Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Rob Crittenden
Sigbjørn Lie wrote: On 03/11/2011 09:16 PM, Rob Crittenden wrote: Sigbjørn Lie wrote: Hi, I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a sync agreement with Active Directory. Added CA certificate /root/testing-ca.cer to certificate database for ipasrv01.ix.testing.com i

Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Dmitri Pal
On 03/11/2011 03:31 PM, Sigbjørn Lie wrote: > > > On 03/11/2011 09:15 PM, Dmitri Pal wrote: >> On 03/11/2011 03:00 PM, Sigbjørn Lie wrote: >>> Hi, >>> >>> I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a >>> sync agreement with Active Directory. >> Did you upgrade in place or r

Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Sigbjørn Lie
On 03/11/2011 09:15 PM, Dmitri Pal wrote: On 03/11/2011 03:00 PM, Sigbjørn Lie wrote: Hi, I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a sync agreement with Active Directory. Did you upgrade in place or re-installed? The recent (a month ago or so) changes moved the loc

Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Sigbjørn Lie
On 03/11/2011 09:16 PM, Rob Crittenden wrote: Sigbjørn Lie wrote: Hi, I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a sync agreement with Active Directory. Added CA certificate /root/testing-ca.cer to certificate database for ipasrv01.ix.testing.com ipa: INFO: AD Suffix i

Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Rob Crittenden
Sigbjørn Lie wrote: Hi, I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a sync agreement with Active Directory. Added CA certificate /root/testing-ca.cer to certificate database for ipasrv01.ix.testing.com ipa: INFO: AD Suffix is: DC=ad,DC=testing,DC=com The user for the Win

Re: [Freeipa-users] Sync with AD error

2011-03-11 Thread Dmitri Pal
On 03/11/2011 03:00 PM, Sigbjørn Lie wrote: > Hi, > > I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a > sync agreement with Active Directory. Did you upgrade in place or re-installed? The recent (a month ago or so) changes moved the location of the replication agreements. The

[Freeipa-users] Sync with AD error

2011-03-11 Thread Sigbjørn Lie
Hi, I just upgraded my FreeIPA @ F14 to 2.0.0.rc3, and attempted to add a sync agreement with Active Directory. Added CA certificate /root/testing-ca.cer to certificate database for ipasrv01.ix.testing.com ipa: INFO: AD Suffix is: DC=ad,DC=testing,DC=com The user for the Windows PassSync ser

Re: [Freeipa-users] Repository error

2011-03-11 Thread Sylvain PANNETRAT
De: "Rob Crittenden" rcrit...@redhat.com > Sylvain PANNETRAT wrote: >> Hello, >> I try to update a fedora 14 client, and get: >> >> http://freeipa.com/downloads/devel/rpms/F14/x86_64/repodata/primar >> y.xml.gz: >> [Errno -1] Metadata file does not match checksum >> After yum clean all, i get: >>

Re: [Freeipa-users] Repository error

2011-03-11 Thread Rob Crittenden
Sylvain PANNETRAT wrote: Hello, I try to update a fedora 14 client, and get: http://freeipa.com/downloads/devel/rpms/F14/x86_64/repodata/primary.xml.gz: [Errno -1] Metadata file does not match checksum After yum clean all, i get: freeipa-devel/primary | 8.8 kB 00:00 http://freeipa.com/downloads/d

[Freeipa-users] Repository error

2011-03-11 Thread Sylvain PANNETRAT
Hello, I try to update a fedora 14 client, and get: http://freeipa.com/downloads/devel/rpms/F14/x86_64/repodata/primary.xml.gz: [Errno -1] Metadata file does not match checksum After yum clean all, i get: freeipa-devel/primary | 8.8 kB 00:00 http://freeipa.com/downloads/devel/rpms/F14/x8

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-11 Thread Rob Crittenden
Simo Sorce wrote: - Original Message - Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [sss_krb5_verify_keytab_ex] (0): Principal [host/fed14-64-ipacl03.ipa.ac...@ipa.ac .NZ] not found in keytab [default] (Fri Mar 11 12:47:41 2011) [sssd[be[ipa.ac.nz]]] [setup_child] (0): Could not verif

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-11 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/10/2011 07:26 PM, Dmitri Pal wrote: > On 03/10/2011 06:30 PM, Steven Jones wrote: >> My problem is "To troubleshoot we need logs. There are all sorts of >> logs and configuration files on the server and on the client." > On the client: > > Confi

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-11 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/10/2011 06:30 PM, Steven Jones wrote: > My problem is "To troubleshoot we need logs. There are all sorts of > logs and configuration files on the server and on the client." > > Thats just it.I dont know where to look.its simply not > doc