[Freeipa-users] Re: migration command cannot enable user

2018-05-22 Thread barrykfl--- via FreeIPA-users
example 1 Operations Error Some entries were not deleted Hide details - aaron: user not found example 2 Is it possible to skip the password migration process so user no need confirm once ( all password harsh transffered so user use same password?

[Freeipa-users] Re: Major Server Failure

2018-05-22 Thread Mark Reynolds via FreeIPA-users
On 05/22/2018 05:32 PM, Michael Rainey (Contractor, Code 7320) via FreeIPA-users wrote: > The mystery continues.  It seems might be working but in reality it's > not.  The replica has stopped updating from the master and is unable > to talk to the LDAP server.  I'm fairly certain this is a

[Freeipa-users] Re: Major Server Failure

2018-05-22 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
The mystery continues.  It seems might be working but in reality it's not.  The replica has stopped updating from the master and is unable to talk to the LDAP server.  I'm fairly certain this is a certificate issue.  However, my certs appear to be valid. So far, the ipa-replica-manage command

[Freeipa-users] Re: ipa operation errors from a client, but not servers

2018-05-22 Thread Rob Crittenden via FreeIPA-users
Kat via FreeIPA-users wrote: > Now if only I could figure out how this happened??! > > Weirdness indeed. Had to re-install python-gssapi and then reboot the > server. > > everything working flawlessly now. rpm -V might show you if something is corrupted. rob > > -K > > > On 5/22/18 10:24,

[Freeipa-users] Re: ipa operation errors from a client, but not servers

2018-05-22 Thread Kat via FreeIPA-users
Now if only I could figure out how this happened??! Weirdness indeed. Had to re-install python-gssapi and then reboot the server. everything working flawlessly now. -K On 5/22/18 10:24, Alexander Bokovoy wrote: On ti, 22 touko 2018, Kat via FreeIPA-users wrote: Anyone seen this before?

[Freeipa-users] Re: Major Server Failure

2018-05-22 Thread Mark Reynolds via FreeIPA-users
On 05/22/2018 11:24 AM, Michael Rainey (Contractor, Code 7320) via FreeIPA-users wrote: > Well I'm sure how this happened.  It looks like I have an Identity > server that has a replication agreement with itself.  Is there a > method to help clean this up? > >> # ipa-replica-manage list sump. -v

[Freeipa-users] Re: ipa operation errors from a client, but not servers

2018-05-22 Thread Kat via FreeIPA-users
BUT - using your logic - I removed just python-gssapi and re-installed it and everything works again. Should have tried that. Kat On 5/22/18 10:24, Alexander Bokovoy wrote: On ti, 22 touko 2018, Kat via FreeIPA-users wrote: Anyone seen this before? Can't find anything in searches. (Client

[Freeipa-users] Re: ipa operation errors from a client, but not servers

2018-05-22 Thread Kat via FreeIPA-users
nope - first thing I looked at. On the client that works: $ sudo rpm -qa | grep gss cyrus-sasl-gssapi-2.1.26-21.el7.x86_64 python-gssapi-1.2.0-3.el7.x86_64 gssproxy-0.7.0-4.el7.x86_64 On the broken client: $ sudo rpm -qa | grep gss python-gssapi-1.2.0-3.el7.x86_64 gssproxy-0.7.0-4.el7.x86_64

[Freeipa-users] Re: Major Server Failure

2018-05-22 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
Well I'm sure how this happened.  It looks like I have an Identity server that has a replication agreement with itself.  Is there a method to help clean this up? # ipa-replica-manage list sump. -v Directory Manager password: sump.: replica   last init status: None   last init ended:

[Freeipa-users] Re: ipa operation errors from a client, but not servers

2018-05-22 Thread Alexander Bokovoy via FreeIPA-users
On ti, 22 touko 2018, Kat via FreeIPA-users wrote: Anyone seen this before? Can't find anything in searches. (Client - ipa-client-4.5.4-10.el7_5.1.x86_64) (Server - ipa-server-4.5.4-10.el7_5.1.x86_64) On a client, running RHEL 7.4, and IPA server is RHEL 7.5  $ipa user-show freddy --all ipa:

[Freeipa-users] ipa operation errors from a client, but not servers

2018-05-22 Thread Kat via FreeIPA-users
Anyone seen this before? Can't find anything in searches. (Client - ipa-client-4.5.4-10.el7_5.1.x86_64) (Server - ipa-server-4.5.4-10.el7_5.1.x86_64) On a client, running RHEL 7.4, and IPA server is RHEL 7.5  $ipa user-show freddy --all ipa: ERROR: ImportError: No module named gssapi Traceback

[Freeipa-users] Re: PKI with IPA

2018-05-22 Thread Rob Crittenden via FreeIPA-users
Maciej Drobniuch via FreeIPA-users wrote: > Hey Fraser, > > That it is in CRL format. Then yes. rob > > BR > Maciej > > On Fri, May 18, 2018 at 6:18 AM, Fraser Tweedale > wrote: > > Hi Maciej, > > I concur with the answers in

[Freeipa-users] Re: ipsilon

2018-05-22 Thread Andrew Meyer via FreeIPA-users
What about on CentOS 7? On Tuesday, May 22, 2018 5:08 AM, Jan Pazdziora via FreeIPA-users wrote: On Thu, May 17, 2018 at 10:53:13PM +0300, Alexander Bokovoy via FreeIPA-users wrote: > On to, 17 touko 2018, Andrew Meyer wrote: > > So I followed the

[Freeipa-users] Re: ipsilon

2018-05-22 Thread Jan Pazdziora via FreeIPA-users
On Thu, May 17, 2018 at 10:53:13PM +0300, Alexander Bokovoy via FreeIPA-users wrote: > On to, 17 touko 2018, Andrew Meyer wrote: > > So I followed the directions to add it to my dev freeipa servers, > > restarted the httpd.  But when I go to log in  at > > https://myserver/idp as admin or myself,

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-22 Thread Duncan Colhoun via FreeIPA-users
Thanks - very helpful ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-22 Thread Duncan Colhoun via FreeIPA-users
Thanks ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] Re: PKI with IPA

2018-05-22 Thread Maciej Drobniuch via FreeIPA-users
Hey Fraser, That it is in CRL format. BR Maciej On Fri, May 18, 2018 at 6:18 AM, Fraser Tweedale wrote: > Hi Maciej, > > I concur with the answers in Rob's reply. But I have one question. > > On Thu, May 17, 2018 at 04:03:36PM +0200, Maciej Drobniuch via > FreeIPA-users