Hi everybody,
I established a bidirectional trust between an IPA server (version 4.1.0 on
CentOS 7.1), ipa.mydomain.local and an AD (Windows 2012 r2), mydomain.local.
Everything is working fine, and I'm able to authenticate and logon on a linux
host joined to IPA server using AD credentials (username@mydomain.local).
But active directory is configured with two more UPN suffixes (otherdomain.com
and sub.otherdomain.com), and I cannot logon with credentials using alternative
UPN (example: john....@otherdomain.com).

How can I make this possible? Another trust (ipa trust-add) with the same AD?
Manual configuration of krb5 and/or sssd?

Thanks in advance

-- 
gb

PGP Key: http://pgp.mit.edu/
Primary key fingerprint: C510 0765 943E EBED A4F2 69D3 16CC DC90 B9CB 0F34

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to