HBAC rule does not work for AD trust users
Issue
-
In IPA-AD trust,
IPA POSIX groupis not shown inid adusercommand when adding group membership for AD users asAD user --> AD group --> IPA external group --> IPA POSIX group. -
However, in the same IPA-AD trust environment,
IPA POSIX groupis shown in theid adusercommand when adding AD user directly into IPA external group asAD user --> IPA external group --> IPA POSIX group. -
This affects the HBAC rule which should be applies to the AD groups and AD users in the first scenario.
Environment
- IPA-AD trust
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.