Re: [SSSD-users] could not store group failures for lookups on Active Directory groups

2015-05-06 Thread Jakub Hrozek
On Wed, May 06, 2015 at 07:47:11AM +0200, Lukas Slebodnik wrote: On (06/05/15 01:12), James Ralston wrote: Hi, I think this problem may be part (or related to) the FreeIPA/SSSD LDAP cross-forest trust slow queries issue, but I'm not sure. We've been testing sssd on our RHEL6 and RHEL7

Re: [SSSD-users] could not store group failures for lookups on Active Directory groups

2015-05-06 Thread James Ralston
Hi Lukas, On Wed, May 6, 2015 at 1:47 AM, Lukas Slebodnik lsleb...@redhat.com wrote: On (06/05/15 01:12), James Ralston wrote: enumerate = true I Hope it was just for testing purposes. We do not recommend to enable enumeration. I know it's not recommended. I'll address this in a

Re: [SSSD-users] could not store group failures for lookups on Active Directory groups

2015-05-06 Thread Jakub Hrozek
On Wed, May 06, 2015 at 01:02:22PM -0400, James Ralston wrote: What do you recommend doing for RHEL6 (currently on 1.11.6-30.el6_6.4)? 1. Use your 1.12.5 packages on RHEL6? 2. Wait for Red Hat to backport the patch for ticket/2588 to their 1.11.6 branch? Unlikely to

Re: [SSSD-users] could not store group failures for lookups on Active Directory groups

2015-05-06 Thread James Ralston
On Wed, May 6, 2015 at 1:26 PM, Jakub Hrozek jhro...@redhat.com wrote: On Wed, May 06, 2015 at 01:02:22PM -0400, James Ralston wrote: 3. Wait for Red Hat to rebase RHEL6 to 1.12.5? RHEL-6.7 will rebase to sssd-1-12. If you want to stay on the supported patch, this is the best option. btw

[SSSD-users] could not store group failures for lookups on Active Directory groups

2015-05-05 Thread James Ralston
Hi, I think this problem may be part (or related to) the FreeIPA/SSSD LDAP cross-forest trust slow queries issue, but I'm not sure. We've been testing sssd on our RHEL6 and RHEL7 hosts, using the latest available packages. We have a fairly simple sssd configuration. We use the ad provider with