I've tried multiple methods that don't appear to work, but I'm ultimately trying to add multiple external users to a non-POSIX group using the ipa group-add-member ...
command.
NOTE: These external users are coming in via a trust with an Active Directory environment.
Usage
$ ipa -v help group-add-member
Usage: ipa [global-options] group-add-member GROUP-NAME [options]
Add members to a group.
Options:
-h, --help show this help message and exit
--external=STR Members of a trusted domain in DOM\name or name@domain form
--all Retrieve and print all attributes from the server. Affects
command output.
--raw Print entries as stored on the server. Only affects output
format.
--no-members Suppress processing of membership attributes.
--users=STR users to add
--groups=STR groups to add
What I'm trying to do
$ ipa -n group-add-member ad_users_external \
--external="user1@AD.mydom.com,user2@AD.mydom.com"
Group name: ad_users_external
Description: External group of admins from AD
External member: S-2-3-12-1396123456-1786123456-1027123456-123456
Member of groups: ad_users
Failed members:
member user:
member group: user1@AD.mydom.com,user2@AD.mydom.com: invalid 'trusted domain object': Ambiguous search, user domain was not specified
-------------------------
Number of members added 0
-------------------------