All Windows clients are properly enrolled into the AD domain. We can't use two-way trust because of reasons you explained here before. A one-way external trust is used. All perfectly established and working, but somehow windows clients don't follow the topology.
By adding a domain_realm mapping to a windows client, also describe on FreeIPA-users before, the routing problem is solved. But I (and especially the AD admins ;-) ) would prefer to solve the underlying issue. Thanks a lot, it is quite hard to find experts (with knowledge of both LDAP, AD and different Kerberos implementations)(we are reaching out to RH) Sincerely Pieter On Wed, 16 Oct 2019, 10:08 Alexander Bokovoy, <[email protected]> wrote: > On ke, 16 loka 2019, Pieter Baele via FreeIPA-users wrote: > >The only open issue we have with IPA is Windows clients not being directed > >to the Kerberos servers of the IPA realm. > > I think there is lack of a context here in your question. > > For forest trust to Active Directory, all cross-realm routing is being > done by AD DCs according to the topology associated with the trusted > domain object. FreeIPA pushes out that information when trust is created > and AD DCs follow it. We take all domains from the list maintained by > realmdomains command. > > So there is no need to have anything additional there. Windows clients > will properly use SRV DNS records from primary IPA DNS domain. I think > there is one missing DNS record right now that was found recently in > FreeIPA 4.8.1: https://bugzilla.redhat.com/show_bug.cgi?id=1711958 > > However, this has nothing to do with Kerberos. > > We do not support non-enrolled Windows configurations, so if by 'Windows > clients' you mean exactly that, sorry, nothing can be done. > > > -- > / Alexander Bokovoy > Sr. Principal Software Engineer > Security / Identity Management Engineering > Red Hat Limited, Finland >
_______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
