[Freeipa-users] Possible bug in SSSD/IPA/AD trust

Troels Hansen th at casalogic.dk
Tue Aug 23 06:42:42 UTC 2016



----- On Aug 11, 2016, at 3:56 PM, Jakub Hrozek jhrozek at redhat.com wrote:

> On Thu, Aug 11, 2016 at 03:11:10PM +0200, Troels Hansen wrote:
>> Hi, we are curretly workig on a larger IPA test project and I have a problems
>> which have been buggin me for some time now:
> 
> Which version?

Most recent in Red Hat 7.

SSSD 1.13.0-40.el7_2.12
IPA 4.2.0-15.el7_2.18

>> 
>> On the client we are have set "full_name_format = %1$s" to have users presented
>> without the AD domain part.
>> However, this seems to make SSSD not lookup a users group membership?
> 
> This only works with sssd-1.14+
> 

But it actually works? The username is presented correctly (without domain part) if set, and the parameter is documented in `man sssd.conf`?
Only group lookup fails.




More information about the Freeipa-users mailing list