Answer the question
In order to leave comments, you need to log in
How to make debian see all groups of a user in ldap?
There is one old, old server on debian, the only task of which is to give some resources to users that are stored in ldap on another server. It has been working for 100 years already, and everything seems to be normal, but periodically it gives a thrashing where it should give good.
Began to understand - it turns out he sees only the default group of the user!
That is something like this:
Для локального
id administrator
uid=1000(administrator) gid=1000(administrator) группы=1000(administrator),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev)
Для лдап
uid=15000(user)) gid=10000(domainadmins) группы=10000(domainadmins)
Answer the question
In order to leave comments, you need to log in
In general, my stupidity and inattention. Some time ago I migrated from openldap to freeipa. The authors of the latter directly say - if you want to directly climb requests into ldap, turn on the compatibility mode and look for a separate branch dc=compat,dc=domain,dc=loc It maintains compatibility with rfc.
Actually, I didn't check it, I just reconfigured debian to freeipa-client, that's it. But later I encountered the fact that openfire also does not see the user's belonging to groups. Having written to the mailing list, I received a kick in the direction of the documentation.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question