On Fri, Dec 04, 2015 at 10:56:26AM +0100, Lukas Slebodnik wrote:
On (04/12/15 09:19), Jakub Hrozek wrote:
>On Thu, Dec 03, 2015 at 04:05:04PM -0800, aaron wang wrote:
>> Hi All,
>>
>> The issue is:
>> I'm using "authconfig --enablesssd --enablesssdauth
--enablelocauthorze
>> --update" to configure the /etc/nsswitch
>>
>> The authconfig put in the entry like this : "services: files sss"
>>
>> So what happens is, LDAP server is getting a lot of requests like this:
>> *[***sanitzied fields***]
>>
filter="(&(cn=ntp)(ipServiceProtocol=sctp)(objectClass=ipService))"
>> attrs="objectClass cn ipServicePort ipServiceProtocol
modifyTimestamp"*
>>
>> I don't see any options that authconfig has to avoid including sss in nss
>> services for now. So is there anything I can use on the SSSD side to filter
>> out nss services requests ?
>>
>> Thanks,
>> Aaron
>
>There is no such option, but I think this is a very resonable request,
>can you open a ticket at:
>
https://fedorahosted.org/sssd/newticket
>please?
I think it should be a RFE for authconfig and not sssd.
LS
Yes, but I still think a ticket for filter_services would be valid (not
urgent, though, most users would be OK with removing sss from services).