Bug 57246 - Legacy user object - join-backup and join-slave
Summary: Legacy user object - join-backup and join-slave
Status: NEW
Alias: None
Product: UCS
Classification: Unclassified
Component: Join (univention-join)
Version: UCS 5.0
Hardware: Other Linux
: P5 normal
Target Milestone: ---
Assignee: UCS maintainers
QA Contact: UCS maintainers
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-05-02 13:24 CEST by Mirac Erdemiroglu
Modified: 2025-03-21 14:54 CET (History)
1 user (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 3: Simply Wrong: The implementation doesn't match the docu
Who will be affected by this bug?: 1: Will affect a very few installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.034
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2024042321000295
Bug group (optional):
Customer ID:
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Mirac Erdemiroglu univentionstaff 2024-05-02 13:24:50 CEST
There are user objects with uid=join-backup and uid=join-slave on our UCS instances. These can be retrieved via ldapsearch and udm, but are not available in the UMC.

What are they used for, or are these objects used at all?

Would it be possible to check them for removability and remove them if not needed?




Here is an output from my test primary node to get more clarity.

dn: uid=join-backup,cn=users,dc=ucs5schoolhejne,dc=intranet
krb5MaxLife: 86400
krb5MaxRenew: 604800
uid: join-backup
uidNumber: 2003
sn: Joinuser
gecos: Joinuser
displayName: Joinuser
homeDirectory: /dev/null
loginShell: /bin/bash
mailForwardCopyToSelf: 0
univentionObjectFlag: hidden
cn: Joinuser
krb5PrincipalName: join-backup@UCS5SCHOOLHEJNE.INTRANET
krb5KDCFlags: 126
userPassword:: e2NyeXB0fSQ2JHczSndqV3RjeWpDT1lzcnIkWW91VVJtL1VwM2dpVnpFa2lrb0dBeFJ6SUZzWFJXWGZkY2VhSTJ3ZXNuMGtHVmZiSWdCbDREekNDN1hoNHJXSzVQL1kudlguQzZIS3NQbUdmcGdkeS8=
krb5Key:: MEWhEzARoAMCAQGhCgQIxAF8LzGAVKiiLjAsoAMCAQOhJQQjVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1iYWNrdXA=
krb5Key:: MF2hKzApoAMCARKhIgQgk3VfSes25jeFfRVBjpiUmyqrkk3f4Idvvty5uvPDlrKiLjAsoAMCAQOhJQQjVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1iYWNrdXA=
krb5Key:: MEWhEzARoAMCAQOhCgQIxAF8LzGAVKiiLjAsoAMCAQOhJQQjVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1iYWNrdXA=
krb5Key:: MFWhIzAhoAMCARChGgQYrW5bio+hBP1rg8LxN2gvxICn1eWXAp6Aoi4wLKADAgEDoSUEI1VDUzVTQ0hPT0xIRUpORS5JTlRSQU5FVGpvaW4tYmFja3Vw
krb5Key:: ME2hGzAZoAMCARehEgQQQsN5Loa4bkHW7XNH1jkBraIuMCygAwIBA6ElBCNVQ1M1U0NIT09MSEVKTkUuSU5UUkFORVRqb2luLWJhY2t1cA==
krb5Key:: MEWhEzARoAMCAQKhCgQIxAF8LzGAVKiiLjAsoAMCAQOhJQQjVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1iYWNrdXA=
krb5Key:: ME2hGzAZoAMCARGhEgQQO4E/qBxgJH2gtT4UG/xWgaIuMCygAwIBA6ElBCNVQ1M1U0NIT09MSEVKTkUuSU5UUkFORVRqb2luLWJhY2t1cA==
krb5KeyVersionNumber: 1
pwhistory:: ICQ2JHFNWTdNZnpBWkhVNDZDajEkMTI4UlBVZ3JRZVJwcmZGd3l1WUF5ZGNkQ0guUktFcmtWelh4eDhVYkZLSWd4YlRtWnVQS09wZWYzckhmYVJsLzBJdmI2RnBPR0RIMFlpZzI0UWVFYjE=
sambaNTPassword: 42C3792E86B86E41D6ED7347D63901AD
sambaPasswordHistory: 8C4AC36E2C6DA6EE429FD9195A7B6E946095A79D7B5BD611423073E773B47AF9
sambaPwdLastSet: 1656062038
sambaBadPasswordCount: 0
sambaBadPasswordTime: 0
sambaAcctFlags: [U          ]
objectClass: organizationalPerson
objectClass: person
objectClass: automount
objectClass: univentionMail
objectClass: posixAccount
objectClass: shadowAccount
objectClass: univentionPWHistory
objectClass: krb5KDCEntry
objectClass: top
objectClass: univentionObject
objectClass: sambaSamAccount
objectClass: inetOrgPerson
objectClass: krb5Principal
sambaSID: S-1-5-21-1150003711-260972013-2878653590-5006
gidNumber: 5008
sambaPrimaryGroupSID: S-1-5-21-1150003711-260972013-2878653590-11017
univentionObjectType: users/user

dn: uid=join-slave,cn=users,dc=ucs5schoolhejne,dc=intranet
krb5MaxLife: 86400
krb5MaxRenew: 604800
uid: join-slave
uidNumber: 2004
sn: Joinuser
gecos: Joinuser
displayName: Joinuser
homeDirectory: /dev/null
loginShell: /bin/bash
mailForwardCopyToSelf: 0
univentionObjectFlag: hidden
cn: Joinuser
krb5PrincipalName: join-slave@UCS5SCHOOLHEJNE.INTRANET
krb5KDCFlags: 126
userPassword:: e2NyeXB0fSQ2JE83UEhub0l1cmxHNk9xLnMkelFacy5wemdTbjhtNHh2ME9wcjZINE5lR2lxL1RJcldnSE1iSlNBR2gwc25WdDBXZ2VBcmJ4MTIyblFiRFlUZFBiMk5CNk5kQmw4ellyODdadEFVbi8=
krb5Key:: MEShEzARoAMCAQGhCgQIhasLZBz0VwuiLTAroAMCAQOhJAQiVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1zbGF2ZQ==
krb5Key:: MFShIzAhoAMCARChGgQY7GenYtM7keomoh/W35fjTxqF3zKi+/uuoi0wK6ADAgEDoSQEIlVDUzVTQ0hPT0xIRUpORS5JTlRSQU5FVGpvaW4tc2xhdmU=
krb5Key:: MEShEzARoAMCAQKhCgQIhasLZBz0VwuiLTAroAMCAQOhJAQiVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1zbGF2ZQ==
krb5Key:: MEyhGzAZoAMCARehEgQQO6hy/E0otOfCDUSvWuEg1qItMCugAwIBA6EkBCJVQ1M1U0NIT09MSEVKTkUuSU5UUkFORVRqb2luLXNsYXZl
krb5Key:: MEyhGzAZoAMCARGhEgQQgvJbV2kACZ1v8ozQPSgWTKItMCugAwIBA6EkBCJVQ1M1U0NIT09MSEVKTkUuSU5UUkFORVRqb2luLXNsYXZl
krb5Key:: MFyhKzApoAMCARKhIgQgDITzpHxID/dq1/GE2zaO9dc5ZEIHVi2EFKCZtZzz2vKiLTAroAMCAQOhJAQiVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1zbGF2ZQ==
krb5Key:: MEShEzARoAMCAQOhCgQIhasLZBz0VwuiLTAroAMCAQOhJAQiVUNTNVNDSE9PTEhFSk5FLklOVFJBTkVUam9pbi1zbGF2ZQ==
krb5KeyVersionNumber: 1
pwhistory:: ICQ2JENGREFLVnRqRmtMMjcyZ0EkODZDdk9vSFI0eERTNFlsZXR1c2lmVzFMQlY4QkdxV3pGbmo0WFhZR3BtYks5SDI5cHdzZDhSZXdDVXpoNTJNLi5GTWFQUi5kNGIxaGhHOEs5Z3JxczE=
sambaNTPassword: 3BA872FC4D28B4E7C20D44AF5AE120D6
sambaPasswordHistory: 35E5FD5E88FD94608B4F7166301D6771616BCDD6AA4A506CC7034D354275CB61
sambaPwdLastSet: 1656062038
sambaBadPasswordCount: 0
sambaBadPasswordTime: 0
sambaAcctFlags: [U          ]
objectClass: organizationalPerson
objectClass: person
objectClass: automount
objectClass: univentionMail
objectClass: posixAccount
objectClass: shadowAccount
objectClass: univentionPWHistory
objectClass: krb5KDCEntry
objectClass: top
objectClass: univentionObject
objectClass: sambaSamAccount
objectClass: inetOrgPerson
objectClass: krb5Principal
sambaSID: S-1-5-21-1150003711-260972013-2878653590-5008
gidNumber: 5009
sambaPrimaryGroupSID: S-1-5-21-1150003711-260972013-2878653590-11019
univentionObjectType: users/user
Comment 1 Florian Best univentionstaff 2025-03-21 14:54:47 CET
You can see them in UMC if you click in the search on "Include hidden objects".
They seem to be required for something but are explicitly flagged as system objects and aren't counted in the license.