[Freeipa-users] Re: IPA -> AD trust : can't ssh with an AD user

2020-06-04 Thread Christophe BERGER via FreeIPA-users
Florence, I didn't change anything and it now works :\ Anyway I'll follow your recommandation and use external groups and so on. Merci ! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: IPA -> AD trust : can't ssh with an AD user

2020-06-04 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, in order to use AD users or groups in HBAC/sudo rules, you need to first create an external group (ipa group-add --external extgrp) that will contain your AD users/groups, then create a posix group (ipa group-add grp) and add the external group as member of the posix group (ipa