Thanks for your fast reply.

I did'nt know that I must not use the root domain under the domain realms. 
Thanks for the hint and the reference.
We configured the trust again, now with all relevant subdomains and SSO is now 
working.

I noticed only one thing after login: It seems that the GSSAPI Credential 
Delegation is still not working.
I would assume to have a valid ticket from the example.int domain after login. 
As for now I have to manually do a kinit and it prompts me for the AD user 
password. After that I have a valid ticket.

Is this problem still related to some suffix routing problem or is this a new 
separat issue?

Thanks,

Hannes
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to