Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-28 Thread Jakub Hrozek
On Thu, Apr 24, 2014 at 12:46:46PM +, Longina Przybyszewska wrote: > Still, isn't it preferable to specify all domains in sssd.conf and use for > each, dns_discovery_domain to speed up lookups? I don't think so, because 1) you'd have to configure the domains on all clients and 2) You'd lose c

Re: [SSSD-users] [SSSD] New AD provider howto-proper krb5.conf in multidomain env

2014-04-24 Thread Longina Przybyszewska
7 To: 'End-user discussions about the System Security Services Daemon' Subject: Re: [SSSD-users] [SSSD] New AD provider howto Still, isn't it preferable to specify all domains in sssd.conf and use for each, dns_discovery_domain to speed up lookups? _ > Using ad provider in multi doma

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-24 Thread Longina Przybyszewska
Still, isn't it preferable to specify all domains in sssd.conf and use for each, dns_discovery_domain to speed up lookups? _ > Using ad provider in multi domain environment and Global Catalog search: > -do I still need the section for each subdomain in sssd.conf? Can I > configure sssd only f

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-16 Thread Timo Aaltonen
Subject: Re: [SSSD-users] [SSSD] New AD provider howto > > On Tue, Apr 15, 2014 at 10:42:42AM +, Longina Przybyszewska wrote: >> I think, it is worth to mention the 'msktutil' for joining AD; it is >> specially useful for installing a batch of computers, Is well do

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-16 Thread Pieter Baele
sssd-users-boun...@lists.fedorahosted.org [mailto: > sssd-users-boun...@lists.fedorahosted.org] On Behalf Of Jakub Hrozek > Sent: 15. april 2014 13:34 > To: sssd-users@lists.fedorahosted.org > Subject: Re: [SSSD-users] [SSSD] New AD provider howto > > On Tue, Apr 15, 2014 at 10:42:42AM +, Longin

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-16 Thread Longina Przybyszewska
-Original Message- From: sssd-users-boun...@lists.fedorahosted.org [mailto:sssd-users-boun...@lists.fedorahosted.org] On Behalf Of Jakub Hrozek Sent: 15. april 2014 13:34 To: sssd-users@lists.fedorahosted.org Subject: Re: [SSSD-users] [SSSD] New AD provider howto On Tue, Apr 15, 2014 at

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-15 Thread Jakub Hrozek
On Tue, Apr 15, 2014 at 10:42:42AM +, Longina Przybyszewska wrote: > I think, it is worth to mention the 'msktutil' for joining AD; it is > specially useful for installing a batch of computers, > Is well documented with a lot of options. It lets to join domain independent > from samba, with f

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-15 Thread Longina Przybyszewska
. april 2014 11:00 To: End-user discussions about the System Security Services Daemon Subject: Re: [SSSD-users] [SSSD] New AD provider howto One minor thing (not sure if worth mentioning): When installing IDMU on windows server, it is quite useful to stop& disable the "server for NIS"

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-14 Thread Ondrej Valousek
NIS). Ondrej From: sssd-users-boun...@lists.fedorahosted.org [sssd-users-boun...@lists.fedorahosted.org] on behalf of Simo Sorce [s...@redhat.com] Sent: Friday, April 11, 2014 6:09 PM To: End-user discussions about the System Security Services Daemon Subject: Re: [SSSD-users] [SSSD] N

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Simo Sorce
On Fri, 2014-04-11 at 11:14 -0400, Stephen Gallagher wrote: > > Well, the major technical reason is that it would be a > backwards-incompatible change. Updating the SSSD and changing that > behavior could very easily mean suddenly locking a whole lot of people > out of their system. There's really

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 11:14:33AM -0400, Stephen Gallagher wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 04/11/2014 08:31 AM, Jakub Hrozek wrote: > > On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: > >> On 04/10/2014 04:20 PM, Jakub Hrozek wrote: > >>> Hi, > >>>

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/11/2014 08:31 AM, Jakub Hrozek wrote: > On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: >> On 04/10/2014 04:20 PM, Jakub Hrozek wrote: >>> Hi, >>> >>> our current HOWTO[1] on connecting SSSD to an AD DC is >>> outdated, mostly bec

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 01:11:40PM +0200, Pavel Březina wrote: > On 04/10/2014 04:20 PM, Jakub Hrozek wrote: > >Hi, > > > >our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > >mostly because the page still only introduces the LDAP provider. Recently, > >me, > >Sumit and Jeremy Agee

Re: [SSSD-users] [SSSD] New AD provider howto

2014-04-11 Thread Pavel Březina
On 04/10/2014 04:20 PM, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises to use the AD provider and also use rea