> One part of the question is not clear to me:
> Is the context AD users coming via trusts or is the client configured to
> access AD directly?
They are from trust, not directly.
> Anyhow, you can override the shell on the client using the
> override_shell directive of sssd.conf. Simply put it into the domain
> section and restart the SSSD.
Thanks for that tip, will try that one.
Freeipa-users mailing list