[Freeipa-users] Re: FreeIPA 4.5.0 CentOS 7 managed ldap.conf entries

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Dagan McGregor via FreeIPA-users wrote: > Hi all, > > We have a number of CentOS 7 hosts enrolled with FreeIPA, and I have noticed > the ldap.conf on some hosts has two separate URI lines, similar to this: > > URI ldaps://ipa.example.com > BASE dc=example,dc=com > TLS_CACERT /etc/ipa/ca.crt > UR

[Freeipa-users] FreeIPA 4.5.0 CentOS 7 managed ldap.conf entries

2018-01-30 Thread Dagan McGregor via FreeIPA-users
Hi all, We have a number of CentOS 7 hosts enrolled with FreeIPA, and I have noticed the ldap.conf on some hosts has two separate URI lines, similar to this: URI ldaps://ipa.example.com BASE dc=example,dc=com TLS_CACERT /etc/ipa/ca.crt URI https://ipa.example.com This caused our configuration m

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Fraser Tweedale via FreeIPA-users
On Tue, Jan 30, 2018 at 05:29:46PM +0100, Christof Schulze via FreeIPA-users wrote: > Hi, > > > Checked AVCs first. Selinux is always a burden on our Fedora Clients. > > Certmonger is still trying. > > Does it make sense to make some timetravel for certificate renewal with the > Renewal master

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher wrote: > On 01/30/2018 02:27 PM, Rob Crittenden wrote: >> Not sure what you mean by arbitrary. You can definitely generate a CSR >> using your favorite tool and pass that to ipa cert-request. > > By arbitrary I meant a CSR/certificate that doesn't correspond to a host > (or user) that

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Ian Pilcher via FreeIPA-users
On 01/30/2018 02:27 PM, Rob Crittenden wrote: Not sure what you mean by arbitrary. You can definitely generate a CSR using your favorite tool and pass that to ipa cert-request. By arbitrary I meant a CSR/certificate that doesn't correspond to a host (or user) that is managed by the FreeIPA serv

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > On 01/30/2018 09:53 AM, Rob Crittenden wrote: >> Ian Pilcher via FreeIPA-users wrote: >>> >>> Jumping in to this thread ... I know how to generate a keypair and CSR, >>> but I've never been able to figure out how to get FreeIPA to generate a >>> certificate fr

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Ian Pilcher via FreeIPA-users
On 01/30/2018 09:53 AM, Rob Crittenden wrote: Ian Pilcher via FreeIPA-users wrote: Jumping in to this thread ... I know how to generate a keypair and CSR, but I've never been able to figure out how to get FreeIPA to generate a certificate from a CSR. If there's documentation somewhere that I'v

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Christof Schulze via FreeIPA-users
Hi, Checked AVCs first. Selinux is always a burden on our Fedora Clients. Certmonger is still trying. Does it make sense to make some timetravel for certificate renewal with the Renewal master, even if the renewal didn't work when the certificates where still valid? On 30.01.2018 16:42,

[Freeipa-users] Re: Howto renew certificates with external CA?

2018-01-30 Thread Harald.Husemann--- via FreeIPA-users
Hello Flo, I'm resending the mail since my first response was rejected because of SPF, and only found its way to the mailing list... Many thanks again for your response. First of all, I've figured out that the package "pki-symkey" was missing, so I've installed it with yum. Now, according to s

[Freeipa-users] Re: Howto renew certificates with external CA?

2018-01-30 Thread Harald Husemann via FreeIPA-users
Hello Flo, and thanks again for your response. First of all, I've figured out that the package "pki-symkey" was missing, so I've installed it with yum. Now, according to systemctl, pki-tomcatd is running: root@mat-ipa-master-1:~$ systemctl status pki-tomcatd@pki-tomcat.service ● pki-tomcatd@p

[Freeipa-users] Re: web administration on secondary node

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Andrew Meyer via FreeIPA-users wrote: > I was just checking the web admin on my secondary node (still in testing > phase) but it won't resolve at all. I'm not sure why. > > These are the only errors I have from the Apache logs: > > > > > [Tue Jan 30 09:49:54.429727 2018] [mpm_prefork:notice]

[Freeipa-users] Re: web administration on secondary node

2018-01-30 Thread Andrew Meyer via FreeIPA-users
Please ignore.  This is an issue w/ my proxy. On Tuesday, January 30, 2018 10:01 AM, Andrew Meyer via FreeIPA-users wrote: I was just checking the web admin on my secondary node (still in testing phase) but it won't resolve at all.  I'm not sure why. These are the only errors I have f

[Freeipa-users] web administration on secondary node

2018-01-30 Thread Andrew Meyer via FreeIPA-users
I was just checking the web admin on my secondary node (still in testing phase) but it won't resolve at all. I'm not sure why. These are the only errors I have from the Apache logs: [Tue Jan 30 09:49:54.429727 2018] [mpm_prefork:notice] [pid 3637] AH00170: caught SIGWINCH, shutting down gra

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > On 01/29/2018 05:32 PM, Fraser Tweedale via FreeIPA-users wrote: >> Ideally you should generate the keys and create a CSR on the device. >> Then use IPA to issue certificates for the user. > > Jumping in to this thread ... I know how to generate a keypair and

[Freeipa-users] Re: FreeIPA 4.6.1 cannot bind on 636 but can connect on port.

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Matt . via FreeIPA-users wrote: > Hi, > > I can do! > > Can it be that the certificate, self signed, is more of a security issue now > and that causes the problem ? In the past I was able to use a selfsigned one > for internal tests. > As I asked in IRC you need to provide a GOOD description

[Freeipa-users] Re: FreeIPA PKI with OpenVPN

2018-01-30 Thread Ian Pilcher via FreeIPA-users
On 01/29/2018 05:32 PM, Fraser Tweedale via FreeIPA-users wrote: Ideally you should generate the keys and create a CSR on the device. Then use IPA to issue certificates for the user. Jumping in to this thread ... I know how to generate a keypair and CSR, but I've never been able to figure out h

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Christof Schulze via FreeIPA-users wrote: > Hi, > > Here may be the problem, all are masters, the idm1 I am working on is > the CA renewal master (checked ldap and config-show). > > IPA masters: idm1.ww8kd.fau.de, idm2.ww8kd.fau.de, idm3.ww8kd.fau.de > IPA CA servers: idm1.ww8kd.fau.de, idm2.ww8k

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Trevor Vaughan via FreeIPA-users wrote: > Hi All, > > I have a setup where I have a root CA and a sub CA and the sub CA is set > up with a KRA and SCEP enabled. > > I've fired up certmonger and added the SCEP CA. > > When I attempt to request a certificate, the enrollment completes > successfull

[Freeipa-users] Re: FreeIPA 4.6.1 cannot bind on 636 but can connect on port.

2018-01-30 Thread Matt . via FreeIPA-users
Hi, I can do! Can it be that the certificate, self signed, is more of a security issue now and that causes the problem ? In the past I was able to use a selfsigned one for internal tests. Cheers, Matt ___ FreeIPA-users mailing list -- freeipa-users@

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Christof Schulze via FreeIPA-users
Hi, Here may be the problem, all are masters, the idm1 I am working on is the CA renewal master (checked ldap and config-show). IPA masters: idm1.ww8kd.fau.de, idm2.ww8kd.fau.de, idm3.ww8kd.fau.de IPA CA servers: idm1.ww8kd.fau.de, idm2.ww8kd.fau.de, idm3.ww8kd.fau.de IPA NTP servers: idm1.ww8

[Freeipa-users] Issue with SCEP enrollment to sub-CA

2018-01-30 Thread Trevor Vaughan via FreeIPA-users
Hi All, I have a setup where I have a root CA and a sub CA and the sub CA is set up with a KRA and SCEP enabled. I've fired up certmonger and added the SCEP CA. When I attempt to request a certificate, the enrollment completes successfully per the Dogtag side of the equation but the response fro

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Florence Blanc-Renaud via FreeIPA-users
On 01/30/2018 02:02 PM, Christof Schulze via FreeIPA-users wrote: Hi, Now the roof is on fire, all certificates are synced on all masters since a long time ago. The not renewing certificates in /etc/pki/pki-tomcat/alias have now expired "subsystemCert cert-pki-ca" , "ocspSigningCert cer

[Freeipa-users] Re: Howto renew certificates with external CA?

2018-01-30 Thread Florence Blanc-Renaud via FreeIPA-users
On 01/24/2018 07:35 PM, Harald.Husemann--- via FreeIPA-users wrote: Hello Flo, thanks for your answer, and for the explanation of the certutil output. I have tried your suggestion, first with sudo: hhuseman@mat-ipa-master-1:~$ sudo kinit -kt /etc/krb5.keytab [sudo] password for hhuseman: Sorry

[Freeipa-users] Re: Certificates not renewed till 2 hours before expiring

2018-01-30 Thread Christof Schulze via FreeIPA-users
Hi, Now the roof is on fire, all certificates are synced on all masters since a long time ago. The not renewing certificates in /etc/pki/pki-tomcat/alias have now expired "subsystemCert cert-pki-ca" , "ocspSigningCert cert-pki-ca" , "/var/lib/ipa/ra-agent.pem" The "auditSigningCert

[Freeipa-users] Re: AD policies

2018-01-30 Thread Daniele Liciotti via FreeIPA-users
Perfect. The example has been very clear. Thank you very much! Regards, Daniele On 30 January 2018 at 11:00, Alexander Bokovoy wrote: > On ti, 30 tammi 2018, Daniele Liciotti via FreeIPA-users wrote: >> >> Hi, >> >> I have connected my FreeIPA server with an AD in trust. Is it possible >> to ass

[Freeipa-users] Re: AD policies

2018-01-30 Thread Alexander Bokovoy via FreeIPA-users
On ti, 30 tammi 2018, Daniele Liciotti via FreeIPA-users wrote: Hi, I have connected my FreeIPA server with an AD in trust. Is it possible to assign special permissions (sudo) to some AD users? I noticed that the policies can only be set to AD group. Policies can only be assigned to POSIX users

[Freeipa-users] AD policies

2018-01-30 Thread Daniele Liciotti via FreeIPA-users
Hi, I have connected my FreeIPA server with an AD in trust. Is it possible to assign special permissions (sudo) to some AD users? I noticed that the policies can only be set to AD group. Thanks in advance, Daniele ___ FreeIPA-users mailing list -- freei

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-30 Thread Roderick Johnstone via FreeIPA-users
On 25/01/2018 16:56, Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 13:43, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 21:09, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 15:2