Apparently AD assumes that when no domain/sid is requested that the client is asking for our own domain. We were just failing in the cldap plugin.
Relax the constraint and search for our own domain as reported by getdomainname()
Initial patch for cldap plugin 0001-ipa-cldap-Support-clients-asking-for-default-domain.patch
Patch is currently under review, ticket should be closed soon.
Pushed to the ipa master tree.
Metadata Update from @simo: - Issue assigned to simo - Issue set to the milestone: FreeIPA 3.0 Trust Effort - 2011/12
Login to comment on this ticket.