[SSSD-users] Re: Intermittent SSH authentication failures: SSSD+AD+PAM+Duo

2019-01-17 Thread Sumit Bose
On Thu, Jan 17, 2019 at 09:27:19PM -, Jordan Castillo wrote: > Hi Sumit, > > The server was running samba-client-libs-4.6.2-12. I did a yum update on > samba-client-libs, samba-common-tools, samba-common, samba-common-libs, and > samba-libs. Now it is running running 4.8.3-4 for all of

[SSSD-users] Re: Sssd and gidNumber

2019-01-17 Thread Dmitrij S. Kryzhevich
> I would start with comparing logs for a 'working' and a 'non-working' > client. The config looks OK to me and in general the plain LDAP provider > should only ever generate the gidNumber value if > ldap_auto_private_groups is set to True > Thanks for answer! There was a local user with same

[SSSD-users] Re: Simplify ldap `memberOf` searches

2019-01-17 Thread Sean Roberts
Thanks. For the LDAP provider, what did you mean by matched with a substring search? A wildcard? -- Sean Roberts On Thu, Jan 17, 2019 at 1:29 PM Jakub Hrozek wrote: > On Tue, Jan 15, 2019 at 07:32:34AM -0700, Sean Roberts wrote: > > SSSD experts - Is it possible to simplify ldap searches

[SSSD-users] Re: Intermittent SSH authentication failures: SSSD+AD+PAM+Duo

2019-01-17 Thread Jordan Castillo
Hi Sumit, The server was running samba-client-libs-4.6.2-12. I did a yum update on samba-client-libs, samba-common-tools, samba-common, samba-common-libs, and samba-libs. Now it is running running 4.8.3-4 for all of those packages and I can no longer reproduce the issue. It appears to be

[SSSD-users] Re: Sssd and gidNumber

2019-01-17 Thread Jakub Hrozek
On Wed, Jan 16, 2019 at 05:33:41AM -, Dmitrij S. Kryzhevich wrote: > I have setup with 3 clients and server. Server runs samba as AD and ldap + > kerberos. Clients use sss: 1) fedora with 2.0.0, 2) centos with 1.16.0 and 3) > centos with 1.16.2. All clients use 1:1 sssd.conf. I want sss to

[SSSD-users] Re: Intermittent SSH authentication failures: SSSD+AD+PAM+Duo

2019-01-17 Thread Sumit Bose
On Thu, Jan 17, 2019 at 05:52:57PM -, Jordan Castillo wrote: > Hi Sumit, > Thanks for your response. I am running CentOS 7.4.1708 and installed sssd via > yum. I have sssd-1.16.2-13.el7.x86_64 currently installed. None of the > libraries mentioned are showing available updates. Here are the

[SSSD-users] Re: SSSD with Kerberos for SPENGO ( Nginx + pam + sss + sss_krb )

2019-01-17 Thread Sumit Bose
On Thu, Jan 17, 2019 at 09:01:53AM +0100, Eugen Mayer wrote: > Hello Sumit, > > thank you! I was aware of that nginx module but was striving to get PAM + > SSSD for a more robust, maintained solution - so i did not yet test it. > > TL;dr i tested it with the spengo module and it works without

[SSSD-users] Re: SSSD with Kerberos for SPENGO ( Nginx + pam + sss + sss_krb )

2019-01-17 Thread Eugen Mayer
Hello Sumit, thank you! I was aware of that nginx module but was striving to get PAM + SSSD for a more robust, maintained solution - so i did not yet test it. TL;dr i tested it with the spengo module and it works without issues - so that one at least. Now my question, as far as i understad