[Freeipa-users] Netgroups and users

Sigbjorn Lie sigbjorn at nixtra.com
Tue Dec 13 21:50:50 UTC 2011


Hi,

When adding users or user groups to a netgroup, the format of the 
netgrouptriple ends up as following:

nisNetgroupTriple: (-,username,ix.test.com)

The extra "-" prevents me from using IPA's netgroups for tcp wrappers 
using /etc/hosts.allow and /etc/hosts.deny for user access control.

Making the same test with a NIS server, creating the same entry without 
the "-", works for user access control.

Looking at 389-ds' wiki, the "-" should not be there:
http://directory.fedoraproject.org/wiki/Howto:Netgroups

Is this a configurable setting? Or should I open a ticket?


Regards,
Siggi




More information about the Freeipa-users mailing list