Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Sumit Bose
On Wed, Feb 01, 2012 at 01:59:15PM -0500, Simo Sorce wrote: On Wed, 2012-02-01 at 12:00 -0500, Dmitri Pal wrote: On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Alexander Bokovoy
On Thu, 02 Feb 2012, Sumit Bose wrote: Simo, thank you for give detailed responses and explanations here. To make it - hopefully - even clearer I try to describe the step that are necessary to enable IPA for trust and to create trust to AD domains. I assume that we start from a running IPAv2

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Simo Sorce
On Thu, 2012-02-02 at 13:39 +0200, Alexander Bokovoy wrote: On Thu, 02 Feb 2012, Sumit Bose wrote: Simo, thank you for give detailed responses and explanations here. To make it - hopefully - even clearer I try to describe the step that are necessary to enable IPA for trust and to create

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Dmitri Pal
On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both objectclasses is ipaNTSecurityIdentifier the

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Rob Crittenden
Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both objectclasses is ipaNTSecurityIdentifier the SID or the user or group. We

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Simo Sorce
On Wed, 2012-02-01 at 12:00 -0500, Dmitri Pal wrote: On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Simo Sorce
On Wed, 2012-02-01 at 13:39 -0500, Rob Crittenden wrote: Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both

[Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-01-31 Thread Sumit Bose
Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both objectclasses is ipaNTSecurityIdentifier the SID or the user or group. We would like to