Thank you for your suggestions.
I've got it working after realized that the problem were in AD DN plugin where addn_filter was set to evaluate only nsAccount as objectClass.
However your PAM config looks better and i must confess, i am not a PAM guru. I will explore better this topic.
Regarding my second question, reported here:
i think it would be better to sync AD user that
belongs to specific AD Group in order to have more control over it instead
of defining a specific OU.
I've seen a page which reports the existence of "Support Filters":
And it says:
new config parameters in windwows sync agreement:
Anyway it is not clear if my installed version support this feature
Thanks for your support
389-users mailing list -- email@example.com
To unsubscribe send an email to firstname.lastname@example.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://email@example.com
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure