On 17/10/2016 11:14, Alexander Bokovoy wrote:
We are not yet at the point you could use IPA-hosted identities to login
to Windows machines joined to AD, though, regardless which AD
implementation it is.

That's very helpful, thank you. So basically it means that for the time being, our admins will need two identities (one in each realm) and there is not much benefit in setting up cross-realm trust.

Would there be any benefit the other way round - creating identities in S4 and using them to login to FreeIPA-joined *nix boxes? I guess the problem then is where posix attributes like uid and gid come from.

Regards,

Brian.

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to