Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-22257

[JIT Provisioning] There should be an %{dn} placeholder for the user DN

XMLWordPrintable

    • Icon: Patch request Patch request
    • Resolution: Unresolved
    • Icon: Trivial Trivial
    • None
    • 6.4 (plan)
    • Frontend (F)
    • None

      By the spec, a group `member` should always be an Distinguished Name, so, default filter for groupOfNames (`(%{groupattr}=%{user})`) is wrong. There should be an %{dn} placeholder for the user DN and `(%{groupattr}=%{dn})` should be the default filter.

      I know that one can set %{ref} to `distinguishedName` in case of AD, or `entryDN` for other LDAP implementations, but those are not standard attributes, so, not guaranteed to be present for every LDAP Server implementation, whereas `member` should always be a DN.

            zabbix.dev Zabbix Development Team
            markkrj Marcos de Oliveira
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: