<div dir="ltr">Thanks for the clarifications, one more question, does FreeIPA support partial or fractional replications? Regards<br></div><div class="gmail_extra"><br><div class="gmail_quote">2015-05-28 0:25 GMT-04:00 Alexander Bokovoy <span dir="ltr"><<a href="mailto:abokovoy@redhat.com" target="_blank">abokovoy@redhat.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On Wed, 27 May 2015, Carlos Raúl Laguna wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Hello Martin, Alexander<br>
<br>
Seem that the time shift is large between us, If i understand correctly,<br>
compat tree will allow me to see all users, regardless they location<br>
Windows or FreeIPA, however the kolab-specific attribute must come from<br>
FreeIPA and Windows AD where the users entries lays. This means creating<br>
custom object classes and attributes for AD schema them update compat<br>
plugin to see the custom attribute.<br>
<br>
The second part where kolab needs to update some value in any of this<br>
attribute, for example mailQuota it would be rejected and therefor it must<br>
be done from Windows AD or FreeIPA, is this correct? Thanks both of you for<br>
your time and input in this matter. Regards<br>
</blockquote></span>
Just to make you absolutely clear: using compat tree will not help you<br>
at all. Nothing else in FreeIPA could help you in getting Kolab to work<br>
with both IPA and AD users at the same time.<br>
<br>
It would be nice if kolab could grow a capability to connect to multiple<br>
LDAP servers at the same time, with non-overlapping user and group<br>
trees. I don't think it is there now and I don't see other possibilities<br>
here.<div class="HOEnZb"><div class="h5"><br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
2015-05-27 4:46 GMT-04:00 Alexander Bokovoy <<a href="mailto:abokovoy@redhat.com" target="_blank">abokovoy@redhat.com</a>>:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On Wed, 27 May 2015, Martin Kosek wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 05/27/2015 10:08 AM, Alexander Bokovoy wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On Wed, 27 May 2015, Martin Kosek wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 05/26/2015 07:36 PM, Carlos Raúl Laguna wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Hello Martin,<br>
<br>
The email deployment it is a groupware in this scenario Kolab, kolab<br>
use<br>
389 ad as main backend and it require some kolab ldap specific<br>
attribute to<br>
work properly, this is not a problem in fact is quite easy to use<br>
freeipa<br>
as kolab backend, so far so good but the romance only get this far.<br>
Since<br>
we also use Windows Ad with forest-trust not all user are present in<br>
the<br>
FreeIPA directory and there it is where my problem lays. Since not all<br>
user<br>
are in the same box it become difficult to implement one mail system<br>
for<br>
all users. Regards<br>
<br>
</blockquote>
<br>
As I said, we have compat tree that allows LDAP BIND authentication and<br>
LDAP<br>
identity (not enumeration) for both IPA users and AD users when realm<br>
is in<br>
place.<br>
<br>
You can even update the configuration of the compat tree and add the<br>
kolab<br>
specific fields to be generated there too. There was very similar<br>
request on<br>
freeipa-users. It was for vSphere, but dealing with very similar use<br>
case and<br>
the final solution:<br>
<br>
<a href="http://www.freeipa.org/page/HowTo/vsphere5_integration" target="_blank">http://www.freeipa.org/page/HowTo/vsphere5_integration</a><br>
<br>
Would that approach work for you?<br>
<br>
</blockquote>
I don't think it will work. compat tree is run-time read-only view of<br>
the data coming from somewhere else. You need to have Kolab-specific<br>
data available somewhere to be able to inject it in the compat tree.<br>
Where would that data be stored for Kolab for AD-specific entries?<br>
<br>
</blockquote>
<br>
It would work as long as the attributes are in the "real" user entries in<br>
form<br>
of custom attributes and compat plugin can be updated to add those to<br>
compat view.<br>
<br>
</blockquote>
What real user entries you are talking about for AD users?<br>
<br>
Additionally, Kolab wants to modify these custom attributes and compat<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
tree simply does not support modification, they all are refused.<br>
<br>
</blockquote>
<br>
If Kolab requires modifications, then this approach would not work with<br>
current<br>
FreeIPA implementation, yes.<br>
<br>
</blockquote>
No, we are not going into enabling modifications over compat tree, this<br>
is simply impossible to achieve, sorry.<br>
--<br>
/ Alexander Bokovoy<br>
<br>
</blockquote></blockquote>
<br>
</div></div><span class="HOEnZb"><font color="#888888"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
-- <br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go to <a href="http://freeipa.org" target="_blank">http://freeipa.org</a> for more info on the project<br>
</blockquote>
<br>
<br>
-- <br>
/ Alexander Bokovoy<br>
</font></span></blockquote></div><br></div>