[SSSD-users] Re: sssd-1.16.1 loses POSIX group mapped from AD trusted domain

2018-04-11 Thread Jakub Hrozek
> On 11 Apr 2018, at 17:26, a.miroshniche...@rtk-dc.ru wrote: > > Hi, > > We have AD-trusted FreeIPA environment. > I installed sssd-1.16.1 on IPA servers and client hosts. > Posix user group "ad_app_admins" mapped to app-admins@ADTrustedDomain. > Sometimes AD user fails to login on hosts.

[SSSD-users] sssd-1.16.1 loses POSIX group mapped from AD trusted domain

2018-04-11 Thread a.miroshniche...@rtk-dc.ru
Hi, We have AD-trusted FreeIPA environment. I installed sssd-1.16.1 on IPA servers and client hosts. Posix user group "ad_app_admins" mapped to app-admins@ADTrustedDomain. Sometimes AD user fails to login on hosts. sssd can not see mapping. AD user groups show correct for user, but POSIX user

[SSSD-users] Re: unexpected owner for credentials

2018-04-11 Thread Sumit Bose
On Tue, Apr 10, 2018 at 05:21:26PM +, Charles Hedrick wrote: > Are there any performance issues with having lots of views? The number of views does not matter much because each host will only use the view assigned to it. But you only need multiple views if a single user currently has

[SSSD-users] Re: Config for joining AD forest and Kerberos cross-domain authentication

2018-04-11 Thread Sumit Bose
On Tue, Apr 10, 2018 at 06:57:15PM +0200, Bastian Rosner wrote: > Hi, > > I think I found the solution. After I realized that putting a .k5login file > into $HOME results in a working cross-domain Kerberos authentication, a > search on this ML revealed the following: > > Add this to krb5.conf: >