[Freeipa-users] Re: freeipa/certmonger for openvpn user certificates

2019-06-03 Thread Alexander Bokovoy via FreeIPA-users
On ma, 03 kesä 2019, Patrick Spinler via FreeIPA-users wrote: Thank you kindly Alexander! I confirm this set of privs and permissions did allow me to issue a user key and cert via certmonger. It also helped me understand a little better the structure of IPA permissions from the point of view

[Freeipa-users] Re: freeipa/certmonger for openvpn user certificates

2019-06-03 Thread Patrick Spinler via FreeIPA-users
Thank you kindly Alexander! I confirm this set of privs and permissions did allow me to issue a user key and cert via certmonger. It also helped me understand a little better the structure of IPA permissions from the point of view of someone who's done a little bit of LDAP backend work.

[Freeipa-users] Re: Smartcard host login w/ Third-Party CA and PKINIT

2019-06-03 Thread Florence Blanc-Renaud via FreeIPA-users
On 5/29/19 3:36 PM, Sumit Bose via FreeIPA-users wrote: On Wed, May 29, 2019 at 01:19:19PM -, Khurrum Maqb via FreeIPA-users wrote: They are indeed all self signed: #openssl x509 -in /var/kerberos/krb5kdc/kdc.crt -issuer -subject -noout issuer= /O=DOMAIN.COM/CN=server1.dom.ain subject=

[Freeipa-users] Re: Windows Integration - Using SSH Without Passwords

2019-06-03 Thread John Hearns via FreeIPA-users
Noting that MobaXterm supports GSSAPI https://www.mobatek.net/ In the Settings/SSH you have a choice of SSH Library : Native Windows MIT Kerberos Custom Library On Fri, 31 May 2019 at 17:25, Alexander Bokovoy via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > On pe, 31

[Freeipa-users] Re: ipa server upgrade fails - dirsrv complains about Unknown attribute syntax OID

2019-06-03 Thread Levin Stanislav via FreeIPA-users
Hello, all. Most likely, you faced with 389-ds upgrade issue: https://pagure.io/389-ds-base/issue/50410 30.05.2019 12:40, Dirk Streubel via FreeIPA-users пишет: > Hello Darac, > > i have the same problem like you at two IPA Servers. > > After an update my 389 Directory Server doesn't start