From 9b6be7e47c26cade769163d45dcf06429ba1c728 Mon Sep 17 00:00:00 2001 From: Jen Malloy Date: Mon, 27 Feb 2017 16:05:25 -0500 Subject: [PATCH] SSSD final content --- server_admin/topics/user-federation/sssd.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/server_admin/topics/user-federation/sssd.adoc b/server_admin/topics/user-federation/sssd.adoc index d6154c46ed..a1141ff163 100644 --- a/server_admin/topics/user-federation/sssd.adoc +++ b/server_admin/topics/user-federation/sssd.adoc @@ -8,7 +8,7 @@ SSSD also integrates with the http://www.freeipa.org/page/Main_Page[FreeIPA iden image:../../{{book.images}}/keycloak-sssd-freeipa-integration-overview.png[] -Most of the communication between {{book.project.name}} and SSSD occurs through read-only D-Bus interfaces. For this reason, the only way to provision and update users is to use FreeIPA/IdM administration interface. By default, like the LDAP federation provider, it is set up only to import username, email, first name, and last name. +Most of the communication between {{book.project.name}} and SSSD occurs through read-only D-Bus interfaces. For this reason, the only way to provision and update users is to use the FreeIPA/IdM administration interface. By default, like the LDAP federation provider, it is set up only to import username, email, first name, and last name. [NOTE] Groups and roles are automatically registered, but not synchronized, so any changes made by the {{book.project.name}} administrator directly in {{book.project.name}} is not synchronized with SSSD.