Pretty sure it has nothing to do with unresolvable LDAP uri :-)Hi Koen, I don't have a complete answer, but I'll try to help and maybe we can work out some details. First, do you have an actual AD server around to test with? In the past we've seen bugs with Samba that didn't occur with AD and I'm not sure if anyone tried the GPO integration with Samba.. The SSSD version you're running is pretty recent, the only GPO-related bug after the 1.12.3 release was https://fedorahosted.org/sssd/ticket/2543
We dont have a large environment, and I put it there, on purpose, to see if it worked :-)I would advice against enumerate=True in large environments.
OK good to know, thanks for that !You can drop ldap_schema=ad, it's already the default for id_provider=ad
Can you confirm that the GUIDs of the GPOs SSSD downloads correspond to those you defined on the sever side?
What does that mean? :-)Note that func_versions is 2 and flags is 0, same for the other GPO.
OK, access was denied but since both the flags and the func_version were value we expect, I presume the code made it all the way to ad_gpo_evaluate_ace() where the GPO is really evaluated. Unfortunately there's not much logging there. I wonder if the GUIDs are correct? If so, we can proceed with debugging, maybe with some instrumented build..
btw did you also try the other way around, only allow access?