[Freeipa-users] compat and nested groups for Unix system

Iulian Roman iulian.roman at gmail.com
Mon Mar 20 14:47:32 UTC 2017


Hello,

I noticed that nested group feature do not work with the unix ldap clients
(AIX) if the default groupbasedn (cn=groups,cn=accounts,dc=...) is used. If
i use the cn=compat and change the mapping the nested groups are listed
properly.

My question is if it is allowed to mix the compat and accounts cn for the
userbasedn and groupbasedn on the same unix ldap client ?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20170320/fa4bceb6/attachment.htm>


More information about the Freeipa-users mailing list