[Freeipa-users] FreeIPA Client <--> AD / Kerberos

2022-07-19 Thread Ronald Wimmer via FreeIPA-users
In which scenarios do I need IPA clients to be able to connect to Windows AD DCs directly (Kerberos 44/464 TCP/UDP)? I thought it was needed for passwordless logins because

[Freeipa-users] FreeIPA Client AD Trust user look-up latencies and results

2019-04-22 Thread John Desantis via FreeIPA-users
Hello all, I've pretty much exhausted my searching in order to find a solution to a problem I've been working on for about a week now, and now I find myself grasping at straws. Basically, AD trust user lookups on IPA clients fail several times in a row before finally returning results (after

[Freeipa-users] FreeIPA and AD

2019-03-07 Thread Kristian Petersen via FreeIPA-users
Hello, Where I work we are a small shop. We are currently using just FreeIPA for authentication and DNS and other Linux management stuff that it does for us. We have enough Windows workstations now that it would be really nice to be able to manage those like we can our Linux stuff. From what I

[Freeipa-users] FreeIPA and AD

2018-09-12 Thread Ryan via FreeIPA-users
. After much reading its not as simple as it might sound. In saying that, my question is simple. How or what would be the best way to keep the AD users and FreeIPA users in sync. All I am really looking for is to Auth Users on the new Samba4 AD server. Can this be done or not. Am I going to have

[Freeipa-users] FreeIPA and AD trust

2018-02-06 Thread Nathan Harper via FreeIPA-users
Hi, Clearly my Google skills are lacking, as I've not been able to find anything definitive (mainly just old versions of IPA) We have a well used FreeIPA domain, but I have a few appliances and applications that require Active Directory. I can find information about configuring AD to trust

[Freeipa-users] FreeIPA and AD Trust - macOS cannot see AD trust users

2017-07-09 Thread Louis Abel via FreeIPA-users
Hello! I created a FreeIPA (ipa.angelsofclockwork.net) and Active Directory (ad.angelsofclockwork.net) and put them into a two way trust with posix. I used these commands: ipa-adtrust-install --enable-compat --add-agents ipa trust-add --type=ad ad.angelsofclockwork.net --admin lmabel