Dealing with outsourced IT organization that manages an AD domain we are tying to build an additional trust with so we can upgrade and replace our fleet of IDM servers.

We got a webex work session going with a domain admin to build the trust but we keep seeing this on the CLI and WebUI:

ipa: ERROR: Insufficient access: CIFS server XXXXXX.COMPANY.COM denied your credentials

Running in debug or verbose mode does not reveal more error details and I can't find much in the logs on the IPA server


The AD admin we were working with claims he used an account that is part of the Enterprise Admin group and thus should be allowed to do "all the things" -- they are asking for any docs or details we have on what permissions the IPA server needs when trust building


Looking for info/tips on the following, thanks!


1) Any log locations or places where I can find more info about why the ad-trust setup failed?

2) Any docs or listing of specific AD permissions needed by the AD admin account used to establish the trust

AD is not my strong point - apologies if this is a dumb query!

Regards,
Chris



_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]/message/23P7L37IY4YOSUWEGBHI5TVJWLQXBV4Q/

Reply via email to