> I wonder if the (very) new IPA AD trust feature could solve at least
> some of your problems. Have a look at
> http://freeipa.org/page/IPAv3_testing_AD_trust for some info on how this
> can be tested.
>

The initial documentation looks like it's describing a full two way
trust - in principal would a one way trust be feasible?

Allow the AD users (or a selection thereof) access to the systems part
of the IPA domain but not vice versa?

James

_______________________________________________
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Reply via email to