[Freeipa-users] FreeIPA - AD trust - SSH Public Keys

Taras Drach tsdrach at gmail.com
Thu Nov 3 15:23:06 UTC 2016


Thank for reply,

Unfortunately sssd won’t start with this configuration

Here is part of log

(Thu Nov  3 15:16:40 2016) [sssd[be[ipa.test.loc]]] [sdap_extend_map] (0x0200): 1 extra attributes
(Thu Nov  3 15:16:40 2016) [sssd[be[ipa.test.loc]]] [sdap_extend_map] (0x0010): Attribute sshPublicKey (altSecurityIdentities in LDAP) is already used by SSSD, please choose a different cache name
(Thu Nov  3 15:16:40 2016) [sssd[be[ipa.test.loc]]] [load_backend_module] (0x0010): Error (1432158241) in module (ipa) initialization (sssm_ipa_id_init)!
(Thu Nov  3 15:16:40 2016) [sssd[be[ipa.test.loc]]] [be_process_init] (0x0010): fatal error initializing data providers
(Thu Nov  3 15:16:40 2016) [sssd[be[ipa.test.loc]]] [sbus_remove_watch] (0x2000): 0x7f8183df2640/0x7f8183df2420

Config changes:

   ldap_user_extra_attrs = sshPublicKey:altSecurityIdentities
#   ldap_user_extra_attrs = altSecurityIdentities:altSecurityIdentities
   ldap_user_ssh_public_key = altSecurityIdentities
   ldap_id_mapping = False

> On Nov 3, 2016, at 5:05 PM, Sumit Bose <sbose at redhat.com> wrote:
> 
>  sshPublicKey:

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 832 bytes
Desc: Message signed with OpenPGP using GPGMail
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20161103/d8601b99/attachment.sig>


More information about the Freeipa-users mailing list