[Freeipa-users] WARNING: Existing users or groups do not have a SID identifier assigned

Alexander Bokovoy abokovoy at redhat.com
Fri Feb 24 06:03:21 UTC 2017


On to, 23 helmi 2017, Gady Notrica wrote:
>Hello,
>
>When setting up a trust between IPA and AD I am having the Warning
>below. Question: Is this going to affect the users in Active Directory
>if IPA sync back with AD?
winsync and trust are incompatible options. You are supposed to disable
winsync when switching to trust.

To your question, the attributes that would be added, aren't
synchronized back by winsync. Still, if you are switching from winsync
to trust, disable winsync first.

>
># ipa-adtrust-install
>
>WARNING: 200 existing users or groups do not have a SID identifier assigned.
>Installer can run a task to have ipa-sidgen Directory Server plugin generate
>the SID identifier for all these users. Please note, the in case of a high
>number of users and groups, the operation might lead to high replication
>traffic and performance degradation. Refer to ipa-adtrust-install(1) man page
>for details.
>
>Do you want to run the ipa-sidgen task? [no]:

>-- 
>Manage your subscription for the Freeipa-users mailing list:
>https://www.redhat.com/mailman/listinfo/freeipa-users
>Go to http://freeipa.org for more info on the project


-- 
/ Alexander Bokovoy




More information about the Freeipa-users mailing list