https://bugzilla.redhat.com/show_bug.cgi?id=2361759
Bug ID: 2361759
Summary: sssd version 2.10.2 forgets group membership
information after an hour
Product: Fedora
Version: 42
Hardware: x86_64
OS: Linux
Status: NEW
Component: sssd
Severity: high
Assignee: sssd-maintainers(a)lists.fedoraproject.org
Reporter: fedoraproject(a)ferree-clark.org
QA Contact: extras-qa(a)fedoraproject.org
CC: abokovoy(a)redhat.com, atikhono(a)redhat.com,
lslebodn(a)redhat.com, pbrezina(a)redhat.com,
sbose(a)redhat.com, ssorce(a)redhat.com,
sssd-maintainers(a)lists.fedoraproject.org
Target Milestone: ---
Classification: Fedora
After upgrading to sssd version 2.10.2, on hosts running both Fedora 41 and 42,
sssd "forgets" group membership information after about an hour. After this
occurs, the "id" command shows the user's password information and local
(/etc/group) information but does not include groups that come from freeipa.
Likewise, the getent group <freeipa groupname> command shows the group number
and name, but does not include group members. Restarting sssd does not fix the
problem, and neither does clearing the cache, even deleting the cache files.
Forcing the sssd to switch ipa servers does cause group membership information
to return, but again it disappears after an hour. I have confirmed that group
membership information is correct when queried directly from freeipa when sssd
does not display it. Reverting to sssd version 2.10.0 fixes the problem. This
bug is causing havoc with applications that depend on particular group
membership.
Reproducible: Always
Steps to Reproduce:
1.Start sssd for the first time (or force it to switch ipa servers)
2.Wait about an hour
3.Perform group query: getent group homeassistant (or any other freeipa group)
Actual Results:
homeassistant:*:637200008:
Expected Results:
homeassistant:*:637200008:user1,user2,user3
Additional Information:
I have not been able to find errors in the logs that would explain this
behavior.
--
You are receiving this mail because:
You are the assignee for the bug.
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2361759
Report this comment as SPAM: https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-sp…