[Freeipa-users] How to check IPA <--> AD trust from command line

Sumit Bose sbose at redhat.com
Tue Jan 6 15:41:28 UTC 2015


On Tue, Jan 06, 2015 at 07:19:15AM -0700, Rich Megginson wrote:
> On 01/05/2015 08:35 PM, Ben .T.George wrote:
> >
> >Hi LIst,
> >
> >how to check IPA <-> Active directory trust relationship . i just want to
> >confirm my ipa server is working fine.
> 
> On an IPA server or client machine:
> $ kinit adusername at ADDOMAIN.COM
> Password: aduserpassword
> 
> If there are no AD users yet, you can try with administrator at ADDOMAIN.COM
> assuming you have the AD admin password.

Additionally you have to check if the AD user can get a ticket for an IPA
service e.g. after calling kinit with the AD user call

kvno ldap/ipaserver.ipa.domain at IPA.DOMAIN

bye,
Sumit

> 
> >
> >Regards,
> >Ben
> >
> >
> 

> -- 
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go To http://freeipa.org for more info on the project




More information about the Freeipa-users mailing list