Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-31 Thread Alexander Bokovoy
On Mon, 30 Jul 2012, Martin Kosek wrote: On 07/30/2012 01:34 PM, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as:

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-31 Thread Martin Kosek
On 07/31/2012 02:00 PM, Alexander Bokovoy wrote: On Mon, 30 Jul 2012, Martin Kosek wrote: On 07/30/2012 01:34 PM, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-31 Thread Martin Kosek
On 07/31/2012 04:20 PM, Alexander Bokovoy wrote: On Tue, 31 Jul 2012, Martin Kosek wrote: On 07/31/2012 02:00 PM, Alexander Bokovoy wrote: On Mon, 30 Jul 2012, Martin Kosek wrote: On 07/30/2012 01:34 PM, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-30 Thread Alexander Bokovoy
On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing Samba configuration and using LDAPI/autobind - kinit-ed IPA admin

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-30 Thread Simo Sorce
On Mon, 2012-07-30 at 14:34 +0300, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-30 Thread Martin Kosek
On 07/30/2012 01:34 PM, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing Samba

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-30 Thread Alexander Bokovoy
On Mon, 30 Jul 2012, Simo Sorce wrote: On Mon, 2012-07-30 at 14:34 +0300, Alexander Bokovoy wrote: On Fri, 27 Jul 2012, Rob Crittenden wrote: Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-27 Thread Rob Crittenden
Alexander Bokovoy wrote: On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing Samba configuration and using LDAPI/autobind - kinit-ed IPA admin user, to ensure proper ACIs are granted to

[Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-26 Thread Alexander Bokovoy
Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing Samba configuration and using LDAPI/autobind - kinit-ed IPA admin user, to ensure proper ACIs are granted to fetch keytab As result, we can get rid of Directory Manager

Re: [Freeipa-devel] [PATCH] 0065 Ensure ipa-adtrust-install is run with administrator privileges and Kerberos ticket

2012-07-26 Thread Alexander Bokovoy
On Thu, 26 Jul 2012, Alexander Bokovoy wrote: Hi, When setting up AD trusts support, ipa-adtrust-install utility needs to be run as: - root, for performing Samba configuration and using LDAPI/autobind - kinit-ed IPA admin user, to ensure proper ACIs are granted to fetch keytab As