Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Sumit Bose
On Wed, Feb 01, 2012 at 01:59:15PM -0500, Simo Sorce wrote: On Wed, 2012-02-01 at 12:00 -0500, Dmitri Pal wrote: On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Alexander Bokovoy
On Thu, 02 Feb 2012, Sumit Bose wrote: Simo, thank you for give detailed responses and explanations here. To make it - hopefully - even clearer I try to describe the step that are necessary to enable IPA for trust and to create trust to AD domains. I assume that we start from a running IPAv2

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-02 Thread Simo Sorce
On Thu, 2012-02-02 at 13:39 +0200, Alexander Bokovoy wrote: On Thu, 02 Feb 2012, Sumit Bose wrote: Simo, thank you for give detailed responses and explanations here. To make it - hopefully - even clearer I try to describe the step that are necessary to enable IPA for trust and to create

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Dmitri Pal
On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both objectclasses is ipaNTSecurityIdentifier the

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Rob Crittenden
Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both objectclasses is ipaNTSecurityIdentifier the SID or the user or group. We

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Simo Sorce
On Wed, 2012-02-01 at 12:00 -0500, Dmitri Pal wrote: On 01/31/2012 06:45 AM, Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST

Re: [Freeipa-devel] Adding a new DNA plugin configuration in IPAv3

2012-02-01 Thread Simo Sorce
On Wed, 2012-02-01 at 13:39 -0500, Rob Crittenden wrote: Sumit Bose wrote: Hi, for the IPAv3 trust feature we have to add the objectclass ipaNTUserAttrs/ipaNTGroupAttrs to every user/group which should be visible on the Windows side of the trust. The only MUST attribute of both