[SSSD-users] Re: 'no primary group ID provided' when trying to use ldap mode against AD

2016-09-01 Thread Jakub Hrozek
On Thu, Sep 01, 2016 at 10:13:01AM +0100, John Hodrien wrote: > On Mon, 29 Aug 2016, Jakub Hrozek wrote: > > > btw one more remark. Even if you can't join the client to AD and have to > > resort to id_provider=ldap there is nothing preventing you from using: > >auth_provider=krb5 > > at least

[SSSD-users] Re: 'no primary group ID provided' when trying to use ldap mode against AD

2016-09-01 Thread John Hodrien
On Mon, 29 Aug 2016, Jakub Hrozek wrote: btw one more remark. Even if you can't join the client to AD and have to resort to id_provider=ldap there is nothing preventing you from using: auth_provider=krb5 at least as long as the KDC is reachable.. Although without a system keytab (typically