Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Traiano Welcome wrote: Hi Alexander On Tue, Mar 10, 2015 at 12:08 PM, Alexander Bokovoy wrote: On Tue, 10 Mar 2015, Traiano Welcome wrote: However, I'm still not able to authenticate via the ssh->sssd path (I cn get kerberos tickets for ad users via cli though), so I th

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
Hi Alexander On Tue, Mar 10, 2015 at 12:08 PM, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, Traiano Welcome wrote: >> >> However, I'm still not able to authenticate via the ssh->sssd path (I >> cn get kerberos tickets for ad users via cli though), so I think that >> incorrect dc discovery is

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Jakub Hrozek
On Tue, Mar 10, 2015 at 09:47:18AM +0100, Sumit Bose wrote: > On Mon, Mar 09, 2015 at 08:27:05PM -0400, Dmitri Pal wrote: > > On 03/09/2015 03:40 PM, Jakub Hrozek wrote: > > >On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: > > >>On 03/09/2015 02:29 PM, Traiano Welcome wrote: > > >>>Hi A

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Traiano Welcome wrote: However, I'm still not able to authenticate via the ssh->sssd path (I cn get kerberos tickets for ad users via cli though), so I think that incorrect dc discovery is not really the issue here. Instead, it seem the ldap query against the discovered AD do

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
On Mon, Mar 9, 2015 at 9:49 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Traiano Welcome wrote: >> >> Hi Alexander >> >> Thanks for the response: >> >> On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy >> wrote: >>> >>> On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List >>>

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Sumit Bose
On Mon, Mar 09, 2015 at 08:27:05PM -0400, Dmitri Pal wrote: > On 03/09/2015 03:40 PM, Jakub Hrozek wrote: > >On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: > >>On 03/09/2015 02:29 PM, Traiano Welcome wrote: > >>>Hi Alexander > >>> > >>> Thanks for the response: > >>> > >>>On Mon, Mar

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Dmitri Pal
On 03/09/2015 03:40 PM, Jakub Hrozek wrote: On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: On 03/09/2015 02:29 PM, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote:

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Jakub Hrozek
On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: > On 03/09/2015 02:29 PM, Traiano Welcome wrote: > >Hi Alexander > > > > Thanks for the response: > > > >On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy > >wrote: > >>On Mon, 09 Mar 2015, Traiano Welcome wrote: > >>>Hi List > >>> > >>

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Dmitri Pal
On 03/09/2015 02:29 PM, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a "master" primary domain co

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Alexander Bokovoy
On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a "master" primary domain contro

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Traiano Welcome
Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Traiano Welcome wrote: >> >> Hi List >> >> >> I have AD trusts configured and working between an IPA server and a >> "master" primary domain controller (dc-1) in a forest in one

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Alexander Bokovoy
On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a "master" primary domain controller (dc-1) in a forest in one data center. This allows me to connect with SSH to linux servers in the same data-center, authenticating with my A