On (01/06/14 21:10), steve wrote: >On Sun, 2014-06-01 at 18:17 +0200, Jakub Hrozek wrote: >> On Sat, May 31, 2014 at 04:53:31PM +0200, Lukas Slebodnik wrote: >> > >(Sat May 31 16:25:29 2014) [sssd[be[hh3.site]]] [ad_gpo_access_done] >> > >(0x0040): GPO-based access control failed. >> > ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ >> > You can change value of option ad_gpo_access_control to disable. >> > Default value is permissive. I would say it is a bug that we fail in >> > permissive >> > mode. Details are in manual page sssd-ad. >> > >> > LS >> >> Yes, I agree, but there's a patch on the list already. Let's review it >> for beta2! > >Hi >Just a user pov. Please could we have the fewest possible non default >settings for sssd.conf? > >Please note that we are not microsoft, we use samba 4 so maybe the >default values should be checked against pure AD first? IIRC, it is reproducible with AD as well.
LS _______________________________________________ sssd-users mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/sssd-users
