | Pavel Březina | 2011-12-16 | 1 | -1/+1 |
| | | | | https://fedorahosted.org/sssd/ticket/1113 | ||||
* | Use the case sensitivity flag in the LDAP provider | Jakub Hrozek | 2011-12-16 | 1 | -2/+2 |
| | |||||
* | Refactor saving sdap entities | Jakub Hrozek | 2011-12-16 | 1 | -39/+10 |
| | | | | | There was too much code duplication between sdap_save_{user,group,netgroup}. This patch removes the most egregious ones. | ||||
* | Support search bases in RFC2307bis enumeration | Pavel Březina | 2011-12-14 | 1 | -10/+145 |
| | | | | https://fedorahosted.org/sssd/ticket/960 | ||||
* | Fix two small bugs in group dereferencing | Jakub Hrozek | 2011-11-29 | 1 | -2/+5 |
| | |||||
* | Cleanup: Remove unused parameters | Jakub Hrozek | 2011-11-22 | 1 | -12/+6 |
| | |||||
* | Use one transaction instead of two during RFC2307bis group processing | Jakub Hrozek | 2011-11-11 | 1 | -31/+55 |
| | | | | https://fedorahosted.org/sssd/ticket/1054 | ||||
* | LDAP: Remove redundant groups from the lookup list | Stephen Gallagher | 2011-11-08 | 1 | -23/+0 |
| | |||||
* | LDAP: Add support for multiple search bases for group enumeration | Stephen Gallagher | 2011-11-02 | 1 | -21/+95 |
| | |||||
* | LDAP: Support multiple group search bases (non-enumeration, RFC2307) | Stephen Gallagher | 2011-11-02 | 1 | -13/+62 |
| | |||||
* | SysDB commands that save lastUpdate allows this value to be passed in | Pavel Březina | 2011-10-13 | 1 | -12/+22 |
| | | | | https://fedorahosted.org/sssd/ticket/836 | ||||
* | Fix small bug where TALLOC_CTX could end up unfreed. | Pavel Zuna | 2011-10-06 | 1 | -3/+3 |
| | |||||
* | Store name aliases for users, groups | Jakub Hrozek | 2011-09-28 | 1 | -37/+92 |
| | | | | | | Also checks fake users for aliases when storing a real users so that getgrnam for a RFC2307 group that references a user by his secondary name followed by getpwnam for this user by his primary name works | ||||
* | Allow turning dereference off by setting the threshold to 0 | Jakub Hrozek | 2011-09-06 | 1 | -1/+1 |
| | |||||
* | Fix moving to next entry in deref code | Jakub Hrozek | 2011-08-29 | 1 | -1/+6 |
| | | | | https://fedorahosted.org/sssd/ticket/973 | ||||
* | Moved some functions in sdap_async_groups | Jan Zeleny | 2011-08-15 | 1 | -122/+112 |
| | |||||
* | Confusing part of code cleared out | Jan Zeleny | 2011-08-15 | 1 | -34/+32 |
| | |||||
* | sdap_async_accounts.c split | Jan Zeleny | 2011-08-15 | 1 | -0/+2810 |
The file has been split in three: sdap_async_users.c sdap_async_groups.c sdap_async_initgroups.c https://fedorahosted.org/sssd/ticket/864 |