On ti, 22 joulu 2020, lejeczek via FreeIPA-users wrote:

Hi guys,

IPA with Samba integrated and users migrated from another IPA and a user was available to Samba.
Then on a second master too
-> $ ipa-adtrust-install
was run and I think that was the only bit done. Then user was removed and added with the same UID and Samba does not see that user, which user elsewhere works fine. Removal was done with --no-preserve and also without it but no difference.

Any suggestions as how to fix it are greatly appreciated.

Start with the user's LDAP entry. Check that ipaNTSecurityIdentifier
attribute exists and has SID in the same domain as IPA SID (visible in
'ipa trustconfig-show').

After that, collect Samba logs with 'log level = 10' when attempting to
connect as this user.

--
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to