Bug 32864 - Special pseudo groups
Special pseudo groups
Status: CLOSED FIXED
Product: UCS manual
Classification: Unclassified
Component: Services for Windows
unspecified
Other Linux
: P5 normal (vote)
: UCS 3.2
Assigned To: Moritz Muehlenhoff
Stefan Gohmann
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-10-14 22:31 CEST by Stefan Gohmann
Modified: 2015-04-01 13:48 CEST (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2013-10-14 22:31:44 CEST
AD has some special SIDs (pseudo groups). We need a mapping to POSIX GID, so we create these pseudo groups as normal UCS groups and the S4 connector ignores these groups. I think we should mention these groups in the manual because these groups are not synchronized between S4 and OpenLDAP.

Currently we use these groups:
 - Authenticated Users
 - World Authority
 - Everyone
 - Null Authority
 - Nobody
 - Enterprise Domain Controllers

Depending on Bug #29000 we will create more of these groups.
Comment 1 Moritz Muehlenhoff univentionstaff 2013-10-23 14:22:59 CEST
Pseudo groups in general were already documented in Bug 32927. I've added the list of affected groups in revision 45514
Comment 2 Stefan Gohmann univentionstaff 2013-10-25 20:37:51 CEST
(In reply to Moritz Muehlenhoff from comment #1)
> Pseudo groups in general were already documented in Bug 32927. I've added
> the list of affected groups in revision 45514

Sorry, meanwhile we've added more of these groups: Bug #29000

"Pseudo-Gruppen sind im UCS-Verzeichnisdienst vorhanden, sind aber leer." They are not really empty but they normally don't need to be modified and they are not synced between OpenLDAP and S4.
Comment 3 Moritz Muehlenhoff univentionstaff 2013-11-08 08:18:25 CET
(In reply to Stefan Gohmann from comment #2)
> (In reply to Moritz Muehlenhoff from comment #1)
> > Pseudo groups in general were already documented in Bug 32927. I've added
> > the list of affected groups in revision 45514
> 
> Sorry, meanwhile we've added more of these groups: Bug #29000
>
> "Pseudo-Gruppen sind im UCS-Verzeichnisdienst vorhanden, sind aber leer."
> They are not really empty but they normally don't need to be modified and
> they are not synced between OpenLDAP and S4.

This has been rephrased and the new groups added in revision 45900
Comment 4 Stefan Gohmann univentionstaff 2013-11-13 17:31:36 CET
OK