diff options
author | Jakub Hrozek <jhrozek@redhat.com> | 2013-02-23 10:44:54 +0100 |
---|---|---|
committer | Jakub Hrozek <jhrozek@redhat.com> | 2013-03-19 21:47:30 +0100 |
commit | c0bca1722d6f9dfb654ad78397be70f79ff39af1 (patch) | |
tree | 04a479b7191cca127e632a738a48c4182a39cae3 /src/providers/ipa/ipa_utils.c | |
parent | 6569d57e3bc168e6e83d70333b48c5cb43aa04c4 (diff) | |
download | sssd-c0bca1722d6f9dfb654ad78397be70f79ff39af1.tar.gz sssd-c0bca1722d6f9dfb654ad78397be70f79ff39af1.tar.bz2 sssd-c0bca1722d6f9dfb654ad78397be70f79ff39af1.zip |
Resolve GIDs in the simple access provider
Changes the simple access provider's interface to be asynchronous. When
the simple access provider encounters a group that has gid, but no
meaningful name, it attempts to resolve the name using the
be_file_account_request function.
Some providers (like the AD provider) might perform initgroups
without resolving the group names. In order for the simple access
provider to work correctly, we need to resolve the groups before
performing the access check. In AD provider, the situation is
even more tricky b/c the groups HAVE name, but their name
attribute is set to SID and they are set as non-POSIX
Diffstat (limited to 'src/providers/ipa/ipa_utils.c')
0 files changed, 0 insertions, 0 deletions