On Thu, 2011-06-23 at 15:25 +0100, Attila Bogár wrote:
> Hi,
> 
> On 23/06/11 14:04, Simo Sorce wrote:
> > The Full Name field is not read-only in AD.
> > It is exactly the attribute in which you are supposed to put the user's
> > Full Name.
> There are 3 fields, namely: "name", "displayName" and "cn".
> 
> I can see, that IPA was changing the "cn" and "name" fields.
> If you start dsa.msc right click on a user, Attribute Editor tab,
> click Filter, tick show only writable attributes.
> "name" is not a writable attribute.
> 
> However you are partly right, because it's possible to change it by
> renaming the user.
> Right click on the user, select rename.
> 
> According to M$, the name attribute is actually the RDN
> http://support.microsoft.com/kb/257218

It is.
Sorry I thought you were referring to 'cn' not to the 'name' attribute.

CN usually holds the Full Name of a user in AD.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York

_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Reply via email to