[SSSD-users] Re: ldap client configuration in sssd.conf to query views

2021-08-20 Thread iulian roman
Hi, The sssd client is 1.9.4 (SUSE Linux Enterprise Server 11) , but there is not sssd-ipa package, therefore I need to configure ldap provider in sssd.conf. I checked that link before, but I think the views subtree is no longer accessible with anonymous bind, therefore I need somehow to authen

[SSSD-users] ldap client configuration in sssd.conf to query views

2021-08-19 Thread iulian roman
Hello, I try to configure some old sssd clients to connect to IPA server which does use AD and views. Is there any documentation which points which ldap_* related variables needs to be configured in sssd,conf in order to be able to query the views in IPA server ? Currently I can run ldapsear

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-22 Thread iulian roman
quick update regarding the GID override. If I override the GID (and the group name does not exist in AD for that GID) , I can make the sssd client (both versions) work ONLY if i run manually getent group . I cannot do that for hundred of users and thousand of servers (especially when the infr

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-22 Thread iulian roman
Hi Summit, Initially I tried to override both the uid and gid of the active directory users in the Default Trust View. Due to the fact that I did not have a group name for the GID in Active Directory I had to remove the GID override . All works properly with sssd client version 1.16.1 and sss

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-18 Thread iulian roman
> Am Fri, Jun 18, 2021 at 01:16:30PM - schrieb iulian roman: > > Hi, > > if you do not want to send them here, feel free to send them to me > directly. > Hi Sumit, I have sent the logs to your email. They were quite big to attach here. > bye, >

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-18 Thread iulian roman
Where can I upload the logs? ___ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ L

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-18 Thread iulian roman
I forgot to mention that on the Idm Server (version 4.8.7) and sssd 2.4.0 the getent and id queries work, not matter how and what I override in the Default Trust View. ___ sssd-users mailing list -- sssd-users@lists.fedorahosted.org To unsubscribe send

[SSSD-users] Re: sssd issues with Idm Trust View

2021-06-18 Thread iulian roman
Hi Sumit, Thank you for the answer. The same setup works without issues on all Ubuntu 18.04 systems with sssd 1.16.1. I overwrite only the UID and the primary gid is generated automatically by IPA (a long number). The problem is with the Ubuntu 20 and sssd 2.2.3 , therefore I cannot enrol any

[SSSD-users] sssd issues with Idm Trust View

2021-06-17 Thread iulian roman
Hello everybody, I have an issue with listing the AD users part of Default Trust View (all users have the uid overriden ) from an ipa client which is running sssd 2.2.3. The same setup works properly on Ubuntu systems with sssd 1.16.1 and Idm servers with sssd version 2.4.0. I have enabled

[SSSD-users] sssd issues with Idm Trust View

2021-06-17 Thread iulian roman
Hello everybody, I have an issue with listing the AD users part of Default Trust View (all users have the uid overriden ) from an ipa client which is running sssd 2.2.3. The same setup works properly on Ubuntu systems with sssd 1.16.1 and Idm servers with sssd version 2.4.0. I have enabled