Re: [Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-11 Thread Sumit Bose
On Wed, Sep 10, 2014 at 08:19:15AM +0200, Gregor Bregenzer wrote: Hello Sumit, i think maybe there is a different problem i just discovered by accident. As stated in the first email, i have an AD trust with FreeIPA that receives all POSIX attributes from AD, but i get different values: On

Re: [Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-10 Thread Gregor Bregenzer
Hello Sumit, i think maybe there is a different problem i just discovered by accident. As stated in the first email, i have an AD trust with FreeIPA that receives all POSIX attributes from AD, but i get different values: On the FreeIPA server that has the AD trust (ipa1.linux.intern) i get the

Re: [Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-10 Thread Gregor Bregenzer
I added the correct logfiles now - sorry! On linux1.linux.intern 1.) service sssd stop; rm -f /var/lib/sss/db/* ; service sssd start 2.) getent passwd user1@aaa Logfile sssd_linux.intern.log (Wed Sep 10 17:04:24 2014) [sssd[be[linux.intern]]] [sbus_dispatch] (0x4000): dbus conn:

Re: [Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-08 Thread Sumit Bose
On Sun, Sep 07, 2014 at 11:41:16PM +0200, Gregor Bregenzer wrote: Hi! I have an AD trust with FreeIPA 4.0.1 and defined a HBAC rule for a specific user group (=ad_users which is an posix group that has an external group as member) to login on a specific client (=linux1.linux.intern). The

[Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-07 Thread Gregor Bregenzer
Hi! I have an AD trust with FreeIPA 4.0.1 and defined a HBAC rule for a specific user group (=ad_users which is an posix group that has an external group as member) to login on a specific client (=linux1.linux.intern). The problem is: once i disable the rule and the AD user is not allowed to