Comment 0 for bug 1933116

Revision history for this message
Jean-Baptiste Lallement (jibel) wrote : [SRU] Fix GPO support on Focal

[Description]
GPO support in focal doesn't focal MS ADTS spec and is not functional. It means that the default domain policy containing the security policy for example is not applied.

This SRU backports GPO patches from current stable version of SSSD.

[Test Case]
1. Install a machine with SSSD and join and AD domain where the controller is a Windows machine.
2. Add the machine to an OU of the domain
3. Boot the machine and login ad a user of the domain.
4. Verify the content of /var/lib/sss/gpo_cache/

When it fails, this directory is empty
On success it is filled with the GPO downloaded from the domain controller.

It is also possible to check the journal for errors, there should be non related to GPO.

[Where problems could occur]
This code is limited to GPO on AD which is not working in focal. Worst case, it is still not functional.