On Tue, 20 Jun 2023, Ronald Wimmer via FreeIPA-users wrote:
On 20.06.23 15:45, Rob Crittenden via FreeIPA-users wrote:
Ronald Wimmer via FreeIPA-users wrote:
I can and use IPA users on an AIX client. As well as groups. But somehow
group membership does not seem to be configured correctly...

# id y179768
uid=1246660005(y179768) gid=1246660005(y179768)

# lsgroup -R LDAP ipa-aix-g
ipa-aix-g id=1246690508 users= registry=LDAP

Anyone has a hint what could be misconfigured?

There isn't enough information. How is LDAP configured, what search bases?

What is ipa-aix-g? What membership do you expect?

How does the group relate to the user you id'd?

I'll try to clarify.

ipa-aix-g is the IPA group containing several members as y179768 for example.

/etc/security/ldap/ldap.cfg:
userbasedn:cn=users,cn=accounts,dc=linux,dc=mydomain,dc=at
groupbasedn:cn=groups,cn=accounts,dc=linux,dc=mydomain,dc=at

Which LDAP schema AIX configuration is expecting to use? RFC2307 or
RFC2307bis?

The primary LDAP tree in FreeIPA is using RFC2307bis (e.g.
member/memberof, not memberuid attributes).


--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to