On Tue, Aug 21, 2012 at 2:50 AM, Innes, Duncan <duncan.in...@virginmoney.com> wrote: >I can't be alone in deploying IPA in a network already "dominated" by AD.
You're certainly not. In my case it appears the Windows people have done everything they can to sabotage my efforts to implement SSO in unix-land that they can do without being overt about it. They've refused to make simple changes like adding our unix subdomain to the windows client dns search path, forcing our users to use FQDNs for everything. They won't do a domain trust with us, they won't let us sync passwords between AD and IPA, making things easier on our users. But we keep moving ahead anyway, because that's what we do. When did we become the red-headed step-children? --Jason _______________________________________________ Freeipa-users mailing list Freeipaemail@example.com https://www.redhat.com/mailman/listinfo/freeipa-users