Bug 32768 - Sync different group types
Sync different group types
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: S4 Connector
UCS 3.1
Other Linux
: P5 enhancement (vote)
: UCS 3.2
Assigned To: Stefan Gohmann
Arvid Requate
: interim-3
Depends on: 32852
Blocks: 41417
  Show dependency treegraph
 
Reported: 2013-10-01 08:33 CEST by Stefan Gohmann
Modified: 2016-06-02 11:58 CEST (History)
0 users

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments
Differences update vs installation (8.54 KB, text/plain)
2013-10-24 19:45 CEST, Arvid Requate
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2013-10-01 08:33:57 CEST
The group synchronization should be adjusted to the new types.

+++ This bug was initially created as a clone of Bug #32767 +++

We should be able to create and modify the different group types:
 - security groups
 - distribution groups
http://technet.microsoft.com/en-us/library/cc781446%28v=ws.10%29.aspx

We should also be able to modify the group scope:
 - universal groups
 - global groups
 - domain local groups

And the special ones
 - local groups
 - builtin groups
 - pseudo groups

http://technet.microsoft.com/en-us/library/cc755692%28v=ws.10%29.aspx
http://technet.microsoft.com/en-us/library/cc778060%28v=ws.10%29.aspx

http://www.faq-o-matic.net/2011/03/07/windows-gruppen-richtig-nutzen/
Comment 1 Stefan Gohmann univentionstaff 2013-10-11 22:14:44 CEST
The following groups are currently not synced:

 - Guest
 - Group Policy Creator Owners
 - Administrator
 - Users
 - Backup Operators

After re-initialize the connector (removing s4internal.sqlite), the groups are synchronized.
Comment 2 Stefan Gohmann univentionstaff 2013-10-12 17:01:59 CEST
(In reply to Stefan Gohmann from comment #1)
> The following groups are currently not synced:
> 
>  - Guest
>  - Group Policy Creator Owners
>  - Administrator
>  - Users
>  - Backup Operators
> 
> After re-initialize the connector (removing s4internal.sqlite), the groups
> are synchronized.

This seems to be a more generic connector bug: Bug #32852
Comment 3 Stefan Gohmann univentionstaff 2013-10-14 21:28:47 CEST
The grouptypes are now synchronized between OpenLDAP and Samba 4. By default the group type is synced for new installations only (UCR variable: connector/s4/mapping/group/synclocal). All other systems must be migrated manually.

We will provide an SDB article how to migrate manually: Bug #32863

Test case: 52_s4connector/010_sync_group_type

Changelog: r45062
Comment 4 Arvid Requate univentionstaff 2013-10-24 19:45:53 CEST
Created attachment 5533 [details]
Differences update vs installation

Just for documentation, these are the group object changes between an updated and a freshly installed UCS 3.2-0.
Comment 5 Arvid Requate univentionstaff 2013-10-24 19:46:34 CEST
Q: As sent via email, the S4-Connector does not preserve the case of the member DNs. Maybe this is also a generic bug? Leaving this bug open for discussion.

Verified:
* Code Ok
* No reject during installation/join (and update)
* Groups found in UDM
* Testcase works
* Changelog Ok
Comment 6 Stefan Gohmann univentionstaff 2013-10-24 20:00:16 CEST
(In reply to Arvid Requate from comment #5)
> Q: As sent via email, the S4-Connector does not preserve the case of the
> member DNs. Maybe this is also a generic bug? Leaving this bug open for
> discussion.

No, that is not a new bug. The connector does this for group members only.
Comment 7 Arvid Requate univentionstaff 2013-10-25 07:55:13 CEST
Ok.
Comment 8 Stefan Gohmann univentionstaff 2013-11-19 06:43:54 CET
UCS 3.2 has been released:
 http://docs.univention.de/release-notes-3.2-en.html
 http://docs.univention.de/release-notes-3.2-de.html

If this error occurs again, please use "Clone This Bug".