On Tue, May 30, 2017 at 09:27:05PM +0300, Alexander Bokovoy via FreeIPA-users 
wrote:
> On ti, 30 touko 2017, Robert Johnson via FreeIPA-users wrote:
> > So I took a brand new user that I have never used in the system before (I
> > checked that the entry was not in the compat tree) and just ran an "id"
> > command on Solaris system.  I then looked in the /var/log/dirsrv/slapd-<ipa
> > domain>/access log file on the ipa server, for the query and from the log
> > file, the query came in as all caps.
> > 
> > example:
> > [~]$: id 831...@win.mydomin.com
> > 
> > [~]$: cat /var/log/dirsrv/slapd-<ipa domain>/access |grep 831413
> > [30/May/2017:13:34:38.637498942 -0400] conn=94124 op=622 SRCH
> > base="cn=users,cn=compat,dc=ipa,dc=mydomain,dc=com" scope=1
> > filter="(&(objectClass=posixAccount)(uid=831...@win.mydomin.com))"
> > attrs="cn uid uidNumber gidNumber gecos description homeDirectory
> > loginShell"
> > [30/May/2017:13:34:38.651811322 -0400] conn=94124 op=622 RESULT err=0
> > tag=101 nentries=1 etime=0
> > 
> > However, the entry in the compat tree is all lowercase just like I
> > reported.  I can reproduce this easily.
> memberUid value comes from SSSD look up. SSSD normalizes all names to
> low case.
> 
> For group names, I'm not sure they are normalized, though.

with id_provider=ad (which is what is running under the hood of the
sssd-on-idm-masters) everything should be normalized and there shouldn't
even be an option to turn the normalization off.
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

Reply via email to