On Tue, May 30, 2017 at 09:27:05PM +0300, Alexander Bokovoy via FreeIPA-users wrote: > On ti, 30 touko 2017, Robert Johnson via FreeIPA-users wrote: > > So I took a brand new user that I have never used in the system before (I > > checked that the entry was not in the compat tree) and just ran an "id" > > command on Solaris system. I then looked in the /var/log/dirsrv/slapd-<ipa > > domain>/access log file on the ipa server, for the query and from the log > > file, the query came in as all caps. > > > > example: > > [~]$: id 831...@win.mydomin.com > > > > [~]$: cat /var/log/dirsrv/slapd-<ipa domain>/access |grep 831413 > > [30/May/2017:13:34:38.637498942 -0400] conn=94124 op=622 SRCH > > base="cn=users,cn=compat,dc=ipa,dc=mydomain,dc=com" scope=1 > > filter="(&(objectClass=posixAccount)(uid=831...@win.mydomin.com))" > > attrs="cn uid uidNumber gidNumber gecos description homeDirectory > > loginShell" > > [30/May/2017:13:34:38.651811322 -0400] conn=94124 op=622 RESULT err=0 > > tag=101 nentries=1 etime=0 > > > > However, the entry in the compat tree is all lowercase just like I > > reported. I can reproduce this easily. > memberUid value comes from SSSD look up. SSSD normalizes all names to > low case. > > For group names, I'm not sure they are normalized, though.
with id_provider=ad (which is what is running under the hood of the sssd-on-idm-masters) everything should be normalized and there shouldn't even be an option to turn the normalization off. _______________________________________________ FreeIPA-users mailing list -- firstname.lastname@example.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org