<html><body><div style="color:#000; background-color:#fff; font-family:times new roman, new york, times, serif;font-size:12pt"><div><span>Hi Rob and all,</span></div><div><span><br></span></div><div><span>The </span> ipa-managed-entries command is not available on freeIPA 2.1.3 version comes with Redhat 6.2. Is there any other comparable ways to disable private user groups generation at global/system wide, instead of ''--noprivate" option to 'ups user-add' which is user by user? Thanks a lot.</div><div><br></div><div>--David</div><div><br></div> <div style="font-size: 12pt; font-family: 'times new roman', 'new york', times, serif; "> <div style="font-size: 12pt; font-family: 'times new roman', 'new york', times, serif; "> <div dir="ltr"> <font size="2" face="Arial"> <hr size="1"> <b><span style="font-weight:bold;">From:</span></b> Rob Crittenden <rcritten@redhat.com><br> <b><span style="font-weight: bold;">To:</span></b> David
Copperfield <cao2dan@yahoo.com> <br><b><span style="font-weight: bold;">Cc:</span></b> Petr Spacek <pspacek@redhat.com>; "freeipa-users@redhat.com" <freeipa-users@redhat.com> <br> <b><span style="font-weight: bold;">Sent:</span></b> Wednesday, May 9, 2012 10:08 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: [Freeipa-users] Please help: Any way to turn off IPA creation of private user group?<br> </font> </div> <br>
David Copperfield wrote:<br>> Hi Petr and all,<br>><br>> Thanks for your reply.<br>><br>> After the automatic creation of the private user group is turned off,<br>> does the user creation Web page still show the GID field? and pre-filled<br>> with the same number(or the next available GID) as the UID number? or<br>> the filed is completely disappeared? Thanks.<br><br>Disabling UPG has no effect on what appears in the UI or CLI.<br><br>The assignment is done on the server. If either of the UID or GID number <br>is not provided one is assigned. In the case of GID if one is not <br>provided and UPG is enabled then it gets assigned the same value as the <br>UID, otherwise it gets the GID of the default users group if it is <br>POSIX. If it is not POSIX the creation request is denied. In 2.2 anyway. <br>In 2.1.3 it may well allow it and try to create a user with no GID <br>(which should fail).<br><br>rob<br><br>><br>>
--David<br>><br>> ------------------------------------------------------------------------<br>> *From:* Petr Spacek <<a ymailto="mailto:pspacek@redhat.com" href="mailto:pspacek@redhat.com">pspacek@redhat.com</a>><br>> *To:* <a ymailto="mailto:freeipa-users@redhat.com" href="mailto:freeipa-users@redhat.com">freeipa-users@redhat.com</a><br>> *Sent:* Wednesday, May 9, 2012 4:02 AM<br>> *Subject:* Re: [Freeipa-users] Please help: Any way to turn off IPA<br>> creation of private user group?<br>><br>> On 05/08/2012 03:29 PM, Rob Crittenden wrote:<br>> > David Copperfield wrote:<br>> >> Hi folks,<br>> >><br>> >> Are there any way to turn off IPA automatic creation of private user<br>> >> group? We use a common user group like ‘nis-wheel’, and completely<br>> >> disabled private groups in openldap before migration.<br>>
><br>> > If you disable private groups then the primary group of users is<br>> going to be<br>> > the default IPA users group. This group will need to be POSIX. If it<br>> isn't you<br>> > can promote it with:<br>> ><br>> > $ ipa group-mod --posix ipausers<br>> ><br>> > To disable private groups run:<br>> ><br>> > $ ipa-managed-entries disable -e 'UPG Definition'<br>> ><br>> > rob<br>><br>> For record && Google:<br>><br>> http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html-single/Identity_Management_Guide/index.html#user-private-groups<br>><br>> Petr^2 Spacek<br>><br>> _______________________________________________<br>> Freeipa-users mailing list<br>> <a ymailto="mailto:Freeipa-users@redhat.com"
href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a> <mailto:<a ymailto="mailto:Freeipa-users@redhat.com" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a>><br>> <a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>><br>><br>><br>><br>> _______________________________________________<br>> Freeipa-users mailing list<br>> <a ymailto="mailto:Freeipa-users@redhat.com" href="mailto:Freeipa-users@redhat.com">Freeipa-users@redhat.com</a><br>> <a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br><br><br><br> </div> </div> </div></body></html>