SSSD 1.16 and issue with private group

Solution In Progress - Updated -

Issue

  • We're running into an issue with the auto private groups feature which was added in SSSD. As the auto private groups feature
    was specified in the RFE https://bugzilla.redhat.com/1327705, SSSD was to automatically create the group on the client only if the user object's uidNumber and gidNumber are the same in AD. What we are seeing, however, is that the private group is being created regardless of the gidNumber. For example:
$ aduser --query --user myuser | egrep '^uid|uidNumber|gidNumber|gecos' 
uid: myuser 
uidNumber: 153313906
gidNumber: 183244178
gecos: myuser 

With older SSSD:

$ id myuser 
uid=153313906(myuser) gid=183244178(biggroup) groups=183244178(biggroup) 

With SSSD 1.16 and auto private groups:

$ id myuser 
uid=153313906(myuser) gid=153313906(myuser) groups=153313906(myuser),183244178(biggroup)

Environment

  • Red Hat Enterprise Linux 7.5

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.

Current Customers and Partners

Log in for full access

Log In
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.