On ke, 16 loka 2019, Pieter Baele via FreeIPA-users wrote:
The only open issue we have with IPA is Windows clients not being directed to the Kerberos servers of the IPA realm.
I think there is lack of a context here in your question. For forest trust to Active Directory, all cross-realm routing is being done by AD DCs according to the topology associated with the trusted domain object. FreeIPA pushes out that information when trust is created and AD DCs follow it. We take all domains from the list maintained by realmdomains command. So there is no need to have anything additional there. Windows clients will properly use SRV DNS records from primary IPA DNS domain. I think there is one missing DNS record right now that was found recently in FreeIPA 4.8.1: https://bugzilla.redhat.com/show_bug.cgi?id=1711958 However, this has nothing to do with Kerberos. We do not support non-enrolled Windows configurations, so if by 'Windows clients' you mean exactly that, sorry, nothing can be done. -- / Alexander Bokovoy Sr. Principal Software Engineer Security / Identity Management Engineering Red Hat Limited, Finland _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
