[Freeipa-users] Re: Reverse DNS zones with AD Trust

2020-05-21 Thread Rafael Jeffman via FreeIPA-users
Hello Vinicius, If you follow the rules found in Deployment Recomendations [1] I don't see why it wouldn't work. I think your best option is to follow the old discussion [2], and set delegation on AD side, and PTR records on IPA side. You'll also need to grant permission for the dynamic updates a

[Freeipa-users] Auditing screensavers

2020-05-21 Thread Bret Wortman via FreeIPA-users
I have a need to set up an audit rule that will track whenever a user's screensaver is unlocked via password. I've tried setting a watch on pam_sss.so but that gets a lot more than what I strictly need and that also, strangely, had a tendency to audit when the screensaver was activated but not w