[Freeipa-users] UPN suffixes in AD trust

Giorgio Biacchi giorgio at di.unimi.it
Wed Jun 24 15:11:07 UTC 2015


Hi everybody,
I established a bidirectional trust between an IPA server (version 4.1.0 on
CentOS 7.1), ipa.mydomain.local and an AD (Windows 2012 r2), mydomain.local.
Everything is working fine, and I'm able to authenticate and logon on a linux
host joined to IPA server using AD credentials (username at mydomain.local).
But active directory is configured with two more UPN suffixes (otherdomain.com
and sub.otherdomain.com), and I cannot logon with credentials using alternative
UPN (example: john.doe at otherdomain.com).

How can I make this possible? Another trust (ipa trust-add) with the same AD?
Manual configuration of krb5 and/or sssd?

Thanks in advance

-- 
gb

PGP Key: http://pgp.mit.edu/
Primary key fingerprint: C510 0765 943E EBED A4F2 69D3 16CC DC90 B9CB 0F34




More information about the Freeipa-users mailing list