You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Setting up a minimal config for an application domain inheriting from a posix domain as described in the manpage of sssd.conf leads to the appdomain not being read appropriately:
We've been discussing this issue on #sssd IRC channel and basically what happens is that from sssctl the confdb does seem to the support application domains.
While it looks like a simple "confdb_expand_app_domains()" call in sss_tool_domains_init() should solve the problem ... it doesn't seem to be the right path to take as I'm seeing some errors on ldb_wait() when calling confdb_merge_parent_domain().
@jhrozek, do you think that modifying the confdb_get_domains() to also iterate over the app domains would be a valid approach? Or do you know what I may be doing wrong that causes an error with the first approach?
Cloned from Pagure issue: https://pagure.io/SSSD/sssd/issue/3658
Setting up a minimal config for an application domain inheriting from a posix domain as described in the manpage of
sssd.conf
leads to the appdomain not being read appropriately:sssd.conf (some comments removed)
conf.ldb
Output
Setting
debug_level=9
lead to the attached logfile.Comments
Comment from fidencio at 2018-03-06 22:15:24
Metadata Update from @fidencio:
Comment from fidencio at 2018-03-06 23:20:26
@lukasjuhrich, thanks for the report.
We've been discussing this issue on #sssd IRC channel and basically what happens is that from sssctl the confdb does seem to the support application domains.
While it looks like a simple "confdb_expand_app_domains()" call in sss_tool_domains_init() should solve the problem ... it doesn't seem to be the right path to take as I'm seeing some errors on ldb_wait() when calling confdb_merge_parent_domain().
@jhrozek, do you think that modifying the confdb_get_domains() to also iterate over the app domains would be a valid approach? Or do you know what I may be doing wrong that causes an error with the first approach?
Comment from fidencio at 2018-03-14 23:25:57
PR: #537
Comment from fidencio at 2018-03-14 23:25:59
Metadata Update from @fidencio:
Comment from jhrozek at 2018-03-15 11:17:24
Metadata Update from @jhrozek:
Comment from jhrozek at 2018-03-15 12:20:23
Metadata Update from @jhrozek:
Comment from jhrozek at 2018-03-26 21:01:59
Fixed as a part of:
14b485b
885da2c
a73d70f
f405a4a
e5c74ab
Comment from jhrozek at 2018-03-26 21:02:17
Metadata Update from @jhrozek:
The text was updated successfully, but these errors were encountered: