Discussion:
[Freeipa-users] Confused: LDAP authentication of AD users
Dan Dietterich
2017-05-16 20:55:40 UTC
Permalink
With a one-way trust from FreeIPA 4.4 to Active Directory on WinServ2012r2, I am trying to use FreeIPA LDAP for user authentication.
Is that supposed to work?
Jason B. Nance
2017-05-16 22:02:46 UTC
Permalink
Hi Dan
Post by Dan Dietterich
With a one-way trust from FreeIPA 4.4 to Active Directory on WinServ2012r2, I am
trying to use FreeIPA LDAP for user authentication.
Is that supposed to work?
In the way you have described it, no. AD users/groups will not be in the FreeIPA LDAP. So attempting to authenticate a Windows user by pointing an LDAP client at a FreeIPA server will fail.

Installing the FreeIPA client on a Linux host and enrolling it in an IPA domain with a trust to an Active Directory domain will allow you to authenticate Windows users on the Linux host. This is done using SSSD, among other things.

Regards,

j

Continue reading on narkive:
Search results for '[Freeipa-users] Confused: LDAP authentication of AD users' (Questions and Answers)
6
replies
what is internet love ?
started 2006-02-11 18:44:19 UTC
family & relationships
Loading...