Search the docs

REST API Reference

Resource Method Description Response Codes

/name-services/

GET

List all configured name services in resolution order.

200

/name-services/<identifier>

GET

Get a configured name service by UUID, internal ID, or name.

200, 404

/name-services/

POST

Add a new LDAP name service. The connection test runs unless the query parameter skipConnectionTest=true is given, in which case ldapTransport and a port on every network endpoint are required.

200, 400, 409

/name-services/<identifier>

PUT

Update a configured LDAP name service. Accepts skipConnectionTest=true, as for POST.

200, 400, 404, 409

/name-services/<identifier>

DELETE

Remove a configured name service.

204, 404

/name-services/reorder

PUT

Change the resolution order. The body is the list of name services in the new order.

200, 400

/name-services/resolveUser?user-identifier=<user>

GET

Look up a user. Returns one entry per domain searched, each with an sssdQueryResult whose status is SUCCESS, NOT_FOUND, or FAILURE.

200, 400

/name-services/resolveGroup?group-identifier=<group>

GET

Look up a group. Results as for resolveUser.

200, 400

/name-services/resolveUserGroups?user-groups-identifier=<user>

GET

List the groups a user belongs to. Results as for resolveUser.

200, 400

/name-services/connectionTest

POST

Test connectivity for a list of name services without saving them. They do not need to be configured. Returns 400 if every test fails; if only some fail, returns 200 with the header X-Partial-Success: true and the errors in each returned entry. In 5.3, include at most one name service that is not yet configured in each request.

200, 400

A lookup of a name that does not exist returns 200, with NOT_FOUND in the result for each domain. A qualified name whose domain is not configured, or a lookup when no name service is configured, returns 400.

When an add or update succeeds after some connection attempts failed, the response is 200 with X-Partial-Success: true, and the returned name service lists the failed attempts in errors and the successful one in successMessage.

Enumerated values in request bodies, such as ldapTransport and ldapSchema, are case-sensitive in 5.3. Use LDAP, LDAPS, or STARTTLS, and RFC2307 or RFC2307BIS.