[Freeipa-users] UPN suffixes in AD trust

Sumit Bose sbose at redhat.com
Wed Jun 24 16:45:26 UTC 2015


On Wed, Jun 24, 2015 at 05:11:07PM +0200, Giorgio Biacchi wrote:
> Hi everybody,
> I established a bidirectional trust between an IPA server (version 4.1.0 on
> CentOS 7.1), ipa.mydomain.local and an AD (Windows 2012 r2), mydomain.local.
> Everything is working fine, and I'm able to authenticate and logon on a linux
> host joined to IPA server using AD credentials (username at mydomain.local).
> But active directory is configured with two more UPN suffixes (otherdomain.com
> and sub.otherdomain.com), and I cannot logon with credentials using alternative
> UPN (example: john.doe at otherdomain.com).
> 
> How can I make this possible? Another trust (ipa trust-add) with the same AD?
> Manual configuration of krb5 and/or sssd?

Have you tried to login to an IPA client or the server? Please try with
an IPA server first. If this does not work it would be nice if you can
send the SSSD log files from the IPA server which are generated during
the logon attempt. Please call 'sss_cache -E' before to invalidate all
cached entries so that the logs will contain all needed calls to AD.

Using UPN suffixes were added to the AD provider some time ago and the
code is available in the IPA provider as well, but I guess no one has
actually tried this before.

bye,
Sumit

> 
> Thanks in advance
> 
> -- 
> gb
> 
> PGP Key: http://pgp.mit.edu/
> Primary key fingerprint: C510 0765 943E EBED A4F2 69D3 16CC DC90 B9CB 0F34
> 
> -- 
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go to http://freeipa.org for more info on the project




More information about the Freeipa-users mailing list