Re: [Freeipa-users] IPA Trust AD and Illegal cross-realm ticket

2014-10-15 Thread Sumit Bose
On Wed, Oct 15, 2014 at 04:31:55PM +0200, crony wrote: > Alex, > thank you. Now it works, but not completely: > > 1. > > [leszek@ipa1 ~]$ ssh ipatst03.linux.acme.example.com -l > us...@acme.example.com > Password: > Last login: Wed Oct 15 16:11:27 2014 > > -sh-4.1$ id > uid=127283727(us...@acme.

Re: [Freeipa-users] IPA Trust AD and Illegal cross-realm ticket

2014-10-15 Thread crony
Alex, thank you. Now it works, but not completely: 1. [leszek@ipa1 ~]$ ssh ipatst03.linux.acme.example.com -l us...@acme.example.com Password: Last login: Wed Oct 15 16:11:27 2014 -sh-4.1$ id uid=127283727(us...@acme.example.com) gid=127283727(us...@acme.example.com) grupy=127283727(us...@acme.e

Re: [Freeipa-users] IPA Trust AD and Illegal cross-realm ticket

2014-10-15 Thread Alexander Bokovoy
On Wed, 15 Oct 2014, crony wrote: Hi, I've been following the AD integration guide for IPAv3: http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup My setup is: • 5 domain controllers with Windows 2008 R2 AD DC -> example.com as Forest Root Domain and acme.example.com as transitive child domain