[SSSD-users] Re: How to keep the password in sync with AD?

2019-02-05 Thread Ian Puleston
Thanks for the suggestion Sumit. Your kinit command gave this output: kinit: Pre-authentication failed: Permission denied while getting initial credentials I wasn't sure if I should run that direct from my domain user account or with su privilege, so tried the same with sudo and that gave: kin

[SSSD-users] Re: SSSD : id don't display groups name subdomain (Child trust)

2019-02-05 Thread Martial CHAVIGNY
Thank for your reply, Yes, it's working :) Answer is below, On Tue, Feb 05, 2019 at 08:52:27AM +, Martial CHAVIGNY wrote: > Hi everyone, > > In dev environnement, with SSSD 1.16.2 (release 13.el7_6.5) on RHEL > 7.6 > > SSSD is configured to request on mch.dev domain. trusted subdomain > s

[SSSD-users] Re: AD multiple domains - login failed for child domain

2019-02-05 Thread Jeremy Monnet
On Tue, Feb 5, 2019 at 3:35 PM Jeremy Monnet wrote: > > Hello, > > On Tue, Feb 5, 2019 at 10:29 AM Jakub Hrozek wrote: > > > > > Now, everything is OK with the main domain, AFAIK, I can login, sudo > > > based on groups, etc. But for the child domain, most work, I can id a > > > user@child (that

[SSSD-users] Re: AD multiple domains - login failed for child domain

2019-02-05 Thread Jeremy Monnet
Hello, On Tue, Feb 5, 2019 at 10:29 AM Jakub Hrozek wrote: > > > Now, everything is OK with the main domain, AFAIK, I can login, sudo > > based on groups, etc. But for the child domain, most work, I can id a > > user@child (that resolves the user and the groups associated), I can > > "su - user@c

[SSSD-users] Re: SSSD : id don't display groups name subdomain (Child trust)

2019-02-05 Thread Jakub Hrozek
On Tue, Feb 05, 2019 at 08:52:27AM +, Martial CHAVIGNY wrote: > Hi everyone, > > In dev environnement, with SSSD 1.16.2 (release 13.el7_6.5) on RHEL 7.6 > > SSSD is configured to request on mch.dev domain. trusted subdomain > sub.mch.dev exist (Win2k16) > > On mch.dev, I have an user 'user1

[SSSD-users] Re: Best practice, experience with NIS => AD migrations?

2019-02-05 Thread Jakub Hrozek
On Mon, Feb 04, 2019 at 03:19:27PM -0600, Spike White wrote: > Sssd practitioners, > > (I hope this topic is not inappropriate to this target audience.) > > My company is looking at retiring NIS, in favor of AD. Altogether, there > are several thousand Linux servers (& a few UNIX servers) gettin

[SSSD-users] Re: Cannot use smart card auth on Ubuntu 18.04

2019-02-05 Thread Jakub Hrozek
On Fri, Feb 01, 2019 at 02:20:21PM -0700, Orion Poplawski wrote: > I'm not having any luck using smart card auth on an IPA joined Ubuntu 18.04 > system. It appears that pam is not properly configured, and in particular I > don't see "allow_missing_name" in use: > > /etc/pam.d/common-auth: > auth

[SSSD-users] SSSD : id don't display groups name subdomain (Child trust)

2019-02-05 Thread Martial CHAVIGNY
Hi everyone, In dev environnement, with SSSD 1.16.2 (release 13.el7_6.5) on RHEL 7.6 SSSD is configured to request on mch.dev domain. trusted subdomain sub.mch.dev exist (Win2k16) On mch.dev, I have an user 'user1' in Universal groups 'G_TEST' and 'allowed_ssh'. These groups are placed also in

[SSSD-users] Re: AD multiple domains - login failed for child domain

2019-02-05 Thread Jakub Hrozek
On Thu, Jan 31, 2019 at 04:27:02PM +0100, Jeremy Monnet wrote: > Hello, > > I never fixed issues I had last year > https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org/thread/5XUJLUVI5JZILZKDK5DRHK7PSQNIZZBD/ > but I did made a new test on a brand new ubuntu up to date, a