Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-1022: Getent group <GroupName> only returns a partial list of AD user

Centrify DirectAudit ,   Centrify DirectControl ,   Centrify Identity Service, Mac Edition ,  

12 April,16 at 11:13 AM

Applies to: All versions of Centrify DirectControl for UNIX/Linux on Solaris

Question:

It is observed that "getent group <GroupName>" returns only a partial list of Active Directory (AD) users.

For example, there are 1,000 AD users in AD group Testgroup. Running "getent group Testgroup" only returns a partial list of users.

bash-3.00# getent group Testgroup
Testgroup:x:1000:jack,mary,apple,amazon,


Answer:

There is a 1024 char buffer limit on some versions of Solaris. Some versions of Solaris, such as Solaris 10, have increased the buffer size to 8096.

The workaround is to set "nss.split.group.membership: false" in /etc/centrifydc/centrifydc.conf and then run adreload.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.