LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   Foreign Security Principals of Active Directory not showing in Linux nodes (https://www.linuxquestions.org/questions/linux-security-4/foreign-security-principals-of-active-directory-not-showing-in-linux-nodes-4175699112/)

rahul.buragohain 08-13-2021 05:02 AM

Foreign Security Principals of Active Directory not showing in Linux nodes
 
Hi Team,

We have a two way trust of AD Forest (example1.com and example2.com). Linux Centos 7 node is integrated with example1.com through SSSD Realm and users in example1.com is showing properly in linux node using "id user" command which is also expected.

There are a few users in example2.com which are showing as Foreign Security Principals (FSP) in example1.com. I have attached the screenshot of example1.com for your reference.

I tried with "id S-1-5-21-....." in linux but it doesn't show the user in linux and it says no user.

Is this an expected behaviour or do I need to make any changes in SSSD side or in any configuration file in Linux?

Thanks,
Rahul

TB0ne 08-14-2021 02:46 PM

Quote:

Originally Posted by rahul.buragohain (Post 6274880)
Hi Team,
We have a two way trust of AD Forest (example1.com and example2.com). Linux Centos 7 node is integrated with example1.com through SSSD Realm and users in example1.com is showing properly in linux node using "id user" command which is also expected.

There are a few users in example2.com which are showing as Foreign Security Principals (FSP) in example1.com. I have attached the screenshot of example1.com for your reference. I tried with "id S-1-5-21-....." in linux but it doesn't show the user in linux and it says no user. Is this an expected behaviour or do I need to make any changes in SSSD side or in any configuration file in Linux?

Please note we aren't on your 'team', but volunteers who try to help others. And you appear to have been working with LDAP and active directory for several years now:
https://www.linuxquestions.org/quest...rs-4175510051/
https://www.linuxquestions.org/quest...nt-4175510950/
https://www.linuxquestions.org/quest...0/#post5549645

And putting "Foreign security principals ldap active directory" into Google directs you to the Microsoft forum, where this is explained:
https://social.technet.microsoft.com...dentities.aspx

Better question would be: are you actually having any problems/difficulties???


All times are GMT -5. The time now is 01:25 AM.