Dealing with outsourced IT organization that manages an AD domain we are tying to build an additional trust with so we can upgrade and replace our fleet of IDM servers.
We got a webex work session going with a domain admin to build the trust but we keep seeing this on the CLI and WebUI:
ipa: ERROR: Insufficient access: CIFS server XXXXXX.COMPANY.COM denied your credentials
Running in debug or verbose mode does not reveal more error details and I can't find much in the logs on the IPA server
The AD admin we were working with claims he used an account that is part of the Enterprise Admin group and thus should be allowed to do "all the things" -- they are asking for any docs or details we have on what permissions the IPA server needs when trust building
Looking for info/tips on the following, thanks!
1) Any log locations or places where I can find more info about why the ad-trust setup failed?
2) Any docs or listing of specific AD permissions needed by the AD admin account used to establish the trust
AD is not my strong point - apologies if this is a dumb query!
Regards, Chris