APAR status
Closed as program error.
Error description
The getgrgid/getgrgid_r functions do not support domainlessgroups. If the calling application first makes a call to setauthdb("LDAP"), for example, getgrgid will only find LDAP-defined groups. It will not be able to find any group in the user's group set that is defined locally. This is known to affect recent versions of sudo. If an LDAP user belongs to a local group - and that local group is what is used to give this user sudo permissions - their sudo permisisons will not be granted.
Local fix
Problem summary
The getgrgid/getgrgid_r functions do not support domainlessgroups. If the calling application first makes a call to setauthdb("LDAP"), for example, getgrgid will only find LDAP-defined groups. It will not be able to find any group in the user's group set that is defined locally. This is known to affect recent versions of sudo. If an LDAP user belongs to a local group - and that local group is what is used to give this user sudo permissions - their sudo permisisons will not be granted.
Problem conclusion
The getgrgid/getgrgid_r functions now consider domainless groups even if the calling function has set the auth db.
Temporary fix
Comments
APAR Information
APAR number
IJ31131
Reported component name
AIX V7.2
Reported component ID
5765CD200
Reported release
720
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt / Xsystem
Submitted date
2021-03-02
Closed date
2021-07-06
Last modified date
2022-09-12
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.2
Fixed component ID
5765CD200
Applicable component levels
[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SG11S"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"720","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}}]
Document Information
Modified date:
12 September 2022