Bug 34325 - Document the minimal privileges of the synchronization user on the Windows AD server
Document the minimal privileges of the synchronization user on the Windows AD...
Status: RESOLVED WONTFIX
Product: UCS manual
Classification: Unclassified
Component: Services for Windows
unspecified
Other Linux
: P5 enhancement (vote)
: ---
Assigned To: Docu maintainers
Samba maintainers
http://docs.univention.de/handbuch-3....
:
Depends on: 30987
Blocks:
  Show dependency treegraph
 
Reported: 2014-03-12 14:34 CET by Stefan Gohmann
Modified: 2024-04-17 13:16 CEST (History)
5 users (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Gohmann univentionstaff 2014-03-12 14:34:02 CET
> The section has changed due to other changes in the manual. This is now in
> 9.5.2.1
> 
> German version:
> Der Replikationsbenutzer muss im Active Directory Mitglied der Gruppe
> <emphasis>Domänen-Admins</emphasis> sein. Synchronisiert der Connector nur
> lesend von Active Directory zu UCS, kann auch ein Standardbenutzerkonto
> angegeben werden.

That is not right. The password service needs more rights even in read mode.

I think we should carefully re-check the old documentation, see Bug #30987.
 
+++ This bug was initially created as a clone of Bug #30987 +++
Comment 1 Stefan Gohmann univentionstaff 2015-03-06 07:30:04 CET
Remove this issue from the errata list. It has not been requested again.
Comment 2 Ingo Steuwer univentionstaff 2015-03-06 13:27:00 CET
This is requested, not often but regurlarly; last one I noticed is 2014103021000207
Comment 3 Nico Gulden univentionstaff 2024-04-17 13:16:15 CEST
This bug hasn't seen any update for several years. I close it.

If you still see a need for it, you can reopen the bug. Please add an argumentation about why it's important to take care of it.