[gpfsug-discuss] Question concerning integration of CES with AD authentication system

Dorigo Alvise (PSI) alvise.dorigo at psi.ch
Thu May 24 09:45:00 BST 2018


Dear members,
at PSI I'm trying to integrate the CES service with our AD authentication system.

My understanding, after talking to expert people here, is that I should use the RFC2307 model for ID mapping (described here: https://goo.gl/XvqHDH). The problem is that our ID schema is slightly different than that one described in RFC2307. In the RFC the relevant user identification fields are named "uidNumber" and "gidNumber". But in our AD database schema we have:

# egrep 'uid_number|gid_number' /etc/sssd/sssd.conf
ldap_user_uid_number = msSFU30UidNumber
ldap_user_gid_number = msSFU30GidNumber
ldap_group_gid_number = msSFU30GidNumber

My question is: is it possible to configure CES to look for the custom field labels (those ones listed above) instead the default ones officially described in rfc2307 ?

many thanks.
Regards,

   Alvise Dorigo
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://gpfsug.org/pipermail/gpfsug-discuss_gpfsug.org/attachments/20180524/c2388479/attachment-0001.htm>


More information about the gpfsug-discuss mailing list