Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Sumit Bose
On Thu, Jul 30, 2015 at 05:35:53PM -0500, Dan Mossor wrote: > Greetings, folks. > > So, I've been fighting with getting a trust set up between FreeIPA 4.1 on > CentOS 7.1 and Windows Server 2008r2 for nearly a week. Today I finally came > to a conclusion as to what my issue is. > > I operate a se

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Dan Mossor
On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that currently FreeIPA does not have a global catalog, because Windows typically tries to get SIDs from remote objects from the Global Catalog. So, to

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Sumit Bose
On Fri, Jul 31, 2015 at 09:23:53AM -0500, Dan Mossor wrote: > On 07/31/2015 02:52 AM, Sumit Bose wrote: > > > >Thank you for the detailed analysis. I guess the 'server was > >inaccessible' error is due to the fact that currently FreeIPA does not > >have a global catalog, because Windows typically t

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Dan Mossor
On 07/31/2015 10:08 AM, Sumit Bose wrote: On Fri, Jul 31, 2015 at 09:23:53AM -0500, Dan Mossor wrote: On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that currently FreeIPA does not have a global cata

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-08-01 Thread Alexander Bokovoy
On Fri, 31 Jul 2015, Dan Mossor wrote: On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that currently FreeIPA does not have a global catalog, because Windows typically tries to get SIDs from remote obj

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-08-01 Thread Alexander Bokovoy
On Fri, 31 Jul 2015, Dan Mossor wrote: On 07/31/2015 10:08 AM, Sumit Bose wrote: On Fri, Jul 31, 2015 at 09:23:53AM -0500, Dan Mossor wrote: On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that curre