[Freeipa-users] named's LDAP connection hangs

2014-06-16 Thread Thomas Raehalme
Hi, We have a problem with IPA going out of service every now and then. There seems to be two kinds of situations: 1) The connection between named and dirsrv fails. Named can resolve external names but the domain managed by IPA does not resolve any names. named cannot be stopped. After killing

Re: [Freeipa-users] convert krbExtraData password to plain text

2014-06-16 Thread Sumit Bose
On Mon, Jun 16, 2014 at 12:28:09AM -0400, Dmitri Pal wrote: On 06/16/2014 12:20 AM, barry...@gmail.com wrote: dear all: Is it possible to quiry freeipa 's account password and displan in plain txt ? or convert krbExtraData to plaintxt. rather than reset it. Regards barry

Re: [Freeipa-users] named's LDAP connection hangs

2014-06-16 Thread Petr Spacek
On 16.6.2014 09:41, Thomas Raehalme wrote: Hi, We have a problem with IPA going out of service every now and then. There seems to be two kinds of situations: 1) The connection between named and dirsrv fails. Named can resolve external names but the domain managed by IPA does not resolve any

Re: [Freeipa-users] convert krbExtraData password to plain text

2014-06-16 Thread Simo Sorce
On Mon, 2014-06-16 at 12:20 +0800, barry...@gmail.com wrote: dear all: Is it possible to quiry freeipa 's account password and displan in plain txt ? or convert krbExtraData to plaintxt. rather than reset it. FWIW, krbExtraData does not contain passwords. Simo. -- Simo Sorce * Red Hat,

Re: [Freeipa-users] External collaboration edits

2014-06-16 Thread Nordgren, Bryce L -FS
[...talking about views...] It's not only about AD, but use-case and examples in the design page currently all refer to AD. The key is to find a unique reference to the upstream object which in the AD case is obviously the SID. In a previous version of the page there were a bit more details

[Freeipa-users] Problem finding new users via command line

2014-06-16 Thread John Moyer
Hello All, I'm having a problem querying new users. I can create the user from the webpage no problem, and I can see them afterwards via the webpage. I can then see those users via ipa user-find, as well as a LOCAL ldapsearch, even remotely from apache directory studio. However, if

Re: [Freeipa-users] named's LDAP connection hangs

2014-06-16 Thread Thomas Raehalme
Hi! Thanks for the instructions. I have configured KRB5_TRACE as described. I will send logs as soon as we encounter the problem again. Could take a week or two though. Thank you for your help! Best regards, Thomas On Mon, Jun 16, 2014 at 1:54 PM, Petr Spacek pspa...@redhat.com wrote: On

Re: [Freeipa-users] Problem finding new users via command line

2014-06-16 Thread Dmitri Pal
On 06/16/2014 04:20 PM, John Moyer wrote: Hello All, I'm having a problem querying new users. I can create the user from the webpage no problem, and I can see them afterwards via the webpage. I can then see those users via ipa user-find, as well as a LOCAL ldapsearch, even remotely

Re: [Freeipa-users] Problem finding new users via command line

2014-06-16 Thread Rob Crittenden
John Moyer wrote: Hello All, I'm having a problem querying new users. I can create the user from the webpage no problem, and I can see them afterwards via the webpage. I can then see those users via ipa user-find, as well as a LOCAL ldapsearch, even remotely from apache