Re: [Freeipa-users] LDAPS for AD trust?

2016-06-17 Thread Alexander Bokovoy
On Thu, 16 Jun 2016, Erik Mackdanz wrote: Hello, Is it possible to force LDAPS instead of LDAP when connecting to the client's AD domain in a trust situation? I'm sure that the _ldaps SRV must be added to AD (AD doesn't have one by default). There is no such thing as _ldaps SRV record and

Re: [Freeipa-users] LDAPS for AD trust?

2016-06-16 Thread Jakub Hrozek
On Thu, Jun 16, 2016 at 04:53:22PM -0500, Erik Mackdanz wrote: > Hello, > > Is it possible to force LDAPS instead of LDAP when connecting to the > client's AD domain in a trust situation? > > I'm sure that the _ldaps SRV must be added to AD (AD doesn't have one > by default). > > It's not

[Freeipa-users] LDAPS for AD trust?

2016-06-16 Thread Erik Mackdanz
Hello, Is it possible to force LDAPS instead of LDAP when connecting to the client's AD domain in a trust situation? I'm sure that the _ldaps SRV must be added to AD (AD doesn't have one by default). It's not clear, though, whether I can make SSSD request the _ldaps SRV record. I tried setting