[Freeipa-users] Can an Active Directory domain be the default domain?

Jakub Hrozek jhrozek at redhat.com
Mon Apr 13 18:25:37 UTC 2015


On Mon, Apr 13, 2015 at 01:02:18PM -0400, David Guertin wrote:
> 
> >Said that, you can set default domain in SSSD configuration on the
> >legacy clients (RHEL 5) as then SSSD will ensure proper fully-qualified
> >name will be sent towards compat tree and non-qualified name can be
> >asked on the client (RHEL 5) side.
> I was able to do this on RHEL 6/sssd 1.11 with "default_domain_suffix =
> middlebury.edu", and it works great. But that command does not work with
> RHEL 5/sssd 1.5. Is there a comparable sssd.conf setting for older sssd
> versions?

I'm afraid there is not. The AD entries in the compat tree are fully
qualified anyway and in the same tree as IPA users, there needs to be a
way to distinguish them..




More information about the Freeipa-users mailing list