On 11/21/2011 11:43 AM, Ondrej Valousek wrote:
On 11/21/2011 05:41 PM, Ondrej Valousek wrote:
Ok then there is probably nothing to file as I can always use the 'net ads join' options that John mentioned earlier in this thread.
Thanks all involved anyway...
Maybe there is one thing I can do. File a RFE about extending IPA schema to contain a similar attributes in the IPA domain, too. Does it make any sense?
_______________________________________________ sssd-devel mailing list sssd-devel@lists.fedorahosted.org https://fedorahosted.org/mailman/listinfo/sssd-devel
Interesting enough this feature was considered from the very beginning. See item 1.3.5.2  http://freeipa.org/page/V2BPRD#1._Machine_Identity_and_Authentication
But during design the same concerns were risen.

I have a question: can this attribute be made reliable meaning that it adequately reflect the reality?
We could not figure out how to make it happen during the design.  If it can't be made such, is it really useful? Would it be used or administrators will try, see that it does not work out and abandon the idea? We have so many things in front of us. Is it really something that would be usable? Can it be made usable?
If yes, let us file the ticket...

-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager IPA project,
Red Hat Inc.


-------------------------------
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/