[Freeipa-devel] [PATCH] 0196 trusts: format Kerberos principal properly when fetching trust topology

Tomas Babej tbabej at redhat.com
Mon Aug 24 08:44:26 UTC 2015



On 08/20/2015 02:21 PM, Alexander Bokovoy wrote:
> Hi,
> 
> one more fix for the problem with trusts that Scott Poore found when
> verifying fixes to bug https://bugzilla.redhat.com/show_bug.cgi?id=1250190
> 
> Details are in the commit message.
> 
> 
> 

ACK, this fixes the issue in case of two-way trusts.

$ echo Secret123456 | ipa trust-add --type=ad ad.test --range-type
ipa-ad-trust --admin Administrator --password --two-way=TRUE
------------------------------------------------
Added Active Directory trust for realm "ad.test"
------------------------------------------------
  Realm name: ad.test
  Domain NetBIOS name: AD
...
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified

$ ipa idrange-find
----------------
3 ranges matched
----------------
  Range name: AD.TEST_id_range
...
  Range type: Active Directory domain range

  Range name: IPA.TEST_id_range
...
  Range type: local domain range

  Range name: SUB.AD.TEST_id_range
...
  Range type: Active Directory domain range
----------------------------
Number of entries returned 3
----------------------------

Tomas




More information about the Freeipa-devel mailing list