Bug 56389 - Default connector/s4/mapping/group/syncmode=write on UCS@school primary disconnects UCS from Samba
Default connector/s4/mapping/group/syncmode=write on UCS@school primary disco...
Status: NEW
Product: UCS@school
Classification: Unclassified
Component: Samba 4
UCS@school 5.0
Other Linux
: P5 enhancement (vote)
: ---
Assigned To: Samba maintainers
:
Depends on: 33883
Blocks:
  Show dependency treegraph
 
Reported: 2023-08-01 19:50 CEST by Arvid Requate
Modified: 2023-08-01 19:50 CEST (History)
2 users (show)

See Also:
What kind of report is it?: Development Internal
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2023072021000055
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2023-08-01 19:50:48 CEST
UCS@school installations by default use connector/s4/mapping/group/syncmode=write on all systems. This disconnects UCS from Samba group changes. I.e. if a new group is created by default in new Samba versions to keep up with MS Active Directory, then changes to AD groups will not automatically be synchronized to UDM.

E.g. for Ticket#2023072021000055 we wanted to follow

https://help.univention.com/t/activation-of-the-synchronisation-of-the-grouptype-attribute-with-the-s4-connector/6451

but due to this UCR setting the "resync_object_from_s4.py" simply did nothing and I had no other choice but to temporarily hack the S4-Connector code to ignore that setting for specific group DNs.

I have no practical solution to offer, but I'd like to leave this here as a reminder and explanation.


+++ This bug was initially created as a clone of Bug #33883 +++