Re: [Freeipa-users] Sanity check on hbac rule on "foreign" domains.

2013-08-06 Thread KodaK
On Mon, Aug 5, 2013 at 4:23 AM, Sumit Bose wrote: > Which version of FreeIPA are you using on the server? Maybe the sssd > logs at a high debug level will give more details why the access is > denied you you try to log in with ssh as testuser on > stlmoracsbx01.domain.com. Something must have bee

Re: [Freeipa-users] Sanity check on hbac rule on "foreign" domains.

2013-08-05 Thread Sumit Bose
On Fri, Aug 02, 2013 at 12:55:12PM -0500, KodaK wrote: > First, before we go any further: is it supported to use > sssd when the client machines domain differs from > the realm name? If not, then the rest of this is moot. > > Client box is a RHEL 5.something. I didn't do "ipa-client-install" >

[Freeipa-users] Sanity check on hbac rule on "foreign" domains.

2013-08-02 Thread KodaK
First, before we go any further: is it supported to use sssd when the client machines domain differs from the realm name? If not, then the rest of this is moot. Client box is a RHEL 5.something. I didn't do "ipa-client-install" because I wanted to configure by hand as a test. The client box ha