Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Jakub Hrozek
On Tue, Aug 09, 2016 at 03:29:37PM +0200, Troels Hansen wrote: > - On Aug 9, 2016, at 3:16 PM, Jakub Hrozek jhro...@redhat.com wrote: > > >> > >> What does "Cannot handle password prompts" mean? the only thing I can find > >> is > >> some sssd krb5 commits looking to be related to password c

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Troels Hansen
- On Aug 9, 2016, at 3:16 PM, Jakub Hrozek jhro...@redhat.com wrote: >> >> What does "Cannot handle password prompts" mean? the only thing I can find is >> some sssd krb5 commits looking to be related to password change? > > I'm not sure this is related, can you paste more context? Actuall

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Jakub Hrozek
On Tue, Aug 09, 2016 at 03:13:25PM +0200, Troels Hansen wrote: > At least for some users > > One user failing: > > (Tue Aug 9 14:41:37 2016) [[sssd[krb5_child[1360 [unpack_buffer] > (0x0100): cmd [249] uid [1349930179] gid > [1349930179] validate [true] enterprise principal [false] off

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Troels Hansen
At least for some users One user failing: (Tue Aug 9 14:41:37 2016) [[sssd[krb5_child[1360 [unpack_buffer] (0x0100): cmd [249] uid [1349930179] gid [1349930179] validate [true] enterprise principal [false] offline [true] UPN [h...@net.dr.dk] (Tue Aug 9 14:41:37 2016) [[sssd[krb5_chil

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Troels Hansen
- On Aug 9, 2016, at 2:09 PM, Jakub Hrozek jhro...@redhat.com wrote: >> >> So, I currently works in the current RedHat (sssd-ipa-1.13.0-40.el7_2.12) but >> only on the server, but not on a pure IPA client, but will work in 1.14.0 ? > > I would not recommend this setting on the server, eve

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Troels Hansen
- On Aug 9, 2016, at 1:57 PM, Jakub Hrozek jhro...@redhat.com wrote: >> >> If I set it >> "full_name_format = %1$s" > > Yes, This only works with 1.14.0 or newer. >> So, I currently works in the current RedHat (sssd-ipa-1.13.0-40.el7_2.12) but only on the server, but not on a pure IPA cli

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Jakub Hrozek
On Tue, Aug 09, 2016 at 02:04:21PM +0200, Troels Hansen wrote: > - On Aug 9, 2016, at 1:57 PM, Jakub Hrozek jhro...@redhat.com wrote: > > >> > >> If I set it > >> "full_name_format = %1$s" > > > > Yes, This only works with 1.14.0 or newer. > >> > > So, I currently works in the current RedH

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Jakub Hrozek
On Tue, Aug 09, 2016 at 01:45:27PM +0200, Troels Hansen wrote: > Think it was a combination af multiple things, without ever really figuring > out what I have now made it work. > > Mainly, I think it had to do with the "full_name_format" parameter, which > seems to cause problems if being set on

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Troels Hansen
Think it was a combination af multiple things, without ever really figuring out what I have now made it work. Mainly, I think it had to do with the "full_name_format" parameter, which seems to cause problems if being set on the IPA client? If I set it "full_name_format = %1$s" I'm unable to lo

Re: [Freeipa-users] ipa_get_*_acct request failed: [22]: Invalid argument on IPA client when looking up AD users

2016-08-09 Thread Jakub Hrozek
On Tue, Aug 09, 2016 at 12:34:04PM +0200, Troels Hansen wrote: > Hi,I have an sssd client which is currently causing problems when looking up > IPA / AD users. > > # getent passwd drext...@net.dr.dk > returns nothing. > > # getent passwd ad...@linux.dr.dk > ad...@linux.dr.dk:*:1:1:ad