On 07/24/2018 12:04 PM, exploitationwindows wrote:[color=blue]
I’m working on SLES 12 SP2 and I want to script the ActiveDirectory
integration with using SSSD.
I can fill the configuration files without problem and join the domain
with the command “net ads join”.
It’s not working well until I open YAST and go to :
“Network Services” > “User Logon Management” > “Change Settings”, here I
need to check “Allow Domain User Logon”.
If I don’t do that my AD User can not log in to my server. I do not find
the parameter to do this in a configuration file or something.[/color]
Did you check the following files and folders before and after the “net
ads join” command as well as before and after YaST doing it’s magic?
It might also be worth comparing the computer object in AD for a system
that allows user logon with one that doesn’t. Maybe an attribute is
missing there that is created or configured with the YaST module.
My currently prefered method is to prepare the sssd configuration files
automatically and then running the YaST module interactively. Just for a
few servers this is the fasted method for me. In case you do not succeed
in replacing YaST with your own script running AutoYaST on the installed
system just for the AD integration might also be an option for fast
deployment on many servers.