[Freeipa-users] Re: CA no certs being tracked?

2019-02-07 Thread Chris Mohler via FreeIPA-users
I have not been able to renew the expired certificates yet. I would appreciate help if possible. Followup summary: Q: Seems like part of the problem is that the KDC was not running. Had you done ipactl stop prior to the upgrade? A: I could not get the KDC to stay running. So yes it was

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Rob Crittenden via FreeIPA-users
Jernej Jakob via FreeIPA-users wrote: > - Izvirno sporočilo - > Od: "Rob Crittenden" > Za: "FreeIPA users list" > Cc: "Jernej Jakob" > Poslano: Četrtek, 7. Februar 2019 17:05:47 > Zadeva: Re: [Freeipa-users] Upgrading from V3 on Fedora to V4 on CentOS, CA > promotion steps? > >> There

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Jernej Jakob via FreeIPA-users
- Izvirno sporočilo - Od: "Rob Crittenden" Za: "FreeIPA users list" Cc: "Jernej Jakob" Poslano: Četrtek, 7. Februar 2019 17:05:47 Zadeva: Re: [Freeipa-users] Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps? > There is no 8 yet. There is the 8 beta, I was thinking I'd

[Freeipa-users] Re: is anyone running Debian as freeipa-client

2019-02-07 Thread Johan Vermeulen via FreeIPA-users
Hello, thanks for al the work on this. In the mean time I guess the freeze is already there. So how does it go from here with Buster/freeipa? Grtz j. Op vr 11 jan. 2019 om 11:43 schreef Timo Aaltonen via FreeIPA-users < freeipa-users@lists.fedorahosted.org>: > On 11.1.2019 12.10, Alexander

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Jernej Jakob via FreeIPA-users
Thanks Florence. That was the way I had intended to do it (I've studied the process quite some time ago, enough that the guide I was studying got deleted), only my mind slipped when writing up the mail. Still, I can't run: "getcert list -d /var/lib/pki-ca/alias -n "subsystemCert cert-pki-ca" |

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Rob Crittenden via FreeIPA-users
Jernej Jakob via FreeIPA-users wrote: > Hi, > > I'm tasked with upgrading our current setup of 3.3.5 on F19 to something more > recent and stable (CentOS 7 or CentOS 8). There is no 8 yet. > > There were instructions at >

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/7/19 3:48 PM, Jernej Jakob via FreeIPA-users wrote: Hi, I'm tasked with upgrading our current setup of 3.3.5 on F19 to something more recent and stable (CentOS 7 or CentOS 8). There were instructions at

[Freeipa-users] Re: Failed to start 389 Directory Server

2019-02-07 Thread thierry bordaz via FreeIPA-users
Hi, The IPA message are from Jan 28th (failing ipa backup ) while the restart failure is from Feb 2nd. Nothing in the ds error logs from Jan28th ? The first message "Detected Disorderly Shutdown" means that DS stopped abruptly (crash, assert,..). So at restart it runs a recovery of the

[Freeipa-users] Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-07 Thread Jernej Jakob via FreeIPA-users
Hi, I'm tasked with upgrading our current setup of 3.3.5 on F19 to something more recent and stable (CentOS 7 or CentOS 8). There were instructions at

[Freeipa-users] Re: FreeIPA CS replication issues

2019-02-07 Thread dbischof--- via FreeIPA-users
Hi German, On Wed, 6 Feb 2019, German Parente via FreeIPA-users wrote: this is a bug in the product that might have been fixed already: Connectivity: left-right we cannot have these sort of connectivity. In ipa02 there's no replication agreement to ipa01 (for ipaca database). But as in

[Freeipa-users] Re: FreeIPA CS replication issues

2019-02-07 Thread dbischof--- via FreeIPA-users
Hi Rob, On Wed, 6 Feb 2019, Rob Crittenden via FreeIPA-users wrote: dbischof--- via FreeIPA-users wrote: On Wed, 6 Feb 2019, dbischof--- via FreeIPA-users wrote: On Wed, 6 Feb 2019, Florence Blanc-Renaud via FreeIPA-users wrote:  On 2/5/19 4:17 PM, dbischof--- via FreeIPA-users wrote:  

[Freeipa-users] Re: Log into web UI with AD user?

2019-02-07 Thread Alexander Bokovoy via FreeIPA-users
On ke, 06 helmi 2019, Charles Ulrich via FreeIPA-users wrote: Hello, I'm setting up a test instance of FreeIPA with a one-way trust to the organization's AD. So far, that all appears to be working. I can run LDAP queries to look up users, I can log into the test instance via Kerberos, it's all