I made a mistake interpreting the audit log initially. I realized after
I created the subject that the MemberOf changes reflect the changes
being made in the background to the individual record to populate the
memberOf attributes for the change I initiated. Since the audit records
don't actually say what the MemberOf plugins are changing in the record
(they only report updating the modifiersname), I thought it was actually
what was changing the group membership back.
The memberof plugin does not change group memberships it only updates
the memberof attribute to keep it in sync with the member ones.
Something else was changing the group membership back (or rolling back
the initial change), but it is not being recorded in the audit logs.
I still can't get my head around why the audit log reports both plugins
making changes to the record, even though the 389 MemberOf plugin is
modifiersName: cn=MemberOf Plugin,cn=plugins,cn=config
Freeipa-users mailing list