[Freeipa-devel] memberOf wierdness

Rob Crittenden rcritten at redhat.com
Tue Oct 30 15:38:21 UTC 2007


In my experimentation with new indeces I found a strange issue with 
memberOf.

If I install IPA, get a ticket for admin and do:

ldapsearch -Y GSSAPI -b "dc=freeipa,dc=org" 
"memberof=cn=admins,cn=groups,cn=accounts,dc=freeipa,dc=org" cn

I get 0 results back.

If I use ipa-adduser and then add that user to the admins group and then 
issue the search again, I get 1 result back, the user I just added.

The user admin has the following OC's:

objectClass: top
objectClass: person
objectClass: posixAccount
objectClass: KrbPrincipalAux

My test user has:

objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: inetOrgPerson
objectClass: inetUser
objectClass: posixAccount
objectClass: krbPrincipalAux

Could this have something to do with it?

rob
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 3245 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20071030/9c00543e/attachment.bin>


More information about the Freeipa-devel mailing list