[Freeipa-users] Re: Add a picture to freeipa user

2019-02-08 Thread Alexander Bokovoy via FreeIPA-users
On Fri, 08 Feb 2019, Rufa Rufa via FreeIPA-users wrote: Hello, Can someone please help me to add a picture to the freeipa user, i did the following steps: first, you don't need to add any additional attributes. jpegPhoto attribute is already in a default 389-ds set of LDAP schemes, since it

[Freeipa-users] Re: AD Trust: Add "mail" user attribute to AD -> IPA transfer

2019-02-08 Thread Alexander Bokovoy via FreeIPA-users
On Fri, 07 Dec 2018, Lenhardt, Matthias via FreeIPA-users wrote: Hi, we have an IPA 4.6.4 environment with an AD Trust configured and everything's working perfectly. My question is: Is it possible to configure, that extra AD user attributes are transfered? I would need the AD user attribute

[Freeipa-users] Add a picture to freeipa user

2019-02-08 Thread Rufa Rufa via FreeIPA-users
Hello, Can someone please help me to add a picture to the freeipa user, i did the following steps: 1- Create a new file with ldif extension: $vi test.ldif 2- copy the following lines: dn: cn=schema changetype: modify add: attributeTypes attributeTypes: (

[Freeipa-users] Re: Failed to start 389 Directory Server

2019-02-08 Thread Zarko D via FreeIPA-users
Thanks Thierry, IPA backup had failed much before, unfortunate not able to restore those logs. But I did some progress, by trying to restore different daily backups. And I found one, that was restored "successfully", and 389ds has started after that. But new problem is that replica from

[Freeipa-users] Re: AD Trust: Add "mail" user attribute to AD -> IPA transfer

2019-02-08 Thread Ernie M. via FreeIPA-users
I second this request. We have IPA/IDM configured with a one way trust to AD and it is working well. Yet we would like to have user Auth to LDAP in IPA/IDM and one (among others) fields that cannot be seen via LDAP queries is the AD Email field. This really stops the auth in most cases. There

[Freeipa-users] Re: CA no certs being tracked?

2019-02-08 Thread Rob Crittenden via FreeIPA-users
Chris Mohler via FreeIPA-users wrote: > Sorry for the delay and multiple posts. I'm having some trouble with my > mail client. > > thanks again for all the help > > As requested Here is the output from getcert list on the CA renewal master: So these errors are from today, when the certs are

[Freeipa-users] Possible to ignore all AD groups?

2019-02-08 Thread Charles Ulrich via FreeIPA-users
Hello, Hopefully this might be a straightforward question. I have testing instance of FreeIPA version 4.6.4 installed on CentOS 7 from the distro's default repos. I have it configured for a one-way trust to an Active Directory deployment. On the client side, I have installed and configured the

[Freeipa-users] Re: CA no certs being tracked?

2019-02-08 Thread Chris Mohler via FreeIPA-users
Sorry for the delay and multiple posts. I'm having some trouble with my mail client. thanks again for all the help As requested Here is the output from getcert list on the CA renewal master: Number of certificates and requests being tracked: 9. Request ID '20180131032610':     status:

[Freeipa-users] Re: CA no certs being tracked?

2019-02-08 Thread Rob Crittenden via FreeIPA-users
Chris Mohler via FreeIPA-users wrote: > I have not been able the get the expired certs renewed. I would > appreciate any help or advice that you have. Right we need information to help. getcert list output, journalctl -u certmonger or /var/log/messages, anything that will show status/output of

[Freeipa-users] Re: CA no certs being tracked?

2019-02-08 Thread Chris Mohler via FreeIPA-users
I have not been able the get the expired certs renewed. I would appreciate any help or advice that you have. Thanks, -Chris ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Upgrading from V3 on Fedora to V4 on CentOS, CA promotion steps?

2019-02-08 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/7/19 5:20 PM, Jernej Jakob via FreeIPA-users wrote: Thanks Florence. That was the way I had intended to do it (I've studied the process quite some time ago, enough that the guide I was studying got deleted), only my mind slipped when writing up the mail. Still, I can't run: "getcert list

[Freeipa-users] Re: CA no certs being tracked?

2019-02-08 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/7/19 8:22 PM, Chris Mohler via FreeIPA-users wrote: I have not been able to renew the expired certificates yet. I would appreciate help if possible. You will need to start repairing the CA renewal master. Can you provide the output of $ getcert list on that node? Depending on the list