[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Jakub Hrozek via FreeIPA-users
On Thu, Jun 07, 2018 at 03:48:16PM -, Bart via FreeIPA-users wrote: > Thank you Alexander, that was the root cause. I added optimizations to my > setup that you together with Jakub described in this article: >

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Bart via FreeIPA-users
Thank you Alexander, that was the root cause. I added optimizations to my setup that you together with Jakub described in this article: https://jhrozek.wordpress.com/2015/08/19/performance-tuning-sssd-for-large-ipa-ad-trust-deployments/ and things started working on the client side. There is a

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Bart via FreeIPA-users
Thank you Jakub for your hints. I created a brand new instance of FreeIPA client and connected it to the existing servers. Now I cannot resolve anytthing on a client (getent group $group, getent passwd $user yield no results). For the same exact users/groups I tested on the client, they get

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-06 Thread Jakub Hrozek via FreeIPA-users
On Wed, Jun 06, 2018 at 02:30:56PM -, Bart via FreeIPA-users wrote: > Hi Jakub, thank you for help. > > I cannot resolve all of the users nor their groups on a client hosts. getent > passwd doesn't return anything, su - user@ad.domain doesn't work either. > > All AD users I tried get

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-06 Thread Bart via FreeIPA-users
Hi Jakub, thank you for help. I cannot resolve all of the users nor their groups on a client hosts. getent passwd doesn't return anything, su - user@ad.domain doesn't work either. All AD users I tried get resolved on the FreeIPA servers. For the one account it gets resolved on one client host

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-05 Thread Jakub Hrozek via FreeIPA-users
On Tue, Jun 05, 2018 at 03:06:44PM -, Bart via FreeIPA-users wrote: > Hi all, > > I've set up two FreeIPA servers without CA (I provided 3rd party certificates > during the installation process). I also established trust to an AD domain as > below: > > ipa trust-add --type=ad AD.DOMAIN