[Freeipa-users] Re: named-pkcs11 systemd service

2017-05-29 Thread Tomas Krizek via FreeIPA-users
On 05/29/2017 08:24 AM, Sigbjorn Lie-Soland via FreeIPA-users wrote: > Hi. > > I've had several discussions, tickets, crash dumps, logs, etc with the > team over the years regarding this issue. The issue disappeared on > rhel 6 after the troubleshooting, however it's re-appeared on rhel 7. > >

[Freeipa-users] Re: ipa command breaks by setting "NSSVerifyClient require"

2017-05-29 Thread Alexander Bokovoy via FreeIPA-users
On la, 27 touko 2017, Ivars Strazdiņš via FreeIPA-users wrote: Hi there, our IPA servers' https port is exposed to internet. I wanted to restrict access to Web UI by requesting a user certificate issued by IPA and enabling Apache setting "NSSVerifyClient require" (or "optional") in

[Freeipa-users] Re: SSSD Cache and Service Tickets

2017-05-29 Thread Sumit Bose via FreeIPA-users
On Sat, May 27, 2017 at 05:46:57PM +0200, Ronald Wimmer via FreeIPA-users wrote: > On 2017-05-26 18:51, Sumit Bose via FreeIPA-users wrote: > > [...] > > Did you ‘Allow GSSAPI credential delegation’ in the putty configuration? > > Additionally the internal Windows Kerberos handling only allows > >

[Freeipa-users] Re: named-pkcs11 systemd service

2017-05-29 Thread Sigbjorn Lie-Soland via FreeIPA-users
Hi. I've had several discussions, tickets, crash dumps, logs, etc with the team over the years regarding this issue. The issue disappeared on rhel 6 after the troubleshooting, however it's re-appeared on rhel 7. This is by no means a permanent fix. It's a workaround. The mentioned