[Freeipa-users] sudo fails as the Kerberos realm from an alternate UPN suffix

2018-01-09 Thread Marin BERNARD via FreeIPA-users
Hi, We're using FreeIPA 4.5.0 on CentOS 7.4. We've set up a two-way trust between our 2 FreeIPA servers and our AD domain (forest an domain levels both on 2012 R2). So far, everything works as expected, and we're able to perform SSO to both FreeIPA instances with AD accounts. In our AD

[Freeipa-users] sudo fails as the Kerberos realm from an alternate UPN suffix

2018-01-09 Thread Marin BERNARD via FreeIPA-users
Hi, We're using FreeIPA 4.5.0 on CentOS 7.4. We've set up a two-way trust between our 2 FreeIPA servers and our AD domain (forest an domain levels both on 2012 R2). So far, everything works as expected, and we're able to perform SSO to both FreeIPA instances with AD accounts. In our AD