[SSSD-users] Re: All numeric User ID in the Kerberos Provider

2017-01-11 Thread Ondrej Valousek
". If we configure SSSD to use Active Directory for the Auth Provider, then we will end up with the All-number Usernames on Linux." This is not true. It is completely fine if Unix username != Kerberos principal. O. -Original Message- From: Ali, Saqib [mailto:docbook@gmail.com] Sent:

[SSSD-users] Re: AD forest short name lookup

2017-01-11 Thread Mike Smorul
> > > > *Other notes:* > > - We attempted to use the setup described here > > https://lists.fedorahosted.org/pipermail/sssd-users/2015- > February/002648.html, > > however clients attempt to authenticate to each domain and fail as they > are > > only joined to b.site.com. > > This should work as lo

[SSSD-users] All numeric User ID in the Kerberos Provider

2017-01-11 Thread Ali, Saqib
Hello all, The kerberos provider (Active Directory) in our environments uses all numeric username. If we configure SSSD to use Active Directory for the Auth Provider, then we will end up with the All-number Usernames on Linux. What are our options? Note: We are using the Oracle Directory Server

[SSSD-users] Re: AD forest short name lookup

2017-01-11 Thread Jakub Hrozek
On Wed, Jan 11, 2017 at 11:44:18AM -0500, Mike Smorul wrote: > Hi, > We're having an issue getting sssd to lookup non-qualified names across > our forest. From the documentation it appears this should be supported via > lookups done to the global catalog or failing that, queries against all > disc

[SSSD-users] AD forest short name lookup

2017-01-11 Thread Mike Smorul
Hi, We're having an issue getting sssd to lookup non-qualified names across our forest. From the documentation it appears this should be supported via lookups done to the global catalog or failing that, queries against all discovered subdomains. *Setup:* - Two domains, site.com and b.site.com. -