Re: [Freeipa-users] proxy with Active Directory

2012-05-13 Thread Dmitri Pal
@redhat.com Subject: Re: [Freeipa-users] proxy with Active Directory On Wed, 2012-05-09 at 14:19 -0400, Sylvain Angers wrote: Hello Our security group have concern with copying username/password from from AD and might not allow this synchronisation to even happen. Is there a way to configure ipa

Re: [Freeipa-users] proxy with Active Directory

2012-05-10 Thread Brian Cook
@redhat.com Subject: Re: [Freeipa-users] proxy with Active Directory On Wed, 2012-05-09 at 14:19 -0400, Sylvain Angers wrote: Hello Our security group have concern with copying username/password from from AD and might not allow this synchronisation to even happen. Is there a way to configure

Re: [Freeipa-users] proxy with Active Directory

2012-05-10 Thread Simo Sorce
On Thu, 2012-05-10 at 09:27 -0700, Brian Cook wrote: THe problem with the cross realm trust support as I understand it is that it requires you to populate posix attributes in AD, which many AD admins are hesitant to do. You have to install the AD services for unix pack and create metadata

Re: [Freeipa-users] proxy with Active Directory

2012-05-09 Thread Steven Jones
Hi, My understanding is passync intercepts the password before its encrypted in AD and written to the AD's ldap db/disk it cant be decrypted thereafter. It then sends the plain text password via an encrypted link to IPA, so its pretty safe. No there is no easy way I know of, though its

Re: [Freeipa-users] proxy with Active Directory

2012-05-09 Thread Rob Crittenden
Sylvain Angers wrote: Hello Our security group have concern with copying username/password from from AD and might not allow this synchronisation to even happen. Is there a way to configure ipa to go get username/password via kind of proxy? No, the Kerberos credentials don't use the password

Re: [Freeipa-users] proxy with Active Directory

2012-05-09 Thread Rich Megginson
On 05/09/2012 03:11 PM, Steven Jones wrote: Hi, My understanding is passync intercepts the password before its encrypted in AD Yes. and written to the AD's ldap db/disk PassSync writes it to a log file on the windows machine, not to the ldap db. it cant be decrypted thereafter.

Re: [Freeipa-users] proxy with Active Directory

2012-05-09 Thread Steven Jones
...@redhat.com] Sent: Thursday, 10 May 2012 10:15 a.m. To: Sylvain Angers Cc: Freeipa-users@redhat.com Subject: Re: [Freeipa-users] proxy with Active Directory On Wed, 2012-05-09 at 14:19 -0400, Sylvain Angers wrote: Hello Our security group have concern with copying username/password from from AD