[Freeipa-users] cross realm trust - SID doesn't resolve

Dmitri Pal dpal at redhat.com
Mon Dec 10 17:36:12 UTC 2012


On 12/10/2012 12:04 PM, Brian Cook wrote:
> Okay, I'll open an RFE.  Fwiw, when AD can't resolve a SID for any reason, it does display the SID itself but only as a fallback mechanism.  I think this would be acceptable behavior.


Now I think you understand why it is a tech preview.
You hit right away couple things that QE was also expecting to work.

>
> -Brian
>
>
>
> On Dec 10, 2012, at 4:12 AM, Alexander Bokovoy <abokovoy at redhat.com> wrote:
>
>> On Sun, 09 Dec 2012, Brian Cook wrote:
>>> Good to know my setup is working, but for administration purposes
>>> displaying a SID in the GUI is as useless as displaying UID's with no
>>> user name.  SID's are not meant for human eyes.  Is there some issue
>>> with resolving it to the name and displaying the name instead?  Should
>>> I open an RFE?
>> Since resolving SID means contacting AD's global catalog, there might be
>> delays and even failure. I'll see how we can do it in a safe way.
>>
>> Please add an RFE.
>>
>> -- 
>> / Alexander Bokovoy
>
> _______________________________________________
> Freeipa-users mailing list
> Freeipa-users at redhat.com
> https://www.redhat.com/mailman/listinfo/freeipa-users


-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager for IdM portfolio
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/






More information about the Freeipa-users mailing list