From jhorne at skopos.us Mon Apr 22 17:58:00 2013 Content-Type: multipart/mixed; boundary="===============1189879608554314859==" MIME-Version: 1.0 From: Jonathan Horne To: users at ovirt.org Subject: [Users] AD authentication for ovirt manager Date: Mon, 22 Apr 2013 21:57:47 +0000 Message-ID: <9BE6F493F83A594DA60C45E6A09DC5AC2EFD3FF5@AUSP01DAG0201> --===============1189879608554314859== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable --_000_9BE6F493F83A594DA60C45E6A09DC5AC2EFD3FF5AUSP01DAG0201_ Content-Type: text/plain; charset=3D"us-ascii" Content-Transfer-Encoding: quoted-printable Is there a write up out there for setting up ovirt users and adminstrators = =3D to authenticate into the portal via AD? Thanks, Jonathan ________________________________ This is a PRIVATE message. If you are not the intended recipient, please de= =3D lete without copying and kindly advise us by e-mail of the mistake in deliv= =3D ery. NOTE: Regardless of content, this e-mail shall not operate to bind SKO= =3D POS to any order or other contract unless pursuant to explicit written agre= =3D ement or government initiative expressly permitting the use of e-mail for s= =3D uch purpose. --_000_9BE6F493F83A594DA60C45E6A09DC5AC2EFD3FF5AUSP01DAG0201_ Content-Type: text/html; charset=3D"us-ascii" Content-Transfer-Encoding: quoted-printable

Is there a write up out there for setting up ovirt= u=3D sers and adminstrators to authenticate into the portal via AD?

 

Thanks,

Jonathan

 



This is a PRIVATE mess= age. I=3D f you are not the intended recipient, please delete without copying and kin= =3D dly advise us by e-mail of the mistake in delivery. NOTE: Regardless of con= =3D tent, this e-mail shall not operate to bind SKOPOS to any order or other contract unless pursuant to explicit wri= =3D tten agreement or government initiative expressly permitting the use of e-m= =3D ail for such purpose. --_000_9BE6F493F83A594DA60C45E6A09DC5AC2EFD3FF5AUSP01DAG0201_-- --===============1189879608554314859== Content-Type: multipart/alternative MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.bin" LS1fMDAwXzlCRTZGNDkzRjgzQTU5NERBNjBDNDVFNkEwOURDNUFDMkVGRDNGRjVBVVNQMDFEQUcw MjAxXwpDb250ZW50LVR5cGU6IHRleHQvcGxhaW47IGNoYXJzZXQ9InVzLWFzY2lpIgpDb250ZW50 LVRyYW5zZmVyLUVuY29kaW5nOiBxdW90ZWQtcHJpbnRhYmxlCgpJcyB0aGVyZSBhIHdyaXRlIHVw IG91dCB0aGVyZSBmb3Igc2V0dGluZyB1cCBvdmlydCB1c2VycyBhbmQgYWRtaW5zdHJhdG9ycyA9 CnRvIGF1dGhlbnRpY2F0ZSBpbnRvIHRoZSBwb3J0YWwgdmlhIEFEPwoKVGhhbmtzLApKb25hdGhh bgoKCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fClRoaXMgaXMgYSBQUklWQVRFIG1l c3NhZ2UuIElmIHlvdSBhcmUgbm90IHRoZSBpbnRlbmRlZCByZWNpcGllbnQsIHBsZWFzZSBkZT0K bGV0ZSB3aXRob3V0IGNvcHlpbmcgYW5kIGtpbmRseSBhZHZpc2UgdXMgYnkgZS1tYWlsIG9mIHRo ZSBtaXN0YWtlIGluIGRlbGl2PQplcnkuIE5PVEU6IFJlZ2FyZGxlc3Mgb2YgY29udGVudCwgdGhp cyBlLW1haWwgc2hhbGwgbm90IG9wZXJhdGUgdG8gYmluZCBTS089ClBPUyB0byBhbnkgb3JkZXIg b3Igb3RoZXIgY29udHJhY3QgdW5sZXNzIHB1cnN1YW50IHRvIGV4cGxpY2l0IHdyaXR0ZW4gYWdy ZT0KZW1lbnQgb3IgZ292ZXJubWVudCBpbml0aWF0aXZlIGV4cHJlc3NseSBwZXJtaXR0aW5nIHRo ZSB1c2Ugb2YgZS1tYWlsIGZvciBzPQp1Y2ggcHVycG9zZS4KCi0tXzAwMF85QkU2RjQ5M0Y4M0E1 OTREQTYwQzQ1RTZBMDlEQzVBQzJFRkQzRkY1QVVTUDAxREFHMDIwMV8KQ29udGVudC1UeXBlOiB0 ZXh0L2h0bWw7IGNoYXJzZXQ9InVzLWFzY2lpIgpDb250ZW50LVRyYW5zZmVyLUVuY29kaW5nOiBx dW90ZWQtcHJpbnRhYmxlCgo8aHRtbD4KPGhlYWQ+CjxtZXRhIGh0dHAtZXF1aXY9M0QiQ29udGVu dC1UeXBlIiBjb250ZW50PTNEInRleHQvaHRtbDsgY2hhcnNldD0zRHVzLWFzY2lpIj0KPgo8c3R5 bGU+CjwhLS0KQGZvbnQtZmFjZQoJe2ZvbnQtZmFtaWx5OkNhbGlicml9CkBmb250LWZhY2UKCXtm b250LWZhbWlseTpUYWhvbWF9CnAuTXNvTm9ybWFsLCBsaS5Nc29Ob3JtYWwsIGRpdi5Nc29Ob3Jt YWwKCXttYXJnaW46MGluOwoJbWFyZ2luLWJvdHRvbTouMDAwMXB0OwoJZm9udC1zaXplOjExLjBw dDsKCWZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiJ9CmE6bGluaywgc3Bhbi5Nc29I eXBlcmxpbmsKCXtjb2xvcjpibHVlOwoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZX0KYTp2aXNp dGVkLCBzcGFuLk1zb0h5cGVybGlua0ZvbGxvd2VkCgl7Y29sb3I6cHVycGxlOwoJdGV4dC1kZWNv cmF0aW9uOnVuZGVybGluZX0KcC5Nc29BY2V0YXRlLCBsaS5Nc29BY2V0YXRlLCBkaXYuTXNvQWNl dGF0ZQoJe21hcmdpbjowaW47CgltYXJnaW4tYm90dG9tOi4wMDAxcHQ7Cglmb250LXNpemU6OC4w cHQ7Cglmb250LWZhbWlseToiVGFob21hIiwic2Fucy1zZXJpZiJ9CnNwYW4uRW1haWxTdHlsZTE3 Cgl7Zm9udC1mYW1pbHk6IkNhbGlicmkiLCJzYW5zLXNlcmlmIjsKCWNvbG9yOndpbmRvd3RleHR9 CnNwYW4uQmFsbG9vblRleHRDaGFyCgl7Zm9udC1mYW1pbHk6IlRhaG9tYSIsInNhbnMtc2VyaWYi fQouTXNvQ2hwRGVmYXVsdAoJe2ZvbnQtZmFtaWx5OiJDYWxpYnJpIiwic2Fucy1zZXJpZiJ9CkBw YWdlIFdvcmRTZWN0aW9uMQoJe21hcmdpbjoxLjBpbiAxLjBpbiAxLjBpbiAxLjBpbn0KZGl2Lldv cmRTZWN0aW9uMQoJe30KLS0+Cjwvc3R5bGU+CjwvaGVhZD4KPGJvZHkgbGFuZz0zRCJFTi1VUyIg bGluaz0zRCJibHVlIiB2bGluaz0zRCJwdXJwbGUiPgo8ZGl2IGNsYXNzPTNEIldvcmRTZWN0aW9u MSI+CjxwIGNsYXNzPTNEIk1zb05vcm1hbCI+SXMgdGhlcmUgYSB3cml0ZSB1cCBvdXQgdGhlcmUg Zm9yIHNldHRpbmcgdXAgb3ZpcnQgdT0Kc2VycyBhbmQgYWRtaW5zdHJhdG9ycyB0byBhdXRoZW50 aWNhdGUgaW50byB0aGUgcG9ydGFsIHZpYSBBRD88L3A+CjxwIGNsYXNzPTNEIk1zb05vcm1hbCI+ Jm5ic3A7PC9wPgo8cCBjbGFzcz0zRCJNc29Ob3JtYWwiPlRoYW5rcyw8L3A+CjxwIGNsYXNzPTNE Ik1zb05vcm1hbCI+Sm9uYXRoYW4gPC9wPgo8cCBjbGFzcz0zRCJNc29Ob3JtYWwiPiZuYnNwOzwv cD4KPC9kaXY+Cjxicj4KPGhyPgo8Zm9udCBjb2xvcj0zRCJHcmF5IiBmYWNlPTNEIkFyaWFsIiBz aXplPTNEIjEiPlRoaXMgaXMgYSBQUklWQVRFIG1lc3NhZ2UuIEk9CmYgeW91IGFyZSBub3QgdGhl IGludGVuZGVkIHJlY2lwaWVudCwgcGxlYXNlIGRlbGV0ZSB3aXRob3V0IGNvcHlpbmcgYW5kIGtp bj0KZGx5IGFkdmlzZSB1cyBieSBlLW1haWwgb2YgdGhlIG1pc3Rha2UgaW4gZGVsaXZlcnkuIE5P VEU6IFJlZ2FyZGxlc3Mgb2YgY29uPQp0ZW50LCB0aGlzIGUtbWFpbCBzaGFsbCBub3Qgb3BlcmF0 ZSB0bwogYmluZCBTS09QT1MgdG8gYW55IG9yZGVyIG9yIG90aGVyIGNvbnRyYWN0IHVubGVzcyBw dXJzdWFudCB0byBleHBsaWNpdCB3cmk9CnR0ZW4gYWdyZWVtZW50IG9yIGdvdmVybm1lbnQgaW5p dGlhdGl2ZSBleHByZXNzbHkgcGVybWl0dGluZyB0aGUgdXNlIG9mIGUtbT0KYWlsIGZvciBzdWNo IHB1cnBvc2UuPC9mb250Pgo8L2JvZHk+CjwvaHRtbD4KCi0tXzAwMF85QkU2RjQ5M0Y4M0E1OTRE QTYwQzQ1RTZBMDlEQzVBQzJFRkQzRkY1QVVTUDAxREFHMDIwMV8tLQo= --===============1189879608554314859==-- From christianh at 4over.com Mon Apr 22 18:17:54 2013 Content-Type: multipart/mixed; boundary="===============8293037027187505850==" MIME-Version: 1.0 From: Christian Hernandez To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Mon, 22 Apr 2013 15:17:10 -0700 Message-ID: In-Reply-To: 9BE6F493F83A594DA60C45E6A09DC5AC2EFD3FF5@AUSP01DAG0201 --===============8293037027187505850== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Hello Jonathan, I believe you can use the Red Hat Documentation for this. https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtu= alization/3.1/html/Evaluation_Guide/Evaluation_Guide-VDI.html#Evaluation_Gu= ide-Add_Active_Directory One of the "gotchas" that I ran into is that you need to specify the Active Directory as your DNS provider in your resolv.conf file (not sure if it was coincidence or not; but I ran into some issues that went away when I did this) HTH Thank you, Christian Hernandez 1225 Los Angeles Street Glendale, CA 91204 Phone: 877-782-2737 ext. 4566 Fax: 818-265-3152 christianh(a)4over.com www.4over.com On Mon, Apr 22, 2013 at 2:57 PM, Jonathan Horne wrote: > Is there a write up out there for setting up ovirt users and > adminstrators to authenticate into the portal via AD? > > > > Thanks, > > Jonathan > > > > ------------------------------ > This is a PRIVATE message. If you are not the intended recipient, please > delete without copying and kindly advise us by e-mail of the mistake in > delivery. NOTE: Regardless of content, this e-mail shall not operate to > bind SKOPOS to any order or other contract unless pursuant to explicit > written agreement or government initiative expressly permitting the use of > e-mail for such purpose. > > _______________________________________________ > Users mailing list > Users(a)ovirt.org > http://lists.ovirt.org/mailman/listinfo/users > > --===============8293037027187505850== Content-Type: text/html MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.html" PGRpdiBkaXI9Imx0ciI+PGRpdj48ZGl2PjxkaXY+SGVsbG8gSm9uYXRoYW4sPGJyPjxicj48L2Rp dj5JIGJlbGlldmUgeW91IGNhbiB1c2UgdGhlIFJlZCBIYXQgRG9jdW1lbnRhdGlvbiBmb3IgdGhp cy48YnI+PGJyPjxhIGhyZWY9Imh0dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVu dGF0aW9uL2VuLVVTL1JlZF9IYXRfRW50ZXJwcmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9F dmFsdWF0aW9uX0d1aWRlL0V2YWx1YXRpb25fR3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlk ZS1BZGRfQWN0aXZlX0RpcmVjdG9yeSI+aHR0cHM6Ly9hY2Nlc3MucmVkaGF0LmNvbS9zaXRlL2Rv Y3VtZW50YXRpb24vZW4tVVMvUmVkX0hhdF9FbnRlcnByaXNlX1ZpcnR1YWxpemF0aW9uLzMuMS9o dG1sL0V2YWx1YXRpb25fR3VpZGUvRXZhbHVhdGlvbl9HdWlkZS1WREkuaHRtbCNFdmFsdWF0aW9u X0d1aWRlLUFkZF9BY3RpdmVfRGlyZWN0b3J5PC9hPjxicj4KCjxicj48L2Rpdj5PbmUgb2YgdGhl ICZxdW90O2dvdGNoYXMmcXVvdDsgdGhhdCBJIHJhbiBpbnRvIGlzIHRoYXQgeW91IG5lZWQgdG8g c3BlY2lmeSB0aGUgQWN0aXZlIERpcmVjdG9yeSBhcyB5b3VyIEROUyBwcm92aWRlciBpbiB5b3Vy IHJlc29sdi5jb25mIGZpbGUgKG5vdCBzdXJlIGlmIGl0IHdhcyBjb2luY2lkZW5jZSBvciBub3Q7 IGJ1dCBJIHJhbiBpbnRvIHNvbWUgaXNzdWVzIHRoYXQgd2VudCBhd2F5IHdoZW4gSSBkaWQgdGhp cyk8YnI+Cgo8YnI+PC9kaXY+SFRIPGJyPjwvZGl2PjxkaXYgY2xhc3M9ImdtYWlsX2V4dHJhIj48 YnIgY2xlYXI9ImFsbCI+PGRpdj48ZGl2IGRpcj0ibHRyIj48ZGl2Pjxicj5UaGFuayB5b3UsPGJy Pjxicj5DaHJpc3RpYW4gSGVybmFuZGV6PGJyPjwvZGl2PjEyMjUgTG9zIEFuZ2VsZXMgU3RyZWV0 PGJyPjxkaXY+R2xlbmRhbGUsIENBIDkxMjA0PGJyPgpQaG9uZTogPGEgdmFsdWU9IisxODc3Nzgy MjczNyI+ODc3LTc4Mi0yNzM3IGV4dC4gNDU2NjwvYT48YnI+RmF4OiA8YSB2YWx1ZT0iKzE4MTgy NjUzMTUyIj44MTgtMjY1LTMxNTI8L2E+PGJyPjxhIGhyZWY9Im1haWx0bzpjaHJpc3RpYW5oQDRv dmVyLmNvbSIgdGFyZ2V0PSJfYmxhbmsiPmNocmlzdGlhbmhANG92ZXIuY29tPC9hPiAmbHQ7bWFp bHRvOjxhIGhyZWY9Im1haWx0bzpjaHJpc3RpYW5oQDRvdmVyLmNvbSIgdGFyZ2V0PSJfYmxhbmsi PmNocmlzdGlhbmhANG92ZXIuY29tPC9hPiZndDsgPGJyPgoKPGEgaHJlZj0iaHR0cDovL3d3dy40 b3Zlci5jb20vIiB0YXJnZXQ9Il9ibGFuayI+d3d3LjRvdmVyLmNvbTwvYT4gJmx0OzxhIGhyZWY9 Imh0dHA6Ly93d3cuNG92ZXIuY29tLyIgdGFyZ2V0PSJfYmxhbmsiPmh0dHA6Ly93d3cuNG92ZXIu Y29tPC9hPiZndDs8L2Rpdj48L2Rpdj48L2Rpdj4KPGJyPjxicj48ZGl2IGNsYXNzPSJnbWFpbF9x dW90ZSI+T24gTW9uLCBBcHIgMjIsIDIwMTMgYXQgMjo1NyBQTSwgSm9uYXRoYW4gSG9ybmUgPHNw YW4gZGlyPSJsdHIiPiZsdDs8YSBocmVmPSJtYWlsdG86amhvcm5lQHNrb3Bvcy51cyIgdGFyZ2V0 PSJfYmxhbmsiPmpob3JuZUBza29wb3MudXM8L2E+Jmd0Ozwvc3Bhbj4gd3JvdGU6PGJyPjxibG9j a3F1b3RlIGNsYXNzPSJnbWFpbF9xdW90ZSIgc3R5bGU9Im1hcmdpbjowIDAgMCAuOGV4O2JvcmRl ci1sZWZ0OjFweCAjY2NjIHNvbGlkO3BhZGRpbmctbGVmdDoxZXgiPgoKCgoKCgo8ZGl2IGxpbms9 ImJsdWUiIHZsaW5rPSJwdXJwbGUiIGxhbmc9IkVOLVVTIj4KPGRpdj4KPHAgY2xhc3M9Ik1zb05v cm1hbCI+SXMgdGhlcmUgYSB3cml0ZSB1cCBvdXQgdGhlcmUgZm9yIHNldHRpbmcgdXAgb3ZpcnQg dXNlcnMgYW5kIGFkbWluc3RyYXRvcnMgdG8gYXV0aGVudGljYXRlIGludG8gdGhlIHBvcnRhbCB2 aWEgQUQ/PC9wPgo8cCBjbGFzcz0iTXNvTm9ybWFsIj6gPC9wPgo8cCBjbGFzcz0iTXNvTm9ybWFs Ij5UaGFua3MsPC9wPgo8cCBjbGFzcz0iTXNvTm9ybWFsIj5Kb25hdGhhbiA8L3A+CjxwIGNsYXNz PSJNc29Ob3JtYWwiPqA8L3A+CjwvZGl2Pgo8YnI+Cjxocj4KPGZvbnQgY29sb3I9IkdyYXkiIGZh Y2U9IkFyaWFsIiBzaXplPSIxIj5UaGlzIGlzIGEgUFJJVkFURSBtZXNzYWdlLiBJZiB5b3UgYXJl IG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCBwbGVhc2UgZGVsZXRlIHdpdGhvdXQgY29weWlu ZyBhbmQga2luZGx5IGFkdmlzZSB1cyBieSBlLW1haWwgb2YgdGhlIG1pc3Rha2UgaW4gZGVsaXZl cnkuIE5PVEU6IFJlZ2FyZGxlc3Mgb2YgY29udGVudCwgdGhpcyBlLW1haWwgc2hhbGwgbm90IG9w ZXJhdGUgdG8KIGJpbmQgU0tPUE9TIHRvIGFueSBvcmRlciBvciBvdGhlciBjb250cmFjdCB1bmxl c3MgcHVyc3VhbnQgdG8gZXhwbGljaXQgd3JpdHRlbiBhZ3JlZW1lbnQgb3IgZ292ZXJubWVudCBp bml0aWF0aXZlIGV4cHJlc3NseSBwZXJtaXR0aW5nIHRoZSB1c2Ugb2YgZS1tYWlsIGZvciBzdWNo IHB1cnBvc2UuPC9mb250Pgo8L2Rpdj4KCjxicj5fX19fX19fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fXzxicj4KVXNlcnMgbWFpbGluZyBsaXN0PGJyPgo8YSBocmVmPSJt YWlsdG86VXNlcnNAb3ZpcnQub3JnIj5Vc2Vyc0BvdmlydC5vcmc8L2E+PGJyPgo8YSBocmVmPSJo dHRwOi8vbGlzdHMub3ZpcnQub3JnL21haWxtYW4vbGlzdGluZm8vdXNlcnMiIHRhcmdldD0iX2Js YW5rIj5odHRwOi8vbGlzdHMub3ZpcnQub3JnL21haWxtYW4vbGlzdGluZm8vdXNlcnM8L2E+PGJy Pgo8YnI+PC9ibG9ja3F1b3RlPjwvZGl2Pjxicj48L2Rpdj4K --===============8293037027187505850==-- From medievalist at gmail.com Tue Apr 23 10:09:32 2013 Content-Type: multipart/mixed; boundary="===============1505153405138572925==" MIME-Version: 1.0 From: Charlie To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Tue, 23 Apr 2013 10:09:30 -0400 Message-ID: In-Reply-To: CAH3k4=eguq-8KpKSHadHBaHFJKkd_Qjx5-jeTqFraphvX8L-0A@mail.gmail.com --===============1505153405138572925== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Also set your Active Directory source as your time synchronization provider. You need DNS, Directory services, Kerberos and network time all from the same source if you want anything approaching reliability. --Charlie On Mon, Apr 22, 2013 at 6:17 PM, Christian Hernandez wrote: > Hello Jonathan, > > I believe you can use the Red Hat Documentation for this. > > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Vir= tualization/3.1/html/Evaluation_Guide/Evaluation_Guide-VDI.html#Evaluation_= Guide-Add_Active_Directory > > One of the "gotchas" that I ran into is that you need to specify the Acti= ve > Directory as your DNS provider in your resolv.conf file (not sure if it w= as > coincidence or not; but I ran into some issues that went away when I did > this) > > HTH > > > Thank you, > > Christian Hernandez > 1225 Los Angeles Street > Glendale, CA 91204 > Phone: 877-782-2737 ext. 4566 > Fax: 818-265-3152 > christianh(a)4over.com > www.4over.com > > > On Mon, Apr 22, 2013 at 2:57 PM, Jonathan Horne wrot= e: >> >> Is there a write up out there for setting up ovirt users and adminstrato= rs >> to authenticate into the portal via AD? >> >> >> >> Thanks, >> >> Jonathan >> >> >> >> >> ________________________________ >> This is a PRIVATE message. If you are not the intended recipient, please >> delete without copying and kindly advise us by e-mail of the mistake in >> delivery. NOTE: Regardless of content, this e-mail shall not operate to = bind >> SKOPOS to any order or other contract unless pursuant to explicit written >> agreement or government initiative expressly permitting the use of e-mail >> for such purpose. >> >> _______________________________________________ >> Users mailing list >> Users(a)ovirt.org >> http://lists.ovirt.org/mailman/listinfo/users >> > > > _______________________________________________ > Users mailing list > Users(a)ovirt.org > http://lists.ovirt.org/mailman/listinfo/users > --===============1505153405138572925==-- From cnoffsin at gmail.com Tue Apr 23 10:12:44 2013 Content-Type: multipart/mixed; boundary="===============2520301949813114363==" MIME-Version: 1.0 From: Chris Noffsinger To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Tue, 23 Apr 2013 10:12:43 -0400 Message-ID: In-Reply-To: CAJb3uA5Afce8zfgM54GCod0MKpxBVxaznShxnOD8tcCM0BeE-Q@mail.gmail.com --===============2520301949813114363== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Also create a different user. For instance I could not get the Administrator user to bind with my samba4 DC. Had to create a different user to bind to. On Tue, Apr 23, 2013 at 10:09 AM, Charlie wrote: > Also set your Active Directory source as your time synchronization > provider. You need DNS, Directory services, Kerberos and network time > all from the same source if you want anything approaching reliability. > > --Charlie > > On Mon, Apr 22, 2013 at 6:17 PM, Christian Hernandez > wrote: > > Hello Jonathan, > > > > I believe you can use the Red Hat Documentation for this. > > > > > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Vir= tualization/3.1/html/Evaluation_Guide/Evaluation_Guide-VDI.html#Evaluation_= Guide-Add_Active_Directory > > > > One of the "gotchas" that I ran into is that you need to specify the > Active > > Directory as your DNS provider in your resolv.conf file (not sure if it > was > > coincidence or not; but I ran into some issues that went away when I did > > this) > > > > HTH > > > > > > Thank you, > > > > Christian Hernandez > > 1225 Los Angeles Street > > Glendale, CA 91204 > > Phone: 877-782-2737 ext. 4566 > > Fax: 818-265-3152 > > christianh(a)4over.com > > www.4over.com > > > > > > On Mon, Apr 22, 2013 at 2:57 PM, Jonathan Horne > wrote: > >> > >> Is there a write up out there for setting up ovirt users and > adminstrators > >> to authenticate into the portal via AD? > >> > >> > >> > >> Thanks, > >> > >> Jonathan > >> > >> > >> > >> > >> ________________________________ > >> This is a PRIVATE message. If you are not the intended recipient, plea= se > >> delete without copying and kindly advise us by e-mail of the mistake in > >> delivery. NOTE: Regardless of content, this e-mail shall not operate to > bind > >> SKOPOS to any order or other contract unless pursuant to explicit > written > >> agreement or government initiative expressly permitting the use of > e-mail > >> for such purpose. > >> > >> _______________________________________________ > >> Users mailing list > >> Users(a)ovirt.org > >> http://lists.ovirt.org/mailman/listinfo/users > >> > > > > > > _______________________________________________ > > Users mailing list > > Users(a)ovirt.org > > http://lists.ovirt.org/mailman/listinfo/users > > > _______________________________________________ > Users mailing list > Users(a)ovirt.org > http://lists.ovirt.org/mailman/listinfo/users > -- = Chris Noffsinger --===============2520301949813114363== Content-Type: text/html MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.html" QWxzbyBjcmVhdGUgYSBkaWZmZXJlbnQgdXNlci4goEZvciBpbnN0YW5jZSBJIGNvdWxkIG5vdCBn ZXQgdGhlIEFkbWluaXN0cmF0b3IgdXNlciB0byBiaW5kIHdpdGggbXkgc2FtYmE0IERDLiCgSGFk IHRvIGNyZWF0ZSBhIGRpZmZlcmVudCB1c2VyIHRvIGJpbmQgdG8uPGJyPjxicj48ZGl2IGNsYXNz PSJnbWFpbF9xdW90ZSI+T24gVHVlLCBBcHIgMjMsIDIwMTMgYXQgMTA6MDkgQU0sIENoYXJsaWUg PHNwYW4gZGlyPSJsdHIiPiZsdDs8YSBocmVmPSJtYWlsdG86bWVkaWV2YWxpc3RAZ21haWwuY29t IiB0YXJnZXQ9Il9ibGFuayI+bWVkaWV2YWxpc3RAZ21haWwuY29tPC9hPiZndDs8L3NwYW4+IHdy b3RlOjxicj4KPGJsb2NrcXVvdGUgY2xhc3M9ImdtYWlsX3F1b3RlIiBzdHlsZT0ibWFyZ2luOjAg MCAwIC44ZXg7Ym9yZGVyLWxlZnQ6MXB4ICNjY2Mgc29saWQ7cGFkZGluZy1sZWZ0OjFleCI+QWxz byBzZXQgeW91ciBBY3RpdmUgRGlyZWN0b3J5IHNvdXJjZSBhcyB5b3VyIHRpbWUgc3luY2hyb25p emF0aW9uPGJyPgpwcm92aWRlci4goFlvdSBuZWVkIEROUywgRGlyZWN0b3J5IHNlcnZpY2VzLCBL ZXJiZXJvcyBhbmQgbmV0d29yayB0aW1lPGJyPgphbGwgZnJvbSB0aGUgc2FtZSBzb3VyY2UgaWYg eW91IHdhbnQgYW55dGhpbmcgYXBwcm9hY2hpbmcgcmVsaWFiaWxpdHkuPGJyPgo8YnI+Ci0tQ2hh cmxpZTxicj4KPGJyPgpPbiBNb24sIEFwciAyMiwgMjAxMyBhdCA2OjE3IFBNLCBDaHJpc3RpYW4g SGVybmFuZGV6PGJyPgombHQ7PGEgaHJlZj0ibWFpbHRvOmNocmlzdGlhbmhANG92ZXIuY29tIj5j aHJpc3RpYW5oQDRvdmVyLmNvbTwvYT4mZ3Q7IHdyb3RlOjxicj4KJmd0OyBIZWxsbyBKb25hdGhh biw8YnI+CiZndDs8YnI+CiZndDsgSSBiZWxpZXZlIHlvdSBjYW4gdXNlIHRoZSBSZWQgSGF0IERv Y3VtZW50YXRpb24gZm9yIHRoaXMuPGJyPgomZ3Q7PGJyPgomZ3Q7IDxhIGhyZWY9Imh0dHBzOi8v YWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVudGF0aW9uL2VuLVVTL1JlZF9IYXRfRW50ZXJw cmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9FdmFsdWF0aW9uX0d1aWRlL0V2YWx1YXRpb25f R3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlkZS1BZGRfQWN0aXZlX0RpcmVjdG9yeSIgdGFy Z2V0PSJfYmxhbmsiPmh0dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVudGF0aW9u L2VuLVVTL1JlZF9IYXRfRW50ZXJwcmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9FdmFsdWF0 aW9uX0d1aWRlL0V2YWx1YXRpb25fR3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlkZS1BZGRf QWN0aXZlX0RpcmVjdG9yeTwvYT48YnI+CgomZ3Q7PGJyPgomZ3Q7IE9uZSBvZiB0aGUgJnF1b3Q7 Z290Y2hhcyZxdW90OyB0aGF0IEkgcmFuIGludG8gaXMgdGhhdCB5b3UgbmVlZCB0byBzcGVjaWZ5 IHRoZSBBY3RpdmU8YnI+CiZndDsgRGlyZWN0b3J5IGFzIHlvdXIgRE5TIHByb3ZpZGVyIGluIHlv dXIgcmVzb2x2LmNvbmYgZmlsZSAobm90IHN1cmUgaWYgaXQgd2FzPGJyPgomZ3Q7IGNvaW5jaWRl bmNlIG9yIG5vdDsgYnV0IEkgcmFuIGludG8gc29tZSBpc3N1ZXMgdGhhdCB3ZW50IGF3YXkgd2hl biBJIGRpZDxicj4KJmd0OyB0aGlzKTxicj4KJmd0Ozxicj4KJmd0OyBIVEg8YnI+CiZndDs8YnI+ CiZndDs8YnI+CiZndDsgVGhhbmsgeW91LDxicj4KJmd0Ozxicj4KJmd0OyBDaHJpc3RpYW4gSGVy bmFuZGV6PGJyPgomZ3Q7IDEyMjUgTG9zIEFuZ2VsZXMgU3RyZWV0PGJyPgomZ3Q7IEdsZW5kYWxl LCBDQSA5MTIwNDxicj4KJmd0OyBQaG9uZTogPGEgaHJlZj0idGVsOjg3Ny03ODItMjczNyUyMGV4 dC4lMjA0NTY2IiB2YWx1ZT0iKzE4Nzc3ODIyNzM3Ij44NzctNzgyLTI3MzcgZXh0LiA0NTY2PC9h Pjxicj4KJmd0OyBGYXg6IDxhIGhyZWY9InRlbDo4MTgtMjY1LTMxNTIiIHZhbHVlPSIrMTgxODI2 NTMxNTIiPjgxOC0yNjUtMzE1MjwvYT48YnI+CiZndDsgPGEgaHJlZj0ibWFpbHRvOmNocmlzdGlh bmhANG92ZXIuY29tIj5jaHJpc3RpYW5oQDRvdmVyLmNvbTwvYT4gJmx0O21haWx0bzo8YSBocmVm PSJtYWlsdG86Y2hyaXN0aWFuaEA0b3Zlci5jb20iPmNocmlzdGlhbmhANG92ZXIuY29tPC9hPiZn dDs8YnI+CiZndDsgPGEgaHJlZj0iaHR0cDovL3d3dy40b3Zlci5jb20iIHRhcmdldD0iX2JsYW5r Ij53d3cuNG92ZXIuY29tPC9hPiAmbHQ7PGEgaHJlZj0iaHR0cDovL3d3dy40b3Zlci5jb20iIHRh cmdldD0iX2JsYW5rIj5odHRwOi8vd3d3LjRvdmVyLmNvbTwvYT4mZ3Q7PGJyPgomZ3Q7PGJyPgom Z3Q7PGJyPgomZ3Q7IE9uIE1vbiwgQXByIDIyLCAyMDEzIGF0IDI6NTcgUE0sIEpvbmF0aGFuIEhv cm5lICZsdDs8YSBocmVmPSJtYWlsdG86amhvcm5lQHNrb3Bvcy51cyI+amhvcm5lQHNrb3Bvcy51 czwvYT4mZ3Q7IHdyb3RlOjxicj4KJmd0OyZndDs8YnI+CiZndDsmZ3Q7IElzIHRoZXJlIGEgd3Jp dGUgdXAgb3V0IHRoZXJlIGZvciBzZXR0aW5nIHVwIG92aXJ0IHVzZXJzIGFuZCBhZG1pbnN0cmF0 b3JzPGJyPgomZ3Q7Jmd0OyB0byBhdXRoZW50aWNhdGUgaW50byB0aGUgcG9ydGFsIHZpYSBBRD88 YnI+CiZndDsmZ3Q7PGJyPgomZ3Q7Jmd0Ozxicj4KJmd0OyZndDs8YnI+CiZndDsmZ3Q7IFRoYW5r cyw8YnI+CiZndDsmZ3Q7PGJyPgomZ3Q7Jmd0OyBKb25hdGhhbjxicj4KJmd0OyZndDs8YnI+CiZn dDsmZ3Q7PGJyPgomZ3Q7Jmd0Ozxicj4KJmd0OyZndDs8YnI+CiZndDsmZ3Q7IF9fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fPGJyPgomZ3Q7Jmd0OyBUaGlzIGlzIGEgUFJJVkFURSBtZXNz YWdlLiBJZiB5b3UgYXJlIG5vdCB0aGUgaW50ZW5kZWQgcmVjaXBpZW50LCBwbGVhc2U8YnI+CiZn dDsmZ3Q7IGRlbGV0ZSB3aXRob3V0IGNvcHlpbmcgYW5kIGtpbmRseSBhZHZpc2UgdXMgYnkgZS1t YWlsIG9mIHRoZSBtaXN0YWtlIGluPGJyPgomZ3Q7Jmd0OyBkZWxpdmVyeS4gTk9URTogUmVnYXJk bGVzcyBvZiBjb250ZW50LCB0aGlzIGUtbWFpbCBzaGFsbCBub3Qgb3BlcmF0ZSB0byBiaW5kPGJy PgomZ3Q7Jmd0OyBTS09QT1MgdG8gYW55IG9yZGVyIG9yIG90aGVyIGNvbnRyYWN0IHVubGVzcyBw dXJzdWFudCB0byBleHBsaWNpdCB3cml0dGVuPGJyPgomZ3Q7Jmd0OyBhZ3JlZW1lbnQgb3IgZ292 ZXJubWVudCBpbml0aWF0aXZlIGV4cHJlc3NseSBwZXJtaXR0aW5nIHRoZSB1c2Ugb2YgZS1tYWls PGJyPgomZ3Q7Jmd0OyBmb3Igc3VjaCBwdXJwb3NlLjxicj4KJmd0OyZndDs8YnI+CiZndDsmZ3Q7 IF9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPgomZ3Q7 Jmd0OyBVc2VycyBtYWlsaW5nIGxpc3Q8YnI+CiZndDsmZ3Q7IDxhIGhyZWY9Im1haWx0bzpVc2Vy c0BvdmlydC5vcmciPlVzZXJzQG92aXJ0Lm9yZzwvYT48YnI+CiZndDsmZ3Q7IDxhIGhyZWY9Imh0 dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0aW5mby91c2VycyIgdGFyZ2V0PSJfYmxh bmsiPmh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0aW5mby91c2VyczwvYT48YnI+ CiZndDsmZ3Q7PGJyPgomZ3Q7PGJyPgomZ3Q7PGJyPgomZ3Q7IF9fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fX19fPGJyPgomZ3Q7IFVzZXJzIG1haWxpbmcgbGlzdDxi cj4KJmd0OyA8YSBocmVmPSJtYWlsdG86VXNlcnNAb3ZpcnQub3JnIj5Vc2Vyc0BvdmlydC5vcmc8 L2E+PGJyPgomZ3Q7IDxhIGhyZWY9Imh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0 aW5mby91c2VycyIgdGFyZ2V0PSJfYmxhbmsiPmh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1h bi9saXN0aW5mby91c2VyczwvYT48YnI+CiZndDs8YnI+Cl9fX19fX19fX19fX19fX19fX19fX19f X19fX19fX19fX19fX19fX19fX19fX19fPGJyPgpVc2VycyBtYWlsaW5nIGxpc3Q8YnI+CjxhIGhy ZWY9Im1haWx0bzpVc2Vyc0BvdmlydC5vcmciPlVzZXJzQG92aXJ0Lm9yZzwvYT48YnI+CjxhIGhy ZWY9Imh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0aW5mby91c2VycyIgdGFyZ2V0 PSJfYmxhbmsiPmh0dHA6Ly9saXN0cy5vdmlydC5vcmcvbWFpbG1hbi9saXN0aW5mby91c2Vyczwv YT48YnI+CjwvYmxvY2txdW90ZT48L2Rpdj48YnI+PGJyIGNsZWFyPSJhbGwiPjxkaXY+PGJyPjwv ZGl2Pi0tIDxicj5DaHJpcyBOb2Zmc2luZ2VyPGJyPgo= --===============2520301949813114363==-- From tom at ng23.net Tue Apr 23 10:16:20 2013 Content-Type: multipart/mixed; boundary="===============1127309428871274548==" MIME-Version: 1.0 From: Tom Brown To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Tue, 23 Apr 2013 15:16:40 +0100 Message-ID: <873EC74E-AF01-43A2-8012-568C73AF1293@ng23.net> In-Reply-To: CAH3k4=eguq-8KpKSHadHBaHFJKkd_Qjx5-jeTqFraphvX8L-0A@mail.gmail.com --===============1127309428871274548== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable --Apple-Mail=3D_A45E5F81-2FC0-40AB-B8A0-DCD4CC67FE70 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=3Diso-8859-1 > Hello Jonathan, >=3D20 > I believe you can use the Red Hat Documentation for this. >=3D20 > =3D https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virt= =3D ualization/3.1/html/Evaluation_Guide/Evaluation_Guide-VDI.html#Evaluation_= =3D Guide-Add_Active_Directory >=3D20 > One of the "gotchas" that I ran into is that you need to specify the =3D Active Directory as your DNS provider in your resolv.conf file (not sure = =3D if it was coincidence or not; but I ran into some issues that went away =3D when I did this) Has anyone had success doing this with 389 ? cheers --Apple-Mail=3D_A45E5F81-2FC0-40AB-B8A0-DCD4CC67FE70 Content-Transfer-Encoding: 7bit Content-Type: text/html; charset=3Diso-8859-1


One of the "gotchas" that I ran into is that you need to specify = the Active Directory as your DNS provider in your resolv.conf file (not sur= e if it was coincidence or not; but I ran into some issues that went away w= hen I did this)

Has anyone had s= uccess doing this with 389 ?

cheers

--Apple-Mail=3D_A45E5F81-2FC0-40AB-B8A0-DCD4CC67FE70-- --===============1127309428871274548== Content-Type: multipart/alternative MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.bin" Ci0tQXBwbGUtTWFpbD1fQTQ1RTVGODEtMkZDMC00MEFCLUI4QTAtRENENENDNjdGRTcwCkNvbnRl bnQtVHJhbnNmZXItRW5jb2Rpbmc6IHF1b3RlZC1wcmludGFibGUKQ29udGVudC1UeXBlOiB0ZXh0 L3BsYWluOwoJY2hhcnNldD1pc28tODg1OS0xCgoKCgo+IEhlbGxvIEpvbmF0aGFuLAo+PTIwCj4g SSBiZWxpZXZlIHlvdSBjYW4gdXNlIHRoZSBSZWQgSGF0IERvY3VtZW50YXRpb24gZm9yIHRoaXMu Cj49MjAKPiA9Cmh0dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVudGF0aW9uL2Vu LVVTL1JlZF9IYXRfRW50ZXJwcmlzZV9WaXJ0PQp1YWxpemF0aW9uLzMuMS9odG1sL0V2YWx1YXRp b25fR3VpZGUvRXZhbHVhdGlvbl9HdWlkZS1WREkuaHRtbCNFdmFsdWF0aW9uXz0KR3VpZGUtQWRk X0FjdGl2ZV9EaXJlY3RvcnkKPj0yMAo+IE9uZSBvZiB0aGUgImdvdGNoYXMiIHRoYXQgSSByYW4g aW50byBpcyB0aGF0IHlvdSBuZWVkIHRvIHNwZWNpZnkgdGhlID0KQWN0aXZlIERpcmVjdG9yeSBh cyB5b3VyIEROUyBwcm92aWRlciBpbiB5b3VyIHJlc29sdi5jb25mIGZpbGUgKG5vdCBzdXJlID0K aWYgaXQgd2FzIGNvaW5jaWRlbmNlIG9yIG5vdDsgYnV0IEkgcmFuIGludG8gc29tZSBpc3N1ZXMg dGhhdCB3ZW50IGF3YXkgPQp3aGVuIEkgZGlkIHRoaXMpCgpIYXMgYW55b25lIGhhZCBzdWNjZXNz IGRvaW5nIHRoaXMgd2l0aCAzODkgPwoKY2hlZXJzCgoKLS1BcHBsZS1NYWlsPV9BNDVFNUY4MS0y RkMwLTQwQUItQjhBMC1EQ0Q0Q0M2N0ZFNzAKQ29udGVudC1UcmFuc2Zlci1FbmNvZGluZzogN2Jp dApDb250ZW50LVR5cGU6IHRleHQvaHRtbDsKCWNoYXJzZXQ9aXNvLTg4NTktMQoKPGh0bWw+PGhl YWQ+PG1ldGEgaHR0cC1lcXVpdj0iQ29udGVudC1UeXBlIiBjb250ZW50PSJ0ZXh0L2h0bWwgY2hh cnNldD1pc28tODg1OS0xIj48L2hlYWQ+PGJvZHkgc3R5bGU9IndvcmQtd3JhcDogYnJlYWstd29y ZDsgLXdlYmtpdC1uYnNwLW1vZGU6IHNwYWNlOyAtd2Via2l0LWxpbmUtYnJlYWs6IGFmdGVyLXdo aXRlLXNwYWNlOyAiPjxicj48ZGl2PjxkaXY+PGJyPjwvZGl2PjxiciBjbGFzcz0iQXBwbGUtaW50 ZXJjaGFuZ2UtbmV3bGluZSI+PGJsb2NrcXVvdGUgdHlwZT0iY2l0ZSI+PGRpdiBkaXI9Imx0ciI+ PGRpdj48ZGl2PjxkaXY+SGVsbG8gSm9uYXRoYW4sPGJyPjxicj48L2Rpdj5JIGJlbGlldmUgeW91 IGNhbiB1c2UgdGhlIFJlZCBIYXQgRG9jdW1lbnRhdGlvbiBmb3IgdGhpcy48YnI+PGJyPjxhIGhy ZWY9Imh0dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVudGF0aW9uL2VuLVVTL1Jl ZF9IYXRfRW50ZXJwcmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9FdmFsdWF0aW9uX0d1aWRl L0V2YWx1YXRpb25fR3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlkZS1BZGRfQWN0aXZlX0Rp cmVjdG9yeSI+aHR0cHM6Ly9hY2Nlc3MucmVkaGF0LmNvbS9zaXRlL2RvY3VtZW50YXRpb24vZW4t VVMvUmVkX0hhdF9FbnRlcnByaXNlX1ZpcnR1YWxpemF0aW9uLzMuMS9odG1sL0V2YWx1YXRpb25f R3VpZGUvRXZhbHVhdGlvbl9HdWlkZS1WREkuaHRtbCNFdmFsdWF0aW9uX0d1aWRlLUFkZF9BY3Rp dmVfRGlyZWN0b3J5PC9hPjxicj4KCjxicj48L2Rpdj5PbmUgb2YgdGhlICJnb3RjaGFzIiB0aGF0 IEkgcmFuIGludG8gaXMgdGhhdCB5b3UgbmVlZCB0byBzcGVjaWZ5IHRoZSBBY3RpdmUgRGlyZWN0 b3J5IGFzIHlvdXIgRE5TIHByb3ZpZGVyIGluIHlvdXIgcmVzb2x2LmNvbmYgZmlsZSAobm90IHN1 cmUgaWYgaXQgd2FzIGNvaW5jaWRlbmNlIG9yIG5vdDsgYnV0IEkgcmFuIGludG8gc29tZSBpc3N1 ZXMgdGhhdCB3ZW50IGF3YXkgd2hlbiBJIGRpZCB0aGlzKTxicj48L2Rpdj48L2Rpdj48L2Jsb2Nr cXVvdGU+PGJyPjwvZGl2PjxkaXY+SGFzIGFueW9uZSBoYWQgc3VjY2VzcyBkb2luZyB0aGlzIHdp dGggMzg5ID88L2Rpdj48ZGl2Pjxicj48L2Rpdj48ZGl2PmNoZWVyczwvZGl2Pjxicj48L2JvZHk+ PC9odG1sPgotLUFwcGxlLU1haWw9X0E0NUU1RjgxLTJGQzAtNDBBQi1COEEwLURDRDRDQzY3RkU3 MC0tCg== --===============1127309428871274548==-- From christianh at 4over.com Tue Apr 23 13:50:09 2013 Content-Type: multipart/mixed; boundary="===============6441773903742701732==" MIME-Version: 1.0 From: Christian Hernandez To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Tue, 23 Apr 2013 08:13:02 -0700 Message-ID: In-Reply-To: 873EC74E-AF01-43A2-8012-568C73AF1293@ng23.net --===============6441773903742701732== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Tom, I *believe* that you can use 389 with TLS FWIW I have successfully added an AD and IPA domain. Thank you, Christian Hernandez 1225 Los Angeles Street Glendale, CA 91204 Phone: 877-782-2737 ext. 4566 Fax: 818-265-3152 christianh(a)4over.com www.4over.com On Tue, Apr 23, 2013 at 7:16 AM, Tom Brown wrote: > > > > Hello Jonathan, > > I believe you can use the Red Hat Documentation for this. > > > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Vir= tualization/3.1/html/Evaluation_Guide/Evaluation_Guide-VDI.html#Evaluation_= Guide-Add_Active_Directory > > One of the "gotchas" that I ran into is that you need to specify the > Active Directory as your DNS provider in your resolv.conf file (not sure = if > it was coincidence or not; but I ran into some issues that went away when= I > did this) > > > Has anyone had success doing this with 389 ? > > cheers > > --===============6441773903742701732== Content-Type: text/html MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="attachment.html" PGRpdiBkaXI9Imx0ciI+PGRpdj48ZGl2PlRvbSw8YnI+PGJyPjwvZGl2PkkgKmJlbGlldmUqIHRo YXQgeW91IGNhbiB1c2UgMzg5IHdpdGggVExTPGJyPjxicj48L2Rpdj5GV0lXIEkgaGF2ZSBzdWNj ZXNzZnVsbHkgYWRkZWQgYW4gQUQgYW5kIElQQSBkb21haW4uPGJyPjwvZGl2PjxkaXYgY2xhc3M9 ImdtYWlsX2V4dHJhIj48YnIgY2xlYXI9ImFsbCI+PGRpdj48ZGl2IGRpcj0ibHRyIj48ZGl2PgoK PGJyPlRoYW5rIHlvdSw8YnI+PGJyPkNocmlzdGlhbiBIZXJuYW5kZXo8YnI+PC9kaXY+MTIyNSBM b3MgQW5nZWxlcyBTdHJlZXQ8YnI+PGRpdj5HbGVuZGFsZSwgQ0EgOTEyMDQ8YnI+ClBob25lOiA8 YSB2YWx1ZT0iKzE4Nzc3ODIyNzM3Ij44NzctNzgyLTI3MzcgZXh0LiA0NTY2PC9hPjxicj5GYXg6 IDxhIHZhbHVlPSIrMTgxODI2NTMxNTIiPjgxOC0yNjUtMzE1MjwvYT48YnI+PGEgaHJlZj0ibWFp bHRvOmNocmlzdGlhbmhANG92ZXIuY29tIiB0YXJnZXQ9Il9ibGFuayI+Y2hyaXN0aWFuaEA0b3Zl ci5jb208L2E+ICZsdDttYWlsdG86PGEgaHJlZj0ibWFpbHRvOmNocmlzdGlhbmhANG92ZXIuY29t IiB0YXJnZXQ9Il9ibGFuayI+Y2hyaXN0aWFuaEA0b3Zlci5jb208L2E+Jmd0OyA8YnI+Cgo8YSBo cmVmPSJodHRwOi8vd3d3LjRvdmVyLmNvbS8iIHRhcmdldD0iX2JsYW5rIj53d3cuNG92ZXIuY29t PC9hPiAmbHQ7PGEgaHJlZj0iaHR0cDovL3d3dy40b3Zlci5jb20vIiB0YXJnZXQ9Il9ibGFuayI+ aHR0cDovL3d3dy40b3Zlci5jb208L2E+Jmd0OzwvZGl2PjwvZGl2PjwvZGl2Pgo8YnI+PGJyPjxk aXYgY2xhc3M9ImdtYWlsX3F1b3RlIj5PbiBUdWUsIEFwciAyMywgMjAxMyBhdCA3OjE2IEFNLCBU b20gQnJvd24gPHNwYW4gZGlyPSJsdHIiPiZsdDs8YSBocmVmPSJtYWlsdG86dG9tQG5nMjMubmV0 IiB0YXJnZXQ9Il9ibGFuayI+dG9tQG5nMjMubmV0PC9hPiZndDs8L3NwYW4+IHdyb3RlOjxicj48 YmxvY2txdW90ZSBjbGFzcz0iZ21haWxfcXVvdGUiIHN0eWxlPSJtYXJnaW46MCAwIDAgLjhleDti b3JkZXItbGVmdDoxcHggI2NjYyBzb2xpZDtwYWRkaW5nLWxlZnQ6MWV4Ij4KCjxkaXYgc3R5bGU9 IndvcmQtd3JhcDpicmVhay13b3JkIj48ZGl2IGNsYXNzPSJpbSI+PGJyPjxkaXY+PGRpdj48YnI+ PC9kaXY+PGJyPjxibG9ja3F1b3RlIHR5cGU9ImNpdGUiPjxkaXYgZGlyPSJsdHIiPjxkaXY+PGRp dj48ZGl2PkhlbGxvIEpvbmF0aGFuLDxicj48YnI+PC9kaXY+SSBiZWxpZXZlIHlvdSBjYW4gdXNl IHRoZSBSZWQgSGF0IERvY3VtZW50YXRpb24gZm9yIHRoaXMuPGJyPgoKPGJyPjxhIGhyZWY9Imh0 dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVudGF0aW9uL2VuLVVTL1JlZF9IYXRf RW50ZXJwcmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9FdmFsdWF0aW9uX0d1aWRlL0V2YWx1 YXRpb25fR3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlkZS1BZGRfQWN0aXZlX0RpcmVjdG9y eSIgdGFyZ2V0PSJfYmxhbmsiPmh0dHBzOi8vYWNjZXNzLnJlZGhhdC5jb20vc2l0ZS9kb2N1bWVu dGF0aW9uL2VuLVVTL1JlZF9IYXRfRW50ZXJwcmlzZV9WaXJ0dWFsaXphdGlvbi8zLjEvaHRtbC9F dmFsdWF0aW9uX0d1aWRlL0V2YWx1YXRpb25fR3VpZGUtVkRJLmh0bWwjRXZhbHVhdGlvbl9HdWlk ZS1BZGRfQWN0aXZlX0RpcmVjdG9yeTwvYT48YnI+CgoKCjxicj48L2Rpdj5PbmUgb2YgdGhlICZx dW90O2dvdGNoYXMmcXVvdDsgdGhhdCBJIHJhbiBpbnRvIGlzIHRoYXQgeW91IG5lZWQgdG8gc3Bl Y2lmeSB0aGUgQWN0aXZlIERpcmVjdG9yeSBhcyB5b3VyIEROUyBwcm92aWRlciBpbiB5b3VyIHJl c29sdi5jb25mIGZpbGUgKG5vdCBzdXJlIGlmIGl0IHdhcyBjb2luY2lkZW5jZSBvciBub3Q7IGJ1 dCBJIHJhbiBpbnRvIHNvbWUgaXNzdWVzIHRoYXQgd2VudCBhd2F5IHdoZW4gSSBkaWQgdGhpcyk8 YnI+Cgo8L2Rpdj48L2Rpdj48L2Jsb2NrcXVvdGU+PGJyPjwvZGl2PjwvZGl2PjxkaXY+SGFzIGFu eW9uZSBoYWQgc3VjY2VzcyBkb2luZyB0aGlzIHdpdGggMzg5ID88L2Rpdj48ZGl2Pjxicj48L2Rp dj48ZGl2PmNoZWVyczwvZGl2Pjxicj48L2Rpdj48L2Jsb2NrcXVvdGU+PC9kaXY+PGJyPjwvZGl2 Pgo= --===============6441773903742701732==-- From iheim at redhat.com Wed Apr 24 04:39:19 2013 Content-Type: multipart/mixed; boundary="===============1301143178675480403==" MIME-Version: 1.0 From: Itamar Heim To: users at ovirt.org Subject: Re: [Users] AD authentication for ovirt manager Date: Wed, 24 Apr 2013 09:22:06 +0300 Message-ID: <51777A0E.70708@redhat.com> In-Reply-To: CAFKQu78drXyWVwy12bODUYEckZLokv4GA57jXK6_OXWk8g9suw@mail.gmail.com --===============1301143178675480403== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable On 04/23/2013 05:12 PM, Chris Noffsinger wrote: > Also create a different user. For instance I could not get the > Administrator user to bind with my samba4 DC. Had to create a different > user to bind to. that's because the built-in administrator doesn't have a UPN iirc. --===============1301143178675480403==--