[Freeipa-users] ID-View for AD group to use GECOS umask

2019-04-15 Thread Ronald Wimmer via FreeIPA-users
Afaik it should be possible to set a users umask by putting something 
like "umask=0007" in the GECOS field in combination with pam_umask.so.


pam_umask.so seems to be present on our systems. What I do not know is 
in which file (at which exact position) I would have to put "session 
optional pam_umask.so".


Should it work in general or would pam_umask.so only respect the GECOS 
field of local users?


Cheers,
Ronald
___
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org


[Freeipa-users] Re: Lookups for trust uses fails if member of group that has a user with same name, returned more than one object.

2019-04-15 Thread Henrik Johansson via FreeIPA-users


> On 14 Apr 2019, at 08:54, Alexander Bokovoy via FreeIPA-users 
>  wrote:
> 
>> 
>> It does work on the FreeIPA server all the time but fails on clients,
>> if I lookup the conflicting group before the use on the client it also
>> woks.
> This is SSSD-specific issue. Sometimes it doesn't have enough
> information to deduce what is being looked up -- a group or a user and
> has to ask for either. Perhaps, it might be optimized to check whether
> there are two results returned and they are of different nature, as
> opposed to multiple results of the same nature returned which clearly
> would be a wrong result.
> 
> May be you can open a bug against SSSD?

Thank you, this leave us with the same restrictions with one namespace for 
users and groups on the IPA side as in windows and will prevent our migration. 
I will have a bug filed against SSSD but I guess it will take some time to get 
this fixed.

Regards
Henrik


___
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org