I have several linux machines that use PowerBroker Open to authenticate users against AD.
I've noticed that for some users it works just fine (authentication and all), but for others it does not (authentication obviously not due to the required membership stated below, but even groups 'username' only shows one group, domain^users - even when the user is in many groups).
I've narrowed it down that auth and group listing works fine for all users who are in the group which was given in the
/opt/pbis/bin/config RequireMembershipOf command.
I've further found that doing
/opt/pbis/bin/enum-groups --level 1 fixes the problem until next reboot (as opposed to
--level 0, the default, level 1 also shows the group memberships).
But it leaves me with a few questions I'm struggling to find an answer for:
How can I make this behavior persist without doing regular enum-groups commands?
What exactly is going on that makes this fix work, and what exactly did it fix?
This is on RJEL 6.7, pbis-open 8.2.1-2979.