Jira (PUP-9604) Group resource (with auth_membership) fails if local Windows group contains not resolvable Domain accounts (possible regression)

3 views
Skip to first unread message

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:31:02 PM4/4/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
 
Puppet / Bug PUP-9604
Group resource (with auth_membership) fails if local Windows group contains not resolvable Domain accounts (possible regression)
Change By: Halim Wijaya
Summary: Group resource (with auth_membership) fails if local Windows group contains not resolvable Domain accounts (possible regression )
Add Comment Add Comment
 
This message was sent by Atlassian JIRA (v7.7.1#77002-sha1:e75ca93)
Atlassian logo

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:41:02 PM4/4/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
* Puppet Version: * This is spin-off ticket of PUP-7326.
*Puppet Server Version:*
*
OS Name/Version Steps to reproduce :*
# Setup Active Directory with Domain Functional level 2016
Describe your issue # Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1)
in as much detail as possible… Active Directory
Describe steps # Add testadmin1 user to reproduce… local administrators group in Win2012R2
# Delete testadmin1 user in AD
*Desired Behavior # Run
{code
: * java}

*Actual Behavior
puppet apply -e "group {'Administrators' : * members => ['Administrator'], auth_membership => true }"{code}

Please take Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up
a moment Win2016 machine and attach any relevant log output and/or manifests connect to AD
# Create a test user (e
. This will help us immensely when troubleshooting the issue q . testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2016
Examples: # Delete testadmin1 user in AD
# Run puppet agent with --test --trace --debug
{code:java}
Relevant sections of puppet apply -e "group { 'Administrators': members => ['Administrator'], auth_membership => true } { /var/log/puppetlabs/puppetserver/puppetserver.log code } } or any applicable logs from the same directory

Puppet apply returns error below

!Screen Shot 2019-04-03 at 11
. 44.28 AM.png!

For more detailed information turn up Note the server logs by upping error occurs only on Windows client machine with condition its OS version is different with the log AD Domain Functional level in the server's logback . xml

Relevant sections of configurations files (puppet
E . conf, hiera q . conf, Server's conf Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2 . d, defaults/sysconfig)

For memory issues with server heap dumps are also helpful.  

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:42:02 PM4/4/19
to puppe...@googlegroups.com

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:42:04 PM4/4/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
**This is spin-off ticket of PUP-7326.

*Steps to reproduce:*

# Setup Active Directory with Domain Functional level 2016
# Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2012R2

# Delete testadmin1 user in AD
# Run
{code:java}

puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }"{code}


Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up a Win2016 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory

# Add testadmin1 user to local administrators group in Win2016
# Delete testadmin1 user in AD
# Run
{code:java}
puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }{code}


Puppet apply returns error below

! Screen Shot image- 2019-04- 03 at 11 05-10-41-13-985 . 44.28 AM. png!

Note the error occurs only on Windows client machine with condition its OS version is different with the AD Domain Functional level. E.q. Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2.

 

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:43:02 PM4/4/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
**This is spin-off ticket of PUP-7326.

*Steps to reproduce:*
# Setup Active Directory with Domain Functional level 2016
# Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2012R2
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }"{code}

Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up a Win2016 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2016
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }{code}

Puppet apply returns error below

!image- 2019-04-05-10-41- 13-985.png!


Note the error occurs only on Windows client machine with condition its OS version is different with the AD Domain Functional level. E.q. Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2.

 

Halim Wijaya (JIRA)

unread,
Apr 4, 2019, 10:45:02 PM4/4/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
**This is spin-off ticket of PUP-7326.

*Steps to reproduce:*
# Setup Active Directory with Domain Functional level 2016
# Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2012R2
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }"{code}

Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up a Win2016 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2016
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }{code}

Puppet apply returns error below

!image- 2019-04-05-10-41- 13-985.png |thumbnail !


Note the error occurs only on Windows client machine with condition its OS version is different with the AD Domain Functional level. E.q. Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2.

 

Halim Wijaya (JIRA)

unread,
Apr 5, 2019, 4:36:01 AM4/5/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
Change By: Halim Wijaya
CS Priority: Needs Priority
**This is spin-off ticket of PUP-7326.

*Steps to reproduce:*
# Setup Active Directory with Domain Functional level 2016
# Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2012R2
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }"{code}

Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up a Win2016 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2016
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }{code}

Puppet apply returns error below

!image-
2019-04-05-10-41- 13-985.png|thumbnail!

Note the error occurs only on Windows client machine with condition its OS version is different with the AD Domain Functional level. E.q. Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2.

 
Add Comment Add Comment
 

Halim Wijaya (JIRA)

unread,
Apr 5, 2019, 4:36:02 AM4/5/19
to puppe...@googlegroups.com
Halim Wijaya updated an issue
**This is spin-off ticket of PUP-7326.

*Steps to reproduce:*
# Setup Active Directory with Domain Functional level 2016
# Spin up a Win2012R2 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2012R2
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }"{code}

Or
# Setup Active Directory with Domain Functional level 2012 R2
# Spin up a Win2016 machine and connect to AD
# Create a test user (e.q. testadmin1) in Active Directory
# Add testadmin1 user to local administrators group in Win2016
# Delete testadmin1 user in AD
# Run
{code:java}puppet apply -e "group {'Administrators': members => ['Administrator'], auth_membership => true }{code}

Puppet apply returns error below

!image-
2019-04-05-10-41- 13-985.png|thumbnail!

Note the error occurs only on Windows client machine with condition its OS version is different with the AD Domain Functional level. E.q. Client OS Win2012R connected to AD Domain Functional level 2016 or Client OS Win2016 connected to AD Domain Functional level 2012R2.

 
Add Comment Add Comment
 

Halim Wijaya (JIRA)

unread,
Apr 5, 2019, 4:36:02 AM4/5/19
to puppe...@googlegroups.com

Jorie Tappa (JIRA)

unread,
Apr 8, 2019, 12:47:03 PM4/8/19
to puppe...@googlegroups.com

Jorie Tappa (JIRA)

unread,
Apr 8, 2019, 12:48:03 PM4/8/19
to puppe...@googlegroups.com

Jarret Lavallee (JIRA)

unread,
Apr 11, 2019, 7:14:02 PM4/11/19
to puppe...@googlegroups.com

Adam Bottchen (JIRA)

unread,
Apr 11, 2019, 7:19:03 PM4/11/19
to puppe...@googlegroups.com

Usatenko Andrii (JIRA)

unread,
Oct 22, 2019, 9:29:03 AM10/22/19
to puppe...@googlegroups.com
Usatenko Andrii commented on Bug PUP-9604
 
Re: Group resource (with auth_membership) fails if local Windows group contains not resolvable Domain accounts (possible regression)

JANELLE JAMES Hi. You changed the status of this ticket to 'needs information'. We are experiencing this issue and I think i can provide all required information.

Austin Boyd (JIRA)

unread,
Dec 12, 2019, 9:08:11 AM12/12/19
to puppe...@googlegroups.com

Josh Cooper (Jira)

unread,
Mar 31, 2020, 11:49:03 PM3/31/20
to puppe...@googlegroups.com
Josh Cooper updated an issue
Change By: Josh Cooper
Team: Windows Night's Watch
This message was sent by Atlassian Jira (v8.5.2#805002-sha1:a66f935)
Atlassian logo
Reply all
Reply to author
Forward
0 new messages