Re: [Freeipa-users] question about Active Directory authentication

2015-02-19 Thread David Fitzgerald
-users@redhat.com Subject: Re: [Freeipa-users] question about Active Directory authentication Ok, So with winsync I will have the 2000+ users in IPA. Within IPA I have several high risk/impact groups of servers and many low. For the low risk/impact servers and most desktops they can trust

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Dmitri Pal
On 02/17/2015 05:21 PM, Steven Jones wrote: ***maybe*** c) You might be able to do both winsync and trusts at the same time then that is simpler provisioning. ie a user gets created in AD and automatically gets created in IPA ready for you to put in the user group you want. I am not

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Steven Jones
on behalf of Dmitri Pal d...@redhat.com Sent: Wednesday, 18 February 2015 11:51 a.m. To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] question about Active Directory authentication On 02/17/2015 05:21 PM, Steven Jones wrote: ***maybe*** c) You might be able to do both winsync and trusts

[Freeipa-users] question about Active Directory authentication

2015-02-17 Thread David Fitzgerald
Hello, I am currently running an IPA 3.3 server on Centos 7. I have 70 IPA client machines running Scientific Linux 6.6 and 150 users. User directories are auto-mounted from a Centos 7 file server. I have been informed that all computer users on our campus must now authenticate off of the

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Dmitri Pal
On 02/17/2015 04:05 PM, David Fitzgerald wrote: Hello, I am currently running an IPA 3.3 server on Centos 7. I have 70 IPA client machines running Scientific Linux 6.6 and 150 users. User directories are auto-mounted from a Centos 7 file server. I have been informed that all computer

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Steven Jones
david.fitzger...@millersville.edu Sent: Wednesday, 18 February 2015 10:05 a.m. To: freeipa-users@redhat.com Subject: [Freeipa-users] question about Active Directory authentication Hello, I am currently running an IPA 3.3 server on Centos 7. I have 70 IPA client machines running Scientific Linux 6.6

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Dmitri Pal
...@millersville.edu *Sent:* Wednesday, 18 February 2015 10:05 a.m. *To:* freeipa-users@redhat.com *Subject:* [Freeipa-users] question about Active Directory authentication Hello, I am currently running an IPA 3.3 server on Centos 7. I have 70 IPA client machines running Scientific Linux 6.6 and 150 users

Re: [Freeipa-users] question about Active Directory authentication

2015-02-17 Thread Steven Jones
***maybe*** c) You might be able to do both winsync and trusts at the same time then that is simpler provisioning. ie a user gets created in AD and automatically gets created in IPA ready for you to put in the user group you want. I am not sure this is the best solution really. Trust and