----- Original Message ----- > On Wed, May 28, 2014 at 10:47:13AM -0300, tizo wrote: > > I would like to know, if having configured trusts services between FreeIPA > > and Active Directory, allow AD users to authenticate in services that are > > only configured to authenticate against FreeIPA. > > > > For example, having configured the trusts, if I have a mail server that is > > using FreeIPA as its authentication method, can a user A from Active > > Directory, who does not exist in FreeIPA, authenticate in the mail server?. > > It depends a bit on how the users authenticate exactly because IPA > offers Kerberos and LDAP authentication. > > Kerberos should work out of the box because thats one of the trusts > components, trusting Kerberos tickets from the other domain/realm. > > For LDAP authentication you should be able to find the users from the > trusted domain in the compat tree below > cn=compat,dc=your,dc=ipa,dc=domain . To authenticate the user you can > do a LDAP bind with the DN form the compat tree and the password used in > AD. Please note that the latter is valid only for FreeIPA 3.3 and later. FreeIPA 3.0 does not support authentication over LDAP in the compat tree. -- / Alexander Bokovoy
_______________________________________________ Freeipa-users mailing list [email protected] https://www.redhat.com/mailman/listinfo/freeipa-users
