[Freeipa-users] Re: Sync against AD group

2017-10-26 Thread Rob Crittenden via FreeIPA-users
Miguel Angel Coa M. wrote: > Rob, > My idea about A/D group is centralize the users for the winsync because > some are in one OU and others in others (but i see this isn't possible) > > eg. > > Example2.com <-- Domain root > Builtin <-- Default > . > . > Users <-- Default users -> bas

[Freeipa-users] Re: Sync against AD group

2017-10-25 Thread Rob Crittenden via FreeIPA-users
Miguel Angel Coa M. wrote: > Hi Rob, > CN=LAB is a group entry and inside i've a few members > > [.] > # LAB, Users, example2.com > dn: CN=LAB,CN=Users,DC=example2,DC=com > objectClass: top > objectClass: group > cn: LAB > description: Usuario de grupo LAB > m

[Freeipa-users] Re: Sync against AD group

2017-10-25 Thread Rob Crittenden via FreeIPA-users
Miguel Angel Coa M. via FreeIPA-users wrote: > Hello Everyone, > I've setting IPA server connect with AD (Windows Server 2012R2) and work > fine, but i need change the sub-tree for user sync and this step fail > (not sync anything) . > For example, when i sync against the default base is ok > > [.