[SSSD-users] Am I blocked on sssd-users mailing list?

2018-07-19 Thread Spike White
All, I fear I may be blocked. I responded to an email thread, with an email that had two small attachments. That was wrong. I read the mailing list by-laws and I realize that was wrong. I will not repeat that offense. As the guidelines suggest, if I need to send logs I'll post somewhere

[SSSD-users] Re: problems with sssd-1.9

2018-07-19 Thread Laack, Andrea P
I used the files located here: https://copr-be.cloud.fedoraproject.org/results/sgallagh/sssd-1.9-rhel5/epel-5-x86_64/ Yes, libsss_ad.so is in the package. I used samba3x-3.6.23. Andrea -Original Message- From: Jakub Hrozek [mailto:jhro...@redhat.com] Sent: Thursday, July 19, 2018 4:04

[SSSD-users] Re: one user can't be looked up

2018-07-19 Thread Jakub Hrozek
> On 13 Jul 2018, at 00:16, Peter Moody wrote: > > On Wed, Jul 11, 2018 at 12:39 AM Jakub Hrozek wrote: >> >> On Tue, Jul 10, 2018 at 08:14:15PM -0700, Peter Moody wrote: >>> line breaks are in the original logs: >> >> Right, I saw this, but can I see more context earlier in the logs? See

[SSSD-users] Re: sss_override and ssh keys

2018-07-19 Thread Jakub Hrozek
> On 11 Jul 2018, at 15:28, John Hearns wrote: > > I have set up an sss_override for my user account > > johe:*:1234:1234:John Hearns,,,:/home/johe:/bin/bash > > I also have an entry in the locla /etc/passwd file. > When I ssh to a server running sssd my ssh key is accepted. > > When I have

[SSSD-users] Re: Missing group memberships with sssd (when using tokengroups)

2018-07-19 Thread Jakub Hrozek
> On 13 Jul 2018, at 17:40, Spike White wrote: > > Jakub, > > Thank you to answering so promptly. > > We are currently testing this in a lab before full deployment, so I have some > degree of time before we deploy sssd in a bigger context. If you would > prefer for me to work with you

[SSSD-users] Re: Problem with kinit

2018-07-19 Thread Jakub Hrozek
> On 16 Jul 2018, at 11:48, John Hearns wrote: > > I have had my head inside the ldap_child.c source code all morning. > I am getting these errors logged: > > [ldap_child_get_tgt_sync] (0x0100): Using keytab [MEMORY:/etc/krb5.keytab] > [ldap_child_get_tgt_sync] (0x0010): Failed to init

[SSSD-users] Re: problems with sssd-1.9

2018-07-19 Thread Jakub Hrozek
> On 18 Jul 2018, at 21:13, Laack, Andrea P wrote: > > I have been tasked with joining a number of redhat/centos 5 servers to a > domain. I found sssd-1.9 that would allow id_provider ad. This is Centos > 5.11. Well, the upstream 1.9 had the ad_provider bits, but they are not built by

[SSSD-users] sss_override and ssh keys

2018-07-19 Thread John Hearns
I have set up an sss_override for my user account johe:*:1234:1234:John Hearns,,,:/home/johe:/bin/bash I also have an entry in the locla /etc/passwd file. When I ssh to a server running sssd my ssh key is accepted. When I have no local /etc/passwd When I ssh to a server running sssd my ssh key

[SSSD-users] Problem with kinit

2018-07-19 Thread John Hearns
I have had my head inside the ldap_child.c source code all morning. I am getting these errors logged: [ldap_child_get_tgt_sync] (0x0100): Using keytab [MEMORY:/etc/krb5.keytab] [ldap_child_get_tgt_sync] (0x0010): Failed to init credentials: Client 'host/ i...@nzww.nzcorp.net' not found in

[SSSD-users] Re: problems with sssd-1.9

2018-07-19 Thread JOHE (John Hearns)
[domain\xxx.pvt] Is the backslash valid here? I am sure an expert will say yes.. You are well aware that RHEL 5 is out of support lifetime? I would imagine that you have some critical applications which run on these machines though. From: Laack, Andrea P