[Freeipa-users] Re: Problems setting up replica on Raspberry Pi 3B (ARM)

2018-05-15 Thread thierry bordaz via FreeIPA-users
Hi Jonathan, This problem looks new to me and has something specific to your environment. I think the best approach is to continue to debug on your system if you have the possibility to do so. From strace we can see that DS started smoothly (created its pid file then notified systemd it was r

[Freeipa-users] Web UI access for the AD domain users

2018-05-15 Thread Bart via FreeIPA-users
I have an instance of FreeIPA with AD trust established. I know that it is possible to enable access for the web ui for AD users by creating id override as it is explained here: https://www.freeipa.org/page/V4/AD_Users_Login. My question is: would it be possible to enable the same by creating an

[Freeipa-users] Changing configuration to use external certificate instead of self signed

2018-05-15 Thread Bart via FreeIPA-users
Hi all, I have an instance of FreeIPA with PKI server and self signed certificate. It runs on one of the two instances of FreeIPA server. Is it possible to rid of it and use external certificate instead? If so, what steps does it take? Or it would require to reinstall everything from scratch? If

[Freeipa-users] Re: Web UI access for the AD domain users

2018-05-15 Thread Alexander Bokovoy via FreeIPA-users
On ti, 15 touko 2018, Bart via FreeIPA-users wrote: I have an instance of FreeIPA with AD trust established. I know that it is possible to enable access for the web ui for AD users by creating id override as it is explained here: https://www.freeipa.org/page/V4/AD_Users_Login. My question is: wou

[Freeipa-users] Re: some basic questions about FreeIPA

2018-05-15 Thread Udo Rader via FreeIPA-users
On Mon, 2018-05-14 at 16:10 +0300, Alexander Bokovoy wrote: > On pe, 11 touko 2018, Udo Rader via FreeIPA-users wrote:Hi, > > [...] > > > > But what about DHCP and DNS? I understand that FreeIPA's backbone > > is > > the 389 DS. I guess migrating our DHCP DIT into 389 is doable, but > > what > > a

[Freeipa-users] Re: Web UI access for the AD domain users

2018-05-15 Thread Bart via FreeIPA-users
I see, thank you a lot for the explanation. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Re: CA_UNREACHABLE during ipa-replica-install

2018-05-15 Thread Jan Gardian via FreeIPA-users
Hello, Update with new CentOS packages fixed this issue. CA is now found and replication finished. Thanks for help With kind Regards, Jan Gardian On 05/09/2018 10:32 AM, Jan Gardian via FreeIPA-users wrote: Hello, Were you able to find some useful information from provided pki logs? Thank

[Freeipa-users] Re: Problems setting up replica on Raspberry Pi 3B (ARM)

2018-05-15 Thread Jonathan Vaughn via FreeIPA-users
Here is a backtrace from live gdb after the segfault. Looks like things went wrong somewhere during in the replication code ? Thread 36 "ns-slapd" received signal SIGSEGV, Segmentation fault. [Switching to Thread 0x9e0bc280 (LWP 4662)] strlen () at ../sysdeps/arm/armv6t2/strlen.S:142 142

[Freeipa-users] Re: Problems setting up replica on Raspberry Pi 3B (ARM)

2018-05-15 Thread Mark Reynolds via FreeIPA-users
This looks really familiar and I thought it was fixed.  It should have been fixed in 1.3.7.10-1 (https://pagure.io/389-ds-base/issue/49618).   In your debug session go "up" into agmt_maxcsn_update() and do: (gdb) p *agmt Then send us that output please. Thanks, Mark On 05/15/2018 05:29 PM, Jona

[Freeipa-users] Re: Changing configuration to use external certificate instead of self signed

2018-05-15 Thread Bjarne Blichfeldt via FreeIPA-users
Depends on the version you are running, but in the recent version this is really simple: http://www.freeipa.org/page/Using_3rd_part_certificates_for_HTTP/LDAP It basically boils down to first install the relevant root certificate, then install the new server certificate with: ipa-server-certinst