I cannot get smart card login to work for users from my AD trust on IPA
clients. The users have working smart card login on windows.
What should i look at. The IPA is Version 4.4.0  on RHEL 7.3 and the main
test computer is RHEL 6.8.  I have no issues getting it to work for IDM
users. I have the certificate attached to the user account in AD as its
usercertifcate. I cannot find much info on how to troubleshoot certificates
for AD based users. ipa find-certs only shows certs for idm users.

