Rob, << Try adding the inetUser objectclass to your system account. You're probably lacking memberOf. >>
Thanks, that worked. My last issue is to add read/search permission on the "name" attribute as the vendor doesn't offer a way to not include it in a search filter to find user groups. << I was in Code 500 many moons ago, Center Network Environment (CNE). >> Small world :-) The NICS contract covers CNE at Goddard and at the Agency level. I'm setting up a new NMS system for the NASCOM mission network. George Boyce, SAIC/NICS GCC Systems Support NASA GSFC Code 762 -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
