On Thu, 2011-06-23 at 15:25 +0100, Attila Bogár wrote:
> Hi,
> On 23/06/11 14:04, Simo Sorce wrote:
> > The Full Name field is not read-only in AD.
> > It is exactly the attribute in which you are supposed to put the user's
> > Full Name.
> There are 3 fields, namely: "name", "displayName" and "cn".
> I can see, that IPA was changing the "cn" and "name" fields.
> If you start dsa.msc right click on a user, Attribute Editor tab,
> click Filter, tick show only writable attributes.
> "name" is not a writable attribute.
> However you are partly right, because it's possible to change it by
> renaming the user.
> Right click on the user, select rename.
> According to M$, the name attribute is actually the RDN
> http://support.microsoft.com/kb/257218

It is.
Sorry I thought you were referring to 'cn' not to the 'name' attribute.

CN usually holds the Full Name of a user in AD.


Simo Sorce * Red Hat, Inc * New York

Freeipa-users mailing list

Reply via email to