Re: [SSSD-users] New AD provider howto

2014-05-21 Thread Marko Myllynen
Hi, this went unanswered so ... On 2014-04-17 14:16, Marko Myllynen wrote: > On 2014-04-17 13:18, Jakub Hrozek wrote: >> On Thu, Apr 17, 2014 at 09:05:42AM +0300, Marko Myllynen wrote: >> >>> - for completeness sake I'd add dns_lookup_kdc = true and master_kdc = >>> server.ad.example.com to the k

Re: [SSSD-users] New AD provider howto

2014-04-25 Thread steve
On Fri, 2014-04-25 at 10:08 +0100, John Hodrien wrote: > On Fri, 25 Apr 2014, steve wrote: > > > On Thu, 2014-04-24 at 16:33 -0400, Jeremy Agee wrote: > >> On 04/23/2014 05:25 AM, John Hodrien wrote: > >> > > >> > This is a guide for setting up against AD. Is there *any* realistic > >> > circumst

Re: [SSSD-users] New AD provider howto

2014-04-25 Thread John Hodrien
On Fri, 25 Apr 2014, steve wrote: On Thu, 2014-04-24 at 16:33 -0400, Jeremy Agee wrote: On 04/23/2014 05:25 AM, John Hodrien wrote: > > This is a guide for setting up against AD. Is there *any* realistic > circumstance where SHORTNAME$@REALM won't be available? If someone was creating the ke

Re: [SSSD-users] New AD provider howto

2014-04-25 Thread steve
On Thu, 2014-04-24 at 16:33 -0400, Jeremy Agee wrote: > On 04/23/2014 05:25 AM, John Hodrien wrote: > > On Thu, 10 Apr 2014, Jakub Hrozek wrote: > > > >> our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > >> mostly because the page still only introduces the LDAP provider. > >> Rece

Re: [SSSD-users] New AD provider howto

2014-04-24 Thread Jeremy Agee
On 04/23/2014 05:25 AM, John Hodrien wrote: On Thu, 10 Apr 2014, Jakub Hrozek wrote: our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises

Re: [SSSD-users] New AD provider howto

2014-04-23 Thread John Hodrien
On Thu, 10 Apr 2014, Jakub Hrozek wrote: our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises to use the AD provider and also use realmd for

Re: [SSSD-users] New AD provider howto

2014-04-23 Thread Marko Myllynen
Hi, On 2014-04-17 13:18, Jakub Hrozek wrote: > On Thu, Apr 17, 2014 at 09:05:42AM +0300, Marko Myllynen wrote: > >> - for completeness sake I'd add dns_lookup_kdc = true and master_kdc = >> server.ad.example.com to the krb5.conf example > > I've added dns_lookup_kdc, but I'm not sure about maste

Re: [SSSD-users] New AD provider howto

2014-04-17 Thread Jakub Hrozek
On Thu, Apr 17, 2014 at 09:05:42AM +0300, Marko Myllynen wrote: > Hi, > > On 2014-04-10 17:20, Jakub Hrozek wrote: > > > > our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > > mostly because the page still only introduces the LDAP provider. Recently, > > me, > > Sumit and Jeremy

Re: [SSSD-users] New AD provider howto

2014-04-17 Thread Marko Myllynen
Hi, On 2014-04-10 17:20, Jakub Hrozek wrote: > > our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > mostly because the page still only introduces the LDAP provider. Recently, me, > Sumit and Jeremy Agee wrote a new page that specifically advises to use > the AD provider and also u

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 01:22:54PM +0100, Rowland Penny wrote: > On 11/04/14 13:16, Jakub Hrozek wrote: > >On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: > >>OK, I take it all back, I am stupid ;-) > >> > >>Once I scanned the new logfile, it dawned on me what I had forgotten > >>to

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 13:16, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: OK, I take it all back, I am stupid ;-) Once I scanned the new logfile, it dawned on me what I had forgotten to do, so I did it and now everything seems to be working ok. Oh, you want to know

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 12:59:00PM +0100, Rowland Penny wrote: > OK, I take it all back, I am stupid ;-) > > Once I scanned the new logfile, it dawned on me what I had forgotten > to do, so I did it and now everything seems to be working ok. > > Oh, you want to know what I forgot to do? > > I fo

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 12:41, Lukas Slebodnik wrote: On (11/04/14 12:03), Rowland Penny wrote: On 11/04/14 11:10, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 1

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Lukas Slebodnik
On (11/04/14 12:03), Rowland Penny wrote: >On 11/04/14 11:10, Jakub Hrozek wrote: >>On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: >>>On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: >On 10/04/14 22:53, Jakub Hrozek wrote:

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 11:10, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 11:06:24AM +0100, Rowland Penny wrote: > On 11/04/14 10:44, Jakub Hrozek wrote: > >On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: > >>On 10/04/14 22:53, Jakub Hrozek wrote: > >>>On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: > On 10/04/14

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 11/04/14 10:44, Jakub Hrozek wrote: On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: On 10/04/14 15:20, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Fri, Apr 11, 2014 at 10:33:02AM +0100, Rowland Penny wrote: > On 10/04/14 22:53, Jakub Hrozek wrote: > >On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: > >>On 10/04/14 15:20, Jakub Hrozek wrote: > >>>Hi, > >>> > >>>our current HOWTO[1] on connecting SSSD to an AD DC is outdated, >

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Rowland Penny
On 10/04/14 22:53, Jakub Hrozek wrote: On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: On 10/04/14 15:20, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit

Re: [SSSD-users] New AD provider howto

2014-04-11 Thread Jakub Hrozek
On Thu, Apr 10, 2014 at 07:13:56PM -0400, Bryan Harris wrote: > Hi Jakub, > > Hopefully I’m providing a decent discussion starting point. Is placing the > DC into resolv.conf the typical scenario? Or is it more that this is the > Microsoft-recommended way of doing things, full stop? > > For e

Re: [SSSD-users] New AD provider howto

2014-04-10 Thread Bryan Harris
Hi Jakub, Hopefully I’m providing a decent discussion starting point. Is placing the DC into resolv.conf the typical scenario? Or is it more that this is the Microsoft-recommended way of doing things, full stop? For example, I don’t put 8.8.8.8 into my resolver if I want to lookup the www.go

Re: [SSSD-users] New AD provider howto

2014-04-10 Thread Jakub Hrozek
On Thu, Apr 10, 2014 at 04:44:20PM +0100, Rowland Penny wrote: > On 10/04/14 15:20, Jakub Hrozek wrote: > >Hi, > > > >our current HOWTO[1] on connecting SSSD to an AD DC is outdated, > >mostly because the page still only introduces the LDAP provider. Recently, > >me, > >Sumit and Jeremy Agee wrote

Re: [SSSD-users] New AD provider howto

2014-04-10 Thread Rowland Penny
On 10/04/14 15:20, Jakub Hrozek wrote: Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises to use the AD provider and also use realmd f

[SSSD-users] New AD provider howto

2014-04-10 Thread Jakub Hrozek
Hi, our current HOWTO[1] on connecting SSSD to an AD DC is outdated, mostly because the page still only introduces the LDAP provider. Recently, me, Sumit and Jeremy Agee wrote a new page that specifically advises to use the AD provider and also use realmd for setup: https://fedorahosted.org/sssd/w