Re: [Freeipa-devel] HBAC for AD users Active Directory trust setup

2016-10-12 Thread Alexander Bokovoy
On ke, 12 loka 2016, rajat gupta wrote: Hi, thank you for answering. I this case i need to create multiple group in AD side. like user1 have only "server1.example.com" and "server2.example.com" access and some other user have some other server access. Then only the my HBAC rule will be

Re: [Freeipa-devel] HBAC for AD users Active Directory trust setup

2016-10-12 Thread rajat gupta
Hi, thank you for answering. I this case i need to create multiple group in AD side. like user1 have only "server1.example.com" and "server2.example.com" access and some other user have some other server access. Then only the my HBAC rule will be implemented to particular group and every

Re: [Freeipa-devel] HBAC for AD users Active Directory trust setup

2016-10-12 Thread Alexander Bokovoy
On ke, 12 loka 2016, rajat gupta wrote: Hi, Normally HBAC for AD users should be done through an external group. You should use freeipa-users@ mailing list for these questions. And start with documentation:

[Freeipa-devel] HBAC for AD users Active Directory trust setup

2016-10-12 Thread rajat gupta
Hi, Normally HBAC for AD users should be done through an external group. So for example if we have 500+ users on AD and only 100 user are administrator and they have Linux server access. I want to set the HBAC and sudo rules for users. So user have correct access server access and sudo rights