Re: [Freeipa-users] SSSD client (amazon linux) + IPA server (Redhat)

2015-09-24 Thread Pawel Fiuto
Unfortunately sudo package included in amzn linux does not work with sudo rules provided via SSS however it is in the feature requests list. To workaround this you can replace it with the CentOS one: http://mirror.centos.org/centos/6.7/os/x86_64/Packages/sudo-1.8.6p3-19.el6.x86_64.rpm _

Re: [Freeipa-users] AuthorizedKeysCommand for clients using nss-pam-ldapd

2015-09-14 Thread Pawel Fiuto
Hi Gustavo, Using settings from 'ipa-advise config-redhat-sssd-before-1-9' with below modifications seems to work quite well: - on ipa server add permisson to read ipaSshPubKey anonymously: [ipa-server]# ipa permission-add 'Read ipaSshPubKey' --type=user --attrs=ipaSshPubKey --bindtype=anonym