[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread François Cami via FreeIPA-users
On Tue, Apr 30, 2019 at 10:37 AM Karim Bourenane wrote: > > Hello François, all > > Thank you, for the release link version and the Redhat link. > > I just start on small architecture with 1 master + 2 replicats (no link > between), exept via the Master. This is not a recommended replication sch

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
Hello François, all Thank you, for the release link version and the Redhat link. I just start on small architecture with 1 master + 2 replicats (no link between), exept via the Master. I will install / configure the ipa-client, to bind with this 2 replicats. Question : On the replicat server, wh

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
François, Thanks you, about the architecture redundancy strategy. Is not the final architecture. The new architecture will be have more redundancy with more Master and more replicat server in each site, to authenticate several ipa-client. I will deploy more redundancy, but never between each branc

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread François Cami via FreeIPA-users
On Tue, Apr 30, 2019 at 2:22 PM Karim Bourenane wrote: > > François, > > Thanks you, about the architecture redundancy strategy. > Is not the final architecture. The new architecture will be have more > redundancy with more Master and more replicat server in each site, to > authenticate several

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
François I will do it as a recommandation on Redhat doc for the strategy design of replication. I have another question, not related with my experience :). When you buid 2 separate IPA server, and after you want to synchronize them together, I must to install the replication with ipa-replicat-in

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread François Cami via FreeIPA-users
On Tue, Apr 30, 2019 at 5:42 PM Karim Bourenane wrote: > > François > > I will do it as a recommandation on Redhat doc for the strategy design of > replication. > > I have another question, not related with my experience :). > > When you buid 2 separate IPA server, and after you want to synchroni

[Freeipa-users] Nfs server deleted from GUI. Need help

2019-04-30 Thread Karim Bourenane via FreeIPA-users
Hello , Our dedicat NFS server was removed from the IPA GUI. The service does'nt work since this time ONLY for new users. How to restore service for all users without losing the data and the hand ? Can you please help me to correct this state ? Regards Karim Bourenane ___

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
thank you for confirmations on that. I have another request, but I will open another post, to separate the pb. Karim Bourenane Le lun. 29 avr. 2019 à 23:09, François Cami a écrit : > On Mon, Apr 29, 2019 at 10:32 PM Karim Bourenane via FreeIPA-users > wrote: > > > > Hello Jochen > > > > Than

[Freeipa-users] Re: Doing SSO on a non-IPA joined OS X system

2019-04-30 Thread Charles Hedrick via FreeIPA-users
Kerberos works fine on OS X. as long as you don’t need Two Factor authentication or HTTPS proxy. If you need those, install the kerberos5 and ssh packages from MacPorts. ssh, sshd, the NFS client (Kerberized NFS version 3 and 4), Chome and Firefox (SPNEGO) all support Kerberos. I think “join t

[Freeipa-users] Strange ipa group-add gid behavior

2019-04-30 Thread Orion Poplawski via FreeIPA-users
We're seeing some strange gid assignment behavior. When I run ipa group-add on one ipa client I get gids in the expected range for my domain (8000-1). But when it is run on one of our IPA servers we get numbers like 108500 or 58500. ipa idrange-find reports what I would expect everywhere: #

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Alexander Bokovoy via FreeIPA-users
On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote: We're seeing some strange gid assignment behavior. When I run ipa group-add on one ipa client I get gids in the expected range for my domain (8000-1). But when it is run on one of our IPA servers we get numbers like 108500 or 58

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Orion Poplawski via FreeIPA-users
On 4/30/19 2:00 PM, Alexander Bokovoy wrote: > On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote: >> We're seeing some strange gid assignment behavior.  When I run ipa group-add >> on one ipa client I get gids in the expected range for my domain >> (8000-1). >> But when it is run o

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Rob Crittenden via FreeIPA-users
Orion Poplawski via FreeIPA-users wrote: > On 4/30/19 2:00 PM, Alexander Bokovoy wrote: >> On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote: >>> We're seeing some strange gid assignment behavior.  When I run ipa group-add >>> on one ipa client I get gids in the expected range for my do

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Orion Poplawski via FreeIPA-users
On 4/30/19 2:14 PM, Rob Crittenden wrote: > Orion Poplawski via FreeIPA-users wrote: >> On 4/30/19 2:00 PM, Alexander Bokovoy wrote: >>> On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote: We're seeing some strange gid assignment behavior.  When I run ipa group-add on one

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Alexander Bokovoy via FreeIPA-users
On ti, 30 huhti 2019, Orion Poplawski wrote: On 4/30/19 2:14 PM, Rob Crittenden wrote: Orion Poplawski via FreeIPA-users wrote: On 4/30/19 2:00 PM, Alexander Bokovoy wrote: On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote: We're seeing some strange gid assignment behavior.  When

[Freeipa-users] Re: Strange ipa group-add gid behavior

2019-04-30 Thread Orion Poplawski via FreeIPA-users
On 4/30/19 2:51 PM, Alexander Bokovoy wrote: > On ti, 30 huhti 2019, Orion Poplawski wrote: >> On 4/30/19 2:14 PM, Rob Crittenden wrote: >>> Orion Poplawski via FreeIPA-users wrote: On 4/30/19 2:00 PM, Alexander Bokovoy wrote: > On ti, 30 huhti 2019, Orion Poplawski via FreeIPA-users wrote