It was a clean install of 4.0.1(not 4.0.3, I was wrong). I have upgraded to 4.1 and have not yet seen the problem recur - though I have not tested it much yet. On Oct 24, 2014 12:53 AM, "Jakub Hrozek" <jhro...@redhat.com> wrote:
> On Thu, Oct 23, 2014 at 05:19:38PM -0700, Michael Lasevich wrote: > > Small update, it appears that once I run "getent group <groupname>" - my > > user shows up in the group <groupname>. Odd. > > > > (and yes, I have ran "sss_cache -UG" many a time) > > > > -M > > One particular change in IPA 4.x that might be giving old clients > headache is the new permission system. Only clean installs or replicas > of 6.6 (or newer) servers are guaranteed to work with old clients. > > How was your IPA 4.0.3 server installed? What is the 389-ds-base version > you're running? > > Any chance you can try a newer SSSD on your CentOS6 client? I have a > COPR repo with the latest 1.11 branch here: > http://copr-fe.cloud.fedoraproject.org/coprs/jhrozek/SSSD-1.11-RHEL6/ > > -- > Manage your subscription for the Freeipa-users mailing list: > https://www.redhat.com/mailman/listinfo/freeipa-users > Go To http://freeipa.org for more info on the project >
-- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project