Using a RHEL or Centos 5.11 as a legacy client (using sssd) seems to work.
I created an external group which is member of a posix group. Putting an AD user in the external group works, but it seems to take ages beofre it takes effect.
Yesterday late, I remove some AD user from some group and did not see any effect only until this morning.
What could case this delay?
Oh yeah, during the night, IPA is stopped during the back-up... Is this causing the refresh?
It is OK to wait some time for group modifications to take effect, that's the price of the sssd-cache but this looks strange and is far too long....
On both IPA-server and the EL5 client I set "entry_cache_timeout" to 300.
-- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project