Is it possible for accounts in cn=etc,cn=sysaccounts to have kerberos principals or must you use the cn=accounts,cn=users container? I'm thinking this for script-authenticated machine accounts (might be of form user-hostname@REALM or user/hostname@REALM) that need to authenticate to another machine and just a way to separate them from the regular user accounts in cn=accounts,cn=users.
Steve _______________________________________________ Freeipa-users mailing list [email protected] https://www.redhat.com/mailman/listinfo/freeipa-users
