[Freeipa-users] LDAP encryption errors

2018-05-11 Thread Per Qvindesland via FreeIPA-users
Hi All We’re getting the following entries in the error logs [10/May/2018:15:37:18.628665013 +0100] - ERR - ipapwd_encrypt_encode_key - [file encoding.c, line 143]: no krbPrincipalName present in this entry [10/May/2018:15:37:18.630473873 +0100] - ERR - ipapwd_gen_hashes - [file encoding.c, li

[Freeipa-users] Re: LDAP encryption errors

2018-05-11 Thread Alexander Bokovoy via FreeIPA-users
On pe, 11 touko 2018, Per Qvindesland via FreeIPA-users wrote: Hi All We’re getting the following entries in the error logs [10/May/2018:15:37:18.628665013 +0100] - ERR - ipapwd_encrypt_encode_key - [file encoding.c, line 143]: no krbPrincipalName present in this entry [10/May/2018:15:37:18.63

[Freeipa-users] A record discrepency

2018-05-11 Thread Andrew Meyer via FreeIPA-users
On one of my FreeIPA servers I have an A record that points to the correct IP in the web ui, but when I go look at the raw file in /var/named/dyndb-ldap/ipa/master/zone.net/raw it is incorrect.  I have done a kinit admin, and then ipa-replica-manage re-initialize --from know.working.server.net.

[Freeipa-users] Re: A record discrepency

2018-05-11 Thread Andrew Meyer via FreeIPA-users
I think I figured out the issue.  I had the /etc/named.conf setup to do some forward zones only on my FreeIPA server.   I think this was causing the server not to update.  However after removing the zones from /etc/named.conf I no longer see the zone file on that server.  I go to look in /var/n

[Freeipa-users] Re: Major Server Failure

2018-05-11 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
While researching the steps to perform the offline initilalization I notice peculiarity with the the replica aggrements on the system I plan to use as my source data.  Notice the duplicate hostname from the ipa-csreplica-mange command.  Is this yet another concern?  If so, how do I remove the d

[Freeipa-users] FreeIPA Community Porta - intall errors - "No module named ipalib"

2018-05-11 Thread Henery Hawk via FreeIPA-users
Trying to follow the install instructions for the portal at http://freeipa-community-portal.readthedocs.io/en/latest/deploy.html#installation. Using Fedora Server 28. Any thoughts? When creating the stage user via script I get the following error: [*] sudo ./create-portal-user Traceback

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-11 Thread Josh via FreeIPA-users
On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please stay on topic and explain if you can why ktutil can't be used as described in https://kb.iu.edu/d/aumh? Does ipa make

[Freeipa-users] Re: obtaining initial ticket via keytab

2018-05-11 Thread Alexander Bokovoy via FreeIPA-users
On pe, 11 touko 2018, Josh wrote: On 05/11/2018 01:19 AM, Alexander Bokovoy wrote: On to, 10 touko 2018, Josh via FreeIPA-users wrote: Server certificate has expired and all ipa utilities fail. Could you please stay on topic and explain if you can why ktutil can't be used as described in https