Univention Bugzilla – Bug 51771
make "uniqueMember" optional for primary group
Last modified: 2022-10-14 16:14:28 CEST
In POSIX environments, the primary group is only assigned as gidNumber to an user. In UCS, we store this group membership also as "uniqueMember". In larger enviroments the default primary group "Domain Admins" is getting very big and changes are slow, for example because OpenLDAP has to do complex index updates. We should check if we can introduce a configuration option to deactivate the maintenance of "uniqueMember" for primary groups in UDM. Some things are going to "break", examples: * sending Mails to an address assigned to the primary group * AD and S4 connector might fail * LDAP ACLs won't work if based on this group
There is already a UCR variable for that: directory/manager/user/primarygroup/update=false.