[Freeipa-users] ID-View for AD group to use GECOS umask

2019-04-15 Thread Ronald Wimmer via FreeIPA-users
Afaik it should be possible to set a users umask by putting something like "umask=0007" in the GECOS field in combination with pam_umask.so. pam_umask.so seems to be present on our systems. What I do not know is in which file (at which exact position) I would have to put "session optional

[Freeipa-users] Re: Lookups for trust uses fails if member of group that has a user with same name, returned more than one object.

2019-04-15 Thread Henrik Johansson via FreeIPA-users
> On 14 Apr 2019, at 08:54, Alexander Bokovoy via FreeIPA-users > wrote: > >> >> It does work on the FreeIPA server all the time but fails on clients, >> if I lookup the conflicting group before the use on the client it also >> woks. > This is SSSD-specific issue. Sometimes it doesn't have