Re: [Freeipa-users] Fwd: Marking subdomain offline

2017-04-06 Thread Jakub Hrozek
On Thu, Apr 06, 2017 at 02:39:02PM -0400, Chris Dagdigian wrote: > > I see similar things in our environment where IPA is used as "glue" between > AD Forests that have a 1-way trust relationship. We believe that the root > cause has something to do with the 30+ domain controllers the IPA client >

Re: [Freeipa-users] Fwd: Marking subdomain offline

2017-04-06 Thread mike
On 2017-04-06 20:18, Jakub Hrozek wrote: On Thu, Apr 06, 2017 at 07:21:01PM +0200, m...@chinewalking.com wrote: Hi, My IPA<->AD trust setup experiences intermittent failures during login events. The AD subdomain goes in an inactive/offline state and users logging in are put into a 'delayed aut

Re: [Freeipa-users] Fwd: Marking subdomain offline

2017-04-06 Thread Chris Dagdigian
I see similar things in our environment where IPA is used as "glue" between AD Forests that have a 1-way trust relationship. We believe that the root cause has something to do with the 30+ domain controllers the IPA client tries to make contact with (in seemingly random order) across the AD F

Re: [Freeipa-users] Fwd: Marking subdomain offline

2017-04-06 Thread Jakub Hrozek
On Thu, Apr 06, 2017 at 07:21:01PM +0200, m...@chinewalking.com wrote: > Hi, > > My IPA<->AD trust setup experiences intermittent failures during login > events. The AD subdomain goes in an inactive/offline state and users logging > in are put into a 'delayed authentication' queue. Usually logging