Activity log for bug #1973752

Date Who What changed Old value New value Message
2022-05-17 12:19:19 Didier Roche-Tolomelli bug added bug
2022-05-17 12:20:23 Didier Roche-Tolomelli description [Impact] Disallowing local administrator does not work as excepted: - on some AD server, setting in the UI this key (and some other similars) to disabled, go to next GPO rule, then back to this one, AD will display the key as enabled. - on the client machine, we can see that the key has no state and nothing is forcibly allowed or disallowed. [Test case] * Install the new admx/adml with this version on the AD server. * On AD, go to disallow local administator, set it to disabled * Go to next GPO rules and then go back * The rule should still be disabled. * On an Ubuntu machine connected with AD by adsys, with ua attached, force a machine refresh with adsysctl policy update -m. * Check in adsysctl policy applied --all that the key is displayed as disabled * Confirm that no local administrator (part of the sudo group) can run "sudo". [Where problems could occur] The privilege manager and other policies impacts both Windows and client: - on Windows, this is in the admx/adml are statically generated and then shipped as thus. There is no runtime exercising this. The consequence of those generated files to be invalid is that Windows AD server will not show up "Ubuntu" in its GPO template. - on the client, the privilege manager is the main consumer of those disabled key types. The other kinds of keys are not impacted. [Impact] Disallowing local administrator does not work as excepted: - on some AD server, setting in the UI this key (and some other similars) to disabled, go to next GPO rule, then back to this one, AD will display the key as enabled. - on the client machine, we can see that the key has no state and nothing is forcibly allowed or disallowed. [Test case] * Install the new admx/adml with this version on the AD server. * On AD, go to disallow local administator, set it to disabled * Go to next GPO rules and then go back * The rule should still be disabled. * On an Ubuntu machine connected with AD by adsys, with ua attached, force a machine refresh with adsysctl policy update -m. * Check in adsysctl policy applied --all that the key is displayed as disabled * Confirm that no local administrator (part of the sudo group) can run "sudo". [Where problems could occur] The privilege manager and other policies impacts both Windows and client: - on Windows, this is in the admx/adml are statically generated and then shipped as thus. There is no runtime exercising this. The consequence of those generated files to be invalid is that Windows AD server will not show up "Ubuntu" in its GPO template. - on the client, the privilege manager is the main consumer of those disabled key types. The other kinds of keys are not impacted. [Additional informations] * New test cases have been added for the client part.
2022-05-17 12:32:39 Didier Roche-Tolomelli nominated for series Ubuntu Jammy
2022-05-17 12:32:39 Didier Roche-Tolomelli bug task added adsys (Ubuntu Jammy)
2022-05-17 12:33:23 Didier Roche-Tolomelli bug added subscriber Ubuntu Stable Release Updates Team
2022-05-18 07:29:16 Launchpad Janitor adsys (Ubuntu): status New Fix Released
2022-05-20 11:00:37 Timo Aaltonen adsys (Ubuntu Jammy): status New Fix Committed
2022-05-20 11:00:39 Timo Aaltonen bug added subscriber SRU Verification
2022-05-20 11:00:42 Timo Aaltonen tags verification-needed verification-needed-jammy
2022-06-08 08:11:15 Didier Roche-Tolomelli nominated for series Ubuntu Focal
2022-06-08 08:11:15 Didier Roche-Tolomelli bug task added adsys (Ubuntu Focal)
2022-06-08 10:45:01 Jean-Baptiste Lallement tags verification-needed verification-needed-jammy verification-done-jammy verification-needed
2022-06-14 21:41:22 Launchpad Janitor adsys (Ubuntu Jammy): status Fix Committed Fix Released
2022-06-14 21:41:36 Brian Murray removed subscriber Ubuntu Stable Release Updates Team
2022-06-15 06:23:13 Didier Roche-Tolomelli bug added subscriber Ubuntu Stable Release Updates Team
2022-09-21 09:45:33 Łukasz Zemczak adsys (Ubuntu Focal): status New Fix Committed
2022-09-21 09:45:37 Łukasz Zemczak tags verification-done-jammy verification-needed verification-done-jammy verification-needed verification-needed-focal
2022-09-26 14:29:31 Jean-Baptiste Lallement tags verification-done-jammy verification-needed verification-needed-focal verification-done verification-done-focal verification-done-jammy
2022-10-05 01:36:03 Launchpad Janitor adsys (Ubuntu Focal): status Fix Committed Fix Released