Can't use objectGUID as user_id_attribute in Keystone/LDAP integration
Bug #1895903 reported by
Nikolay Vinogradov
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Identity (keystone) |
New
|
Undecided
|
Unassigned |
Bug Description
In order to configure Keystone LDAP integration the upstream docs suggests using cn for user_id_attribute [1]. A more stable alternative attribute to cn as a user ID could be objectGUID, but it doesn't work in keystone:
$ openstack user list --domain fd8fbe474db94bb
ID attribute objectGUID not found in LDAP object CN=..... (HTTP 404) (Request-ID: req-d4564a60-
ldapsearch returns the attribute correctly using the same query as the one failing in keystone.
[1] https:/
To post a comment you must log in.
This looks to be a duplicate of https:/ /bugs.launchpad .net/keystone/ +bug/1889936