#1591 [RFE] Allow locally defined groups to include groups from different domains
Closed: Invalid None Opened 11 years ago by dpal.

Use case is well defined in https://lists.samba.org/archive/samba-technical/2012-October/088039.html mentioned in the ticket #1588.

One should be able to say that Samba share is available to all users from a group X where group X includes a group Y from central LDAP/AD/IPA repository and local group defined on the system.

This RFE is to allow defining such group X.
This ticket is related to ticket #1588.


I think that the prerequisity is ticket #1020.

design: =>
design_review: => 0
fedora_test_page: =>

Fields changed

type: defect => enhancement

Fields changed

milestone: NEEDS_TRIAGE => SSSD 1.10 beta
rhbz: => todo

Fields changed

selected: => Not need

Moving tickets that are not a priority for SSSD 1.10 into the next release.

milestone: SSSD 1.10 beta => SSSD 1.11 beta

Fields changed

mark: => 1

This was requested by Stef Walter as part of Cockpit integration effort. Marking as Critical. See also realmd bugzilla https://bugzilla.redhat.com/show_bug.cgi?id=1146822

changelog: =>
priority: major => critical
review: => 0

Fields changed

milestone: SSSD 1.13 beta => SSSD 1.13 alpha

Picking, I was looking at the nsswitch code recently and was talking to Carlos O'Donnel about details of Simo's propsal at https://sourceware.org/glibc/wiki/Proposals/GroupMerging

Fields changed

owner: somebody => jhrozek

The work will happen in libc, but after we release sssd alpha

milestone: SSSD 1.13 alpha => SSSD 1.13 beta
sensitive: => 0

Fields changed

cc: => tibbs

Stephen has more time to work on this ticket than I do, reassigning.

owner: jhrozek => sgallagh

Also out of scope for 1.13

milestone: SSSD 1.13.1 => SSSD 1.14 beta

Patches to glibc have been submitted upstream: https://sourceware.org/ml/libc-alpha/2015-12/msg00404.html

It is expected that this will be available starting with glibc 2.23 (Fedora 24).

status: new => assigned

The patches are available in Fedora. Also, the work is not related to SSSD, so I'm closing this ticket.

(There is also a requirement to merge different groups on different hosts, but that's tracked in the freeipa bug tracker)

resolution: => wontfix
status: assigned => closed

Metadata Update from @dpal:
- Issue assigned to sgallagh
- Issue set to the milestone: SSSD 1.14 beta

7 years ago

SSSD is moving from Pagure to Github. This means that new issues and pull requests
will be accepted only in SSSD's github repository.

This issue has been cloned to Github and is available here:
- https://github.com/SSSD/sssd/issues/2633

If you want to receive further updates on the issue, please navigate to the github issue
and click on subscribe button.

Thank you for understanding. We apologize for all inconvenience.

Login to comment on this ticket.

Metadata