[Freeipa-users] AD Trust users not resolving on clients: ipa_get_*_acct request failed

2016-11-22 Thread Robert Sturrock
Hi All. I’m having a problem getting trust users to resolve on *any* IPA client (this _was_ working well and I’m not sure what’s changed that may have caused it to start failing - although we have recently updated to IPA 4.4, plus IPA DNS enabled with delegation of ipa.example.com). Whenever I

Re: [Freeipa-users] IPA-AD trust group membership: display 'short' group names for *two* AD domains?

2016-10-20 Thread Robert Sturrock
> On Thu, Oct 20, 2016 at 04:46:01PM +1100, Robert Sturrock wrote: > […] > > However, when I try logging in as a student domain user > > (student.example.au), > > I don't see any of the groups (there should be 8): > > > > $ ssh -l rnst student

[Freeipa-users] IPA-AD trust group membership: display 'short' group names for *two* AD domains?

2016-10-19 Thread Robert Sturrock
Hello, We have an IPA (4.2) server setup on RHEL 7.2 in a trust arrangement with our University organisational AD. The AD forest contains *two* domains: EXAMPLE.AU (staff users) STUDENT.EXAMPLE.AU (student users) The IPA domain that trusts these is called: IPA.EXAMPLE.AU The basic confi

[Freeipa-users] External (AD) groups and sudo/hbac in IPA 4.2

2016-10-11 Thread Robert Sturrock
Hi All. We’re attempting to setup an IPA (4.2) service on RHEL7.2 to provide better connectivity to our (large) organisational AD service for Linux clients. We have setup IPA and configured a suitable AD trust (with SID POSIX mapping) in the hope that users will be able to access IPA resources