Does this still require the use of kerberos? Will 389-ds work on its own?
----- Original Message -----
From: "Alon Bar-Lev" <alonbl(a)redhat.com>
To: "Itamar Heim" <iheim(a)redhat.com>
Cc: users(a)ovirt.org
Sent: Friday, August 8, 2014 3:45:07 PM
Subject: Re: [ovirt-users] ovirt with 389 server inactive groups
----- Original Message -----
From: "Itamar Heim" <iheim(a)redhat.com>
To: "Paul Robert Marino" <prmarino1(a)gmail.com>, users(a)ovirt.org
Sent: Friday, August 8, 2014 10:37:11 PM
Subject: Re: [ovirt-users] ovirt with 389 server inactive groups
On 08/07/2014 07:06 PM, Paul Robert Marino wrote:
> I have ovirt engine running and connected to a 389 server with the
> memberof plugin enabled and working properly.
>
> I can add users and assign them to roles without any issues.
>
> when I look at a user I can see all the LDAP groups they are a member of.
>
> when I run engine-manage-domains -action=validate it tells me the
> domain is valid.
>
> here is my problem when I try to assign a role to an LDAP group it
> looks like it works but in the general tab when under the group it
> tells me the status is Inactive.
>
> dose any one know how to enable the group?
> _______________________________________________
> Users mailing list
> Users(a)ovirt.org
>
http://lists.ovirt.org/mailman/listinfo/users
>
3.4 or new 3.5 Generic LDAP provider?
On case this is 3.5 it is known issue, all groups will be seen as inactive, this field
will probably be removed from UI, as groups are no longer fetched periodically.
This field is totally ignored.
Alon
_______________________________________________
Users mailing list
Users(a)ovirt.org
http://lists.ovirt.org/mailman/listinfo/users