On Tue, Aug 21, 2012 at 2:50 AM, Innes, Duncan
<duncan.in...@virginmoney.com> wrote:
>I can't be alone in deploying IPA in a network already "dominated" by AD.

You're certainly not.  In my case it appears the Windows people have
done everything they can to sabotage my efforts to implement SSO in
unix-land that they can do without being overt about it.  They've
refused to make simple changes like adding our unix subdomain to the
windows client dns search path, forcing our users to use FQDNs for
everything.  They won't do a domain trust with us, they won't let us
sync passwords between AD and IPA, making things easier on our users.
But we keep moving ahead anyway, because that's what we do.

When did we become the red-headed step-children?


