Re: [SSSD-users] please do not remove enumeration from AD provider

2015-05-14 Thread James Ralston
On Wed, May 6, 2015 at 3:10 PM, Stephen Gallagher sgall...@redhat.com wrote: To be fair, it's not that hard to turn that [ldapsearch command] into a bash script that your users can use instead of learning the ldap syntax. But yes, that's still a change in behavior. We could, but I think just

Re: [SSSD-users] please do not remove enumeration from AD provider

2015-05-11 Thread Ondrej Valousek
...@lists.fedorahosted.org [mailto:sssd-users-boun...@lists.fedorahosted.org] On Behalf Of James Ralston Sent: Wednesday, May 06, 2015 7:29 PM To: End-user discussions about the System Security Services Daemon Subject: [SSSD-users] please do not remove enumeration from AD provider On Wed, May 6, 2015 at 4:27 AM

Re: [SSSD-users] please do not remove enumeration from AD provider

2015-05-11 Thread Lukas Slebodnik
On (11/05/15 07:01), Ondrej Valousek wrote: +1 here. I can also confirm that several services (Cadence, are you listening??) depend on enumeration so we need preserve this functionality - but I agree that relying on enumeration is a bad habit which should be avoided. Would it be acceptable for

[SSSD-users] please do not remove enumeration from AD provider

2015-05-06 Thread James Ralston
On Wed, May 6, 2015 at 4:27 AM, Jakub Hrozek jhro...@redhat.com wrote: You know, just this morning, I was thinking about enumeration. It doesn't work for IPA views at all for example. It doesn't work for trusted domains at all either (except for some limited support in AD trusted domains

Re: [SSSD-users] please do not remove enumeration from AD provider

2015-05-06 Thread Stephen Gallagher
- Original Message - From: James Ralston rals...@pobox.com To: End-user discussions about the System Security Services Daemon sssd-users@lists.fedorahosted.org Sent: Wednesday, May 6, 2015 1:28:35 PM Subject: [SSSD-users] please do not remove enumeration from AD provider On Wed