Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
None
-
1
-
Platform Client 2014-11-26, Platform Client 2015-01-07, Platform Client 2015-01-21
Description
The auth_membership group parameter controls whether puppet ensures the group contains exactly the members specified, and no more, or contains at least the members specified. By default, the group parameter defaults to the former, which is opposite to the auth_membership user parameter. This makes the group parameter difficult to use in practice, because you need to know what the complete set of group members should be. For example, on Windows the local Administrators group may contain a combination of local and domain user/group accounts, and that may vary across different types of machines.
We should change the auth_membership group parameter to default to false so that it is consistent with the user parameter.
Attachments
Issue Links
- blocks
-
ENTERPRISE-182 Ability to add a member to a group, instead of specifying the complete list
-
- Closed
-
- relates to
-
PUP-2628 Ability to add a member to a group, instead of specifying the complete list
-
- Closed
-
-
PUP-3653 Unable to create/force empty Windows groups
-
- Closed
-
-
PUP-6542 Group resource emits misleading change notification with auth_membership => false
-
- Closed
-
-
PUP-3883 Support for user resource with a DOMAIN\User title
-
- Closed
-
- links to