There actually is GPO support in SSSD.

Looking at the man page (sssd-ad), you have to use "ad" provider and tune
few options regarding gpo, particularly ad_gpo_access_control and
ad_gpo_implicit_deny.

If it is not working for you, can you share the sssd.conf? Eventually you
can increase the SSSD debug_level and look into logs if there is something
wrong with GPO evaluation.

HTH
Tomáš

On Sat, Sep 10, 2022 at 2:53 AM Gregory Carter <gjcart...@gmail.com> wrote:

> There is no such thing as a GPO for a LINUX box.
>
> That being said I use Puppet to do basically the same thing.  (i.e. Bring
> LINUX, MAC, Windows to bear on a common LDAP policy schema I created to
> enforce machine configurations, authentication and security policies.)
>
> On Fri, Sep 9, 2022 at 12:56 AM 任 昭翰 <zhaohan....@hotmail.com> wrote:
>
>> Hi guys
>>
>> I have a Ubuntu22.04 client which joined to an AD(winserver 2012) server
>> by sssd + realm, in the AD I have a customized GPO, is it possible that the
>> AD refresh/push the GPO to the Ubuntu machine? I also have a win10 client
>> that also joined this AD, the win10 client could receive the GPO update
>> successfully from the AD.
>> _______________________________________________
>> sssd-users mailing list -- sssd-users@lists.fedorahosted.org
>> To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org
>> Fedora Code of Conduct:
>> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
>> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
>> List Archives:
>> https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org
>> Do not reply to spam, report it:
>> https://pagure.io/fedora-infrastructure/new_issue
>>
> _______________________________________________
> sssd-users mailing list -- sssd-users@lists.fedorahosted.org
> To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>


-- 
Tomáš Halman
_______________________________________________
sssd-users mailing list -- sssd-users@lists.fedorahosted.org
To unsubscribe send an email to sssd-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/sssd-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to