[Freeipa-users] Re: OSX (El Capitan) - FreeIPA

2017-07-26 Thread Jason Sherrill via FreeIPA-users
Luiz, Would you please run the below command from an OS X workstation's terminal to test look-up/caching of groups? If it displays a gid then we know the issue isn't LDAP mapping. dscacheutil -q group -a name *yourGroupName* On Tue, Jul 25, 2017 at 11:30 AM, Luiz Garrido ALKEMY X via

[Freeipa-users] Re: OSX (El Capitan) - FreeIPA

2017-07-26 Thread Luiz Garrido ALKEMY X via FreeIPA-users
Our setup is really close to this how-to: http://www.freeipa.org/page/HowTo/Setup_FreeIPA_Services_for_Mac_OS_X_10.12 Just a little different because this didn't exist when we did the configuration. But even if you follow that, users on Mac are not getting IPA groups and without correct

[Freeipa-users] Re: OSX (El Capitan) - FreeIPA

2017-07-25 Thread Jason Sherrill via FreeIPA-users
Hi Luiz, Would you please verify your settings in: System Preferences > Users & Groups > Login Options > Network Account Server > Directory Utility > Services > LDAP > Your LDAP server > Search & Mappings There should be a Record Type called 'Groups' with an attribute 'PrimaryGroupID' that is