On Fri, 2012-05-11 at 09:10 +0200, Jan Zelený wrote: > > On Fri, 2012-05-11 at 08:38 +0200, Jan Zelený wrote: > > > I guess SSSD cache is probably the reason why you still have the old GID. > > > Try running sss_cache -G to invalidate all groups and if you have > > > queried SSSD for that group in last few minutes, wait for the client > > > in-memory cache to expire as well (or you can just restart SSSD). > > > > Sounds promising... but I tried that (as well as -U and -N), restarted > > sssd, logged out and logged back in... and still the user appears to be > > a member of pulse-access (rather than mock). > > And when you run getent group mock, the GID is correct or still wrong?
$ getent group mock mock:x:989: That's correct (that is, it's consistent with that's in LDAP); but it was correct before, too. -- Braden McDaniel <bra...@endoframe.com> _______________________________________________ sssd-devel mailing list sssd-devel@lists.fedorahosted.org https://fedorahosted.org/mailman/listinfo/sssd-devel