>From f7dd694165ea2b9deaf7dc6b395226c23d4a6a95 Mon Sep 17 00:00:00 2001
From: Stephen Gallagher <sgallagh@redhat.com>
Date: Fri, 21 Sep 2012 10:06:47 -0400
Subject: [PATCH] AD: autorid compatibility should recommend the use of
 default domain

Previously, we were failing to start if ldap_idmap_autorid_compat
was True but the default domain SID was unspecified. This is the
recommended configuration, but it is functional without it. There
is just a slight risk that the IDs will be inconsistent between
machines if the first user requested is not from the default
domain.

https://fedorahosted.org/sssd/ticket/1530
---
 src/providers/ldap/sdap_idmap.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/src/providers/ldap/sdap_idmap.c b/src/providers/ldap/sdap_idmap.c
index b41958bbeb193d54472ac5a026d46284176ae1fa..94170e54a3b58418073ad091e265b62c35bfe874 100644
--- a/src/providers/ldap/sdap_idmap.c
+++ b/src/providers/ldap/sdap_idmap.c
@@ -157,11 +157,11 @@ sdap_idmap_init(TALLOC_CTX *mem_ctx,
         } else {
             if (dp_opt_get_bool(idmap_ctx->id_ctx->opts->basic, SDAP_IDMAP_AUTORID_COMPAT)) {
                 /* In autorid compatibility mode, we MUST have a slice 0 */
-                DEBUG(SSSDBG_FATAL_FAILURE,
-                      ("Autorid compatibility mode selected, but %s is not set\n",
+                DEBUG(SSSDBG_CRIT_FAILURE,
+                      ("WARNING: Autorid compatibility mode selected, "
+                       "but %s is not set. UID/GID values may differ "
+                       "between clients.\n",
                        idmap_ctx->id_ctx->opts->basic[SDAP_IDMAP_DEFAULT_DOMAIN_SID].opt_name));
-                ret = EINVAL;
-                goto done;
             }
             /* Otherwise, we'll just fall back to hash values as they are seen */
         }
-- 
1.7.12

