Note: This is a beta release of Red Hat Bugzilla 5.0. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Also email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback here.
Bug 1518700 - Incorrect description in Default Trust View on Clients with Earlier Versions of IdM
Summary: Incorrect description in Default Trust View on Clients with Earlier Versions ...
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: doc-Windows_Integration_Guide
Version: 7.4
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Aneta Šteflová Petrová
QA Contact: ipa-qe
Depends On:
TreeView+ depends on / blocked
Reported: 2017-11-29 13:42 UTC by Aneta Šteflová Petrová
Modified: 2019-03-06 02:28 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2018-03-06 15:41:11 UTC
Target Upstream Version:

Attachments (Terms of Use)

Description Aneta Šteflová Petrová 2017-11-29 13:42:55 UTC
8.1. Active Directory Default Trust View

Default Trust View on Clients with Earlier Versions of IdM

Clients running IdM versions earlier than Red Hat Enterprise Linux 7.1 only see the Default Trust View, because ID views are applied on the client side. If you need a client to apply a different ID view, update SSSD on the client to a version with ID views support or have the client use the compat LDAP tree.


The compat LDAP tree offers a simplified LDAP tree with user and group data for legacy clients.

The text above makes me think that there is only *one* view legacy clients see. And it explicitly says to use SSSD if you need host specific views. This is incorrect.

Additional note from Alexander Bokovoy:  this part simply is undocumented in the guide
and documented elsewhere: slapi-nis package itself, freeIPA wiki pages,

Reported by Dmitri Pal.

Comment 2 Aneta Šteflová Petrová 2018-01-17 12:39:57 UTC
I commented out the text quoted in c#0 for now.

Next, I'm going to search the slapi-nis documentation and FreeIPA wiki for information about how Default Trust View on legacy clients works.

Comment 4 Aneta Šteflová Petrová 2018-01-24 12:11:57 UTC
Pending peer review.

Comment 13 Aneta Šteflová Petrová 2018-02-27 13:18:13 UTC
The guide now includes a new section called 8.1.3. ID Overrides on Clients Based on the Client Version. This section replaces the previous section "Default Trust View on Clients with Earlier Versions of IdM", which was reported as misleading.

Note You need to log in before you can comment on or make changes to this bug.