[SSSD-users] Announcing SSSD 1.11.5.1

2014-04-11 Thread Jakub Hrozek
=== SSSD 1.11.5.1 === The SSSD team is proud to announce the release of version 1.11.5.1 of the System Security Services Daemon. As always, the source is available from https://fedorahosted.org/sssd RPM packages will be made available for Fedora 19, 20 and rawhide shortly.

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Simo Sorce
On Fri, 2014-04-11 at 11:14 -0400, Stephen Gallagher wrote: > > Well, the major technical reason is that it would be a > backwards-incompatible change. Updating the SSSD and changing that > behavior could very easily mean suddenly locking a whole lot of people > out of their system. There's really

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 11:14:33AM -0400, Stephen Gallagher wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 04/11/2014 08:31 AM, Jakub Hrozek wrote: > > On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: > >> On 04/10/2014 04:20 PM, Jakub Hrozek wrote: > >>> Hi, > >>>

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/11/2014 08:31 AM, Jakub Hrozek wrote: > On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: >> On 04/10/2014 04:20 PM, Jakub Hrozek wrote: >>> Hi, >>> >>> our current HOWTO[1] on connecting SSSD to an AD DC is >>> outdated, mostly bec

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 01:22:54PM +0100, Rowland Penny wrote: > On 11/04/14 13:16, Jakub Hrozek wrote: > >On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: > >>OK, I take it all back, I am stupid ;-) > >> > >>Once I scanned the new logfile, it dawned on me what I had forgotten > >>to

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: > On 04/10/2014 04:20 PM, Jakub Hrozek wrote: > >Hi, > > > >our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > >mostly because the page still only introduces the LDAP provider. Recently, > >me, > >Sumit and Jeremy Agee

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 13:16, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: OK, I take it all back, I am stupid ;-) Once I scanned the new logfile, it dawned on me what I had forgotten to do, so I did it and now everything seems to be working ok. Oh, you want to know

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: > OK, I take it all back, I am stupid ;-) > > Once I scanned the new logfile, it dawned on me what I had forgotten > to do, so I did it and now everything seems to be working ok. > > Oh, you want to know what I forgot to do? > > I fo

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 12:41, Lukas Slebodnik wrote: On (11/04/14 12:03), Rowland Penny wrote: On 11/04/14 11:10, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 1

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Lukas Slebodnik
On (11/04/14 12:03), Rowland Penny wrote: >On 11/04/14 11:10, Jakub Hrozek wrote: >>On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: >>>On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: >On 10/04/14 22:53, Jakub Hrozek wrote:

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Pavel Březina
On 04/10/2014 04:20 PM, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises to use the AD provider and also use rea

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 11:10, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: > On 11/04/14 10:44, Jakub Hrozek wrote: > >On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: > >>On 10/04/14 22:53, Jakub Hrozek wrote: > >>>On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: > On 10/04/14

Re: [SSSD-users] enumeration not working

2014-04-11 Thread Jakub Hrozek
On Wed, Apr 09, 2014 at 02:56:42PM +0200, Angel Bosch wrote: > > Additionally please check if e.g. the user maquines is in all > > expected > > groups. If yes, then this messages might just be a side effect of > > enumeration. If SSSD tries to add a user to a group where it is > > already > > a mem

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: On 10/04/14 15:20, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: > On 10/04/14 22:53, Jakub Hrozek wrote: > >On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: > >>On 10/04/14 15:20, Jakub Hrozek wrote: > >>>Hi, > >>> > >>>our current HOWTO[1] on connecting SSSD to an AD DC is outdated, >

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: On 10/04/14 15:20, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Thu, Apr 10, 2014 at 07:13:56PM -0400, Bryan Harris wrote: > Hi Jakub, > > Hopefully I’m providing a decent discussion starting point. Is placing the > DC into resolv.conf the typical scenario? Or is it more that this is the > Microsoft-recommended way of doing things, full stop? > > For e