<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:30:57 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-16901] Provide l_getidentity_nss identity provider</title>
                <link>https://jira.whamcloud.com/browse/LU-16901</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;l_getidenity to fetch user&apos;s supplementary groups info from NIS, LDAP and/or any other services that NSS modules exist for.  Add lustre-only user/group configuration in plain files, keeping Lustre users and groups separate from Linux users/groups on Lustre server&apos;s machines for security reason&lt;/p&gt;</description>
                <environment></environment>
        <key id="76577">LU-16901</key>
            <summary>Provide l_getidentity_nss identity provider</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="stancheff">Shaun Tancheff</assignee>
                                    <reporter username="stancheff">Shaun Tancheff</reporter>
                        <labels>
                    </labels>
                <created>Thu, 15 Jun 2023 09:40:08 +0000</created>
                <updated>Mon, 20 Nov 2023 16:50:27 +0000</updated>
                            <resolved>Sat, 18 Nov 2023 22:05:00 +0000</resolved>
                                                    <fixVersion>Lustre 2.16.0</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>5</watches>
                                                                            <comments>
                            <comment id="375508" author="gerrit" created="Thu, 15 Jun 2023 09:43:55 +0000"  >&lt;p&gt;&quot;Shaun Tancheff &amp;lt;shaun.tancheff@hpe.com&amp;gt;&quot; uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/c/fs/lustre-release/+/51329&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/c/fs/lustre-release/+/51329&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-16901&quot; title=&quot;Provide l_getidentity_nss identity provider&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-16901&quot;&gt;&lt;del&gt;LU-16901&lt;/del&gt;&lt;/a&gt; utils: l_getidentity_nss&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: bf6a4565c11ae2d570e04f3d982e0bd1f4903d71&lt;/p&gt;</comment>
                            <comment id="375710" author="adilger" created="Fri, 16 Jun 2023 20:28:39 +0000"  >&lt;p&gt;I think this was previously submitted under patch  &lt;a href=&quot;https://review.whamcloud.com/45634&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/45634&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;My question there was:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Maybe I&apos;m missing something, but doesn&apos;t the existing l_getidentity.c &lt;b&gt;already&lt;/b&gt; handle lookups based on /etc/nsswitch.conf by calling the Glibc getpwuid/getgrouplist to do lookups in LDAP, NIS, SSS?&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;And the response from Alexander Zarochentsev was:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;the idea is to have configuration independent from the system on in /etc/nsswitch.conf. at least I was told it is useful for server security.&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;but it didn&apos;t provide enough explanation about what security issues this addresses&lt;/p&gt;

&lt;p&gt;It should be possible to query the LDAP without allowing the users to login to the MDS and needing a separate upcall?&lt;/p&gt;</comment>
                            <comment id="393503" author="gerrit" created="Sat, 18 Nov 2023 21:43:39 +0000"  >&lt;p&gt;&quot;Oleg Drokin &amp;lt;green@whamcloud.com&amp;gt;&quot; merged in patch &lt;a href=&quot;https://review.whamcloud.com/c/fs/lustre-release/+/51329/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/c/fs/lustre-release/+/51329/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-16901&quot; title=&quot;Provide l_getidentity_nss identity provider&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-16901&quot;&gt;&lt;del&gt;LU-16901&lt;/del&gt;&lt;/a&gt; utils: l_getidentity with nss module support&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: 5f9f92454ef2a46075c850546ad4ac1621038dcf&lt;/p&gt;</comment>
                            <comment id="393529" author="pjones" created="Sat, 18 Nov 2023 22:05:00 +0000"  >&lt;p&gt;Landed for 2.16&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10010">
                    <name>Duplicate</name>
                                            <outwardlinks description="duplicates">
                                        <issuelink>
            <issuekey id="67295">LU-15267</issuekey>
        </issuelink>
                            </outwardlinks>
                                                        </issuelinktype>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="79088">LU-17301</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i03o3j:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>