Re: [Freeipa-users] [[Test-Announce] Fedora 22 Final status is Go, release on May 26, 2015]

2015-05-22 Thread Carlos Raúl Laguna
Hi Alexander
Great news, does this also mean that user created in freeipa are self
created/synchronized in the windows ad ? Regtards

2015-05-22 15:00 GMT-04:00 Alexander Bokovoy aboko...@redhat.com:

 Hi,

 As per attached message, Fedora 22 final release will come to life next
 week. If you are planning to use FreeIPA in Fedora 22 or upgrade your
 FreeIPA deployment to Fedora 22, make sure updates-testing repository is
 enabled. Several last moment bug fixes related to FreeIPA were not
 rolled into the final Fedora 22 image and they are waiting in
 updats-testing for the gates to be open after release.

 One particular area is support for cross-forest trusts with Active
 Directory --- Samba in Fedora 22 got upgraded to 4.2.1 version which
 caused some changes in underlying libraries FreeIPA uses for supporting
 the cross-forest trust. The fixes are awaiting you after install in the
 updats-testing.

 Happy Fedora 22 use!
 --
 / Alexander Bokovoy


 -- Mensaje reenviado --
 From: Jaroslav Reznik jrez...@redhat.com
 To: devel-annou...@lists.fedoraproject.org, test-announce 
 test-annou...@lists.fedoraproject.org, Fedora Logistics List 
 logist...@lists.fedoraproject.org
 Cc:
 Date: Fri, 22 May 2015 14:46:39 -0400 (EDT)
 Subject: [Test-Announce] Fedora 22 Final status is Go, release on May 26,
 2015
 At the Fedora 22 Final Go/No-Go Meeting #2 that just occurred, it was
 agreed to Go with the Fedora 22 Final by Fedora QA, Release Engineering
 and Development.

 Fedora 22 Final will be publicly available on Tuesday, May 26, 2015.

 Meeting details can be seen here:
 Minutes: http://bit.ly/1Bh2pH1
 Log: http://bit.ly/1HzMI5g

 Thank you everyone for a great job, sleepless nights validating TCs,
 RCs, fixing bugs, composing stuf and everything else needed for
 smooth releases. Amazing last three years wrangling releases for me!

 Jaroslav
 ___
 test-announce mailing list
 test-annou...@lists.fedoraproject.org
 https://admin.fedoraproject.org/mailman/listinfo/test-announce
 --
 devel mailing list
 de...@lists.fedoraproject.org
 https://admin.fedoraproject.org/mailman/listinfo/devel
 Fedora Code of Conduct: http://fedoraproject.org/code-of-conduct
 --
 Manage your subscription for the Freeipa-users mailing list:
 https://www.redhat.com/mailman/listinfo/freeipa-users
 Go to http://freeipa.org for more info on the project

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] [[Test-Announce] Fedora 22 Final status is Go, release on May 26, 2015]

2015-05-22 Thread Rob Crittenden

Carlos Raúl Laguna wrote:

Just for clarification,
If i create a user in Windows 2008R2 it propagates to Freeipa 4.1
because freeIPA trust the AD domain, in this  scenario where AD equally
trust the freeIPA domain (Fedora 22), a user created in freeIPA should
not propagate as well to AD ? Regards


Users are not copied, you can reference an AD user from IPA. So you can 
log into an IPA-managed machine using your AD credentials. This does not 
add the AD user to IPA.


Right now you can't reference IPA users in AD resources, in any version 
of IPA. So no logging into Windows using your IPA credentials (yet).


rob




2015-05-22 16:39 GMT-04:00 Alexander Bokovoy aboko...@redhat.com
mailto:aboko...@redhat.com:

On Fri, 22 May 2015, Carlos Raúl Laguna wrote:

Hi Alexander
Great news, does this also mean that user created in freeipa are
self
created/synchronized in the windows ad ? Regtards

With cross-forest trust we don't synchronize anything to AD. Think about
it as if FreeIPA was a separate AD forest, two AD forests don't
synchronize anything to each other, they _refer_ to each other's domain
controllers for operations that require authentication or other changes.

--
/ Alexander Bokovoy






--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


Re: [Freeipa-users] [[Test-Announce] Fedora 22 Final status is Go, release on May 26, 2015]

2015-05-22 Thread Carlos Raúl Laguna
Just for clarification,
If i create a user in Windows 2008R2 it propagates to Freeipa 4.1 because
freeIPA trust the AD domain, in this  scenario where AD equally trust the
freeIPA domain (Fedora 22), a user created in freeIPA should not propagate
as well to AD ? Regards


2015-05-22 16:39 GMT-04:00 Alexander Bokovoy aboko...@redhat.com:

 On Fri, 22 May 2015, Carlos Raúl Laguna wrote:

 Hi Alexander
 Great news, does this also mean that user created in freeipa are self
 created/synchronized in the windows ad ? Regtards

 With cross-forest trust we don't synchronize anything to AD. Think about
 it as if FreeIPA was a separate AD forest, two AD forests don't
 synchronize anything to each other, they _refer_ to each other's domain
 controllers for operations that require authentication or other changes.

 --
 / Alexander Bokovoy

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] [[Test-Announce] Fedora 22 Final status is Go, release on May 26, 2015]

2015-05-22 Thread Alexander Bokovoy

On Fri, 22 May 2015, Carlos Raúl Laguna wrote:

Hi Alexander
Great news, does this also mean that user created in freeipa are self
created/synchronized in the windows ad ? Regtards

With cross-forest trust we don't synchronize anything to AD. Think about
it as if FreeIPA was a separate AD forest, two AD forests don't
synchronize anything to each other, they _refer_ to each other's domain
controllers for operations that require authentication or other changes.

--
/ Alexander Bokovoy

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project