[Freeipa-users] Are there active plans to allow AD trust users to login to the FreeIPA webUI?

nathan at nathanpeters.com nathan at nathanpeters.com
Fri May 8 16:25:25 UTC 2015


We have all of our users in a trusted Active Directory domain and it would
be nice to allow them to administer our DNS using their AD accounts.

I tried creating a group called DNS administrators and assigning it the
DNS administrator privilege and then adding my ad_domain_admin group
(containing the nested external group containing my ad groups), but when I
try to login to the webui it denies me access.

I see a ticket here regarding allowing this :
https://fedorahosted.org/freeipa/ticket/3242

It doesn't look like anything has happened on that ticket in the last 15
months though.

Any idea if / when this will be implemented?





More information about the Freeipa-users mailing list