Without creating direct separate trust agreement there is no way out ?
So its like freeipa and sssd stands on same page here.
Both of them learns trust relationships within a forest.
:(
On Wed, Mar 2, 2016 at 1:30 AM, Jakub Hrozek <jhrozek(a)redhat.com> wrote:
On Wed, Mar 02, 2016 at 01:20:24AM +1100, PARTH MONGA wrote:
> Hi Jakub,
>
> Thanks for the prompt reply.
> I understood that cross forest transitive trust is not possible with sssd
> right now.
> But can we make this realistic by introducing freeipa with sssd?
> I've checked there documentation seems like they only support domains in
a
> forest not and to another forest.
> Is this even possible without creating a trust with the second domain
> directly using freeipa?
Yes, you can create separate trust agreements with both forests.
_______________________________________________
sssd-users mailing list
sssd-users(a)lists.fedorahosted.org
https://lists.fedorahosted.org/admin/lists/sssd-users@lists.fedorahosted.org