Re: sssd - ldap host attribute ignored

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



On 02/23/2015 03:59 AM, Ulrich Hiller wrote:

/etc/sssd/sssd.conf:
[domain/default]
access_provider = ldap
ldap_access_filter = memberOf=ou=YYYY,o=XXXX
ldap_access_order = host

Because ldap_access_order doesn't include "filter", ldap_access_filter will not be used. You can remove that.

Aside from that, it would be helpful to see the entry for one of the users who can log in and should not be able to.

Make sure you flush the cache before testing.

/etc/ldap.conf:

I don't think that file is relevant.

_______________________________________________
CentOS mailing list
CentOS@xxxxxxxxxx
http://lists.centos.org/mailman/listinfo/centos




[Index of Archives]     [CentOS]     [CentOS Announce]     [CentOS Development]     [CentOS ARM Devel]     [CentOS Docs]     [CentOS Virtualization]     [Carrier Grade Linux]     [Linux Media]     [Asterisk]     [DCCP]     [Netdev]     [Xorg]     [Linux USB]
  Powered by Linux