[Freeipa-users] Re: cannot access webui

2019-06-20 Thread Boyd Ako via FreeIPA-users
Well the Web UI is one part of the IPA server. To debug IPA you might want to look at the SSSD.conf debug_level (https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/deployment_guide/sssd-troubleshooting). Can you elaborate what you see when trying to log in? If you se

[Freeipa-users] IPA Client failed login after screen lock

2019-06-20 Thread Boyd Ako via FreeIPA-users
So, I created a Red Hat ticket to assist and the support is pretty non-productive. I have a RHEL 7 "Workstation" setup as an IPA client that most of the time works. However, there are occasions when the screen locks out due to inactivity that I can't log back in. Most of the time it occurs when

[Freeipa-users] Re: cannot access webui

2019-06-20 Thread Peter Zoltan Keresztes (zozo) via FreeIPA-users
The service is up and running. I am able to access it via cli. Apache is also running. There is not yet firewall installed on the server. This is what I can now see in the apache access and error logs: ==> apache2/error.log <== [Thu Jun 20 17:35:14.632329 2019] [wsgi:error] [pid 13793:tid 13986

[Freeipa-users] Re: cannot access webui

2019-06-20 Thread John Keates via FreeIPA-users
Start at the beginning: - Is the install running? (ipactl status) - Is apache listening (ss -l or netstar -l or systemctl status apache2/httpd/apache/whatverthenameis) - Is the firewall letting you in? - What does /var/log/apache2 or /var/log/httpd or whatever it’s configured to log to say? Joh

[Freeipa-users] cannot access webui

2019-06-20 Thread Peter Zoltan Keresztes (zozo) via FreeIPA-users
Hello, I have just installed the new freeipa on ubuntu18.04 and I am trying to login as admin in the web ui but I am not able to do it so. I was looking for any kind of logs but I don’t seam to find a way to debug the problem Any suggestion where to start looking? Regards Peter

[Freeipa-users] Re: kadmin service not running after installing ipa server

2019-06-20 Thread Peter Zoltan Keresztes (zozo) via FreeIPA-users
That worked. Thanks alot. > On 21 Jun 2019, at 00:05, Rob Crittenden wrote: > > Peter Zoltan Keresztes (zozo) via FreeIPA-users wrote: >> Hello >> >> I have just installed ipa-server on ubuntu 18.04 and I have observed >> that the kadmin service is not running. While investigating the issue >>

[Freeipa-users] Re: kadmin service not running after installing ipa server

2019-06-20 Thread Rob Crittenden via FreeIPA-users
Peter Zoltan Keresztes (zozo) via FreeIPA-users wrote: > Hello > > I have just installed ipa-server on ubuntu 18.04 and I have observed > that the kadmin service is not running. While investigating the issue > I’ve seen that is complaining about the not existance of the > /etc/krb5kdc/kadm5.acl. >

[Freeipa-users] kadmin service not running after installing ipa server

2019-06-20 Thread Keresztes Péter-Zoltán via FreeIPA-users
Hello I have just installed ipa-server on ubuntu 18.04 and I have observed that the kadmin service is not running. While investigating the issue I’ve seen that is complaining about the not existance of the /etc/krb5kdc/kadm5.acl. ipactl status Directory Service: RUNNING krb5kdc Service: RUNNING

[Freeipa-users] Better to Backup / Restore to new server ?

2019-06-20 Thread Karim Bourenane via FreeIPA-users
Hello I need your recommandation about the upgrade/restore from FreeIPA server actually in V 4.5.0 APIV 2.228 to V4.6.4 API 2.230 or last. Is better to Backup / Restore from the old to New IPA server, or to start ipa-server-upgrade from the old server ? As you know my old IPA version use the bgp

[Freeipa-users] kadmin service not running after installing ipa server

2019-06-20 Thread Peter Zoltan Keresztes (zozo) via FreeIPA-users
Hello I have just installed ipa-server on ubuntu 18.04 and I have observed that the kadmin service is not running. While investigating the issue I’ve seen that is complaining about the not existance of the /etc/krb5kdc/kadm5.acl. ipactl status Directory Service: RUNNING krb5kdc Service: RUNNING

[Freeipa-users] Re: AD's users ssh to IPA's client - should it work?

2019-06-20 Thread lejeczek via FreeIPA-users
On 20/06/2019 14:40, Sumit Bose wrote: >> Ok, the maybe to make it more bizzare, I've had it: >> >> includedir /etc/krb5.conf.d/ >> includedir /var/lib/sss/pubconf/krb5.include.d/ >>   >> [libdefaults] >>   default_realm = MINE.PRIVATE >>   dns_lookup_realm = true >>   dns_lookup_kdc = true >>   rd

[Freeipa-users] Re: Cert expired for pki-tomcat and process would not start

2019-06-20 Thread Sayfiddin, Farhad via FreeIPA-users
This is affecting 3 out of 4 our IPA servers. Would you recommend any other solution for this issue? We have only one CRL Master IPA server does not have this issue. Would breaking the replication and recreating replica from one good CRL Master IPA server could work? -Original Message-

[Freeipa-users] Re: AD's users ssh to IPA's client - should it work?

2019-06-20 Thread Sumit Bose via FreeIPA-users
On Wed, Jun 19, 2019 at 04:58:32PM +0100, lejeczek via FreeIPA-users wrote: > On 19/06/2019 16:20, Sumit Bose via FreeIPA-users wrote: > > On Wed, Jun 19, 2019 at 12:34:54PM +0100, lejeczek via FreeIPA-users wrote: > >> On 19/06/2019 10:09, Sumit Bose via FreeIPA-users wrote: > >>> On Wed, Jun 19,

[Freeipa-users] Re: IPA's CA - from its own to an external

2019-06-20 Thread Alexander Bokovoy via FreeIPA-users
On to, 20 kesä 2019, lejeczek via FreeIPA-users wrote: hi guys, I'm starting to look more thoroughly into CA and something I'm not sure is possible, and hoping you could shed more light onto, is - having IPA deployed with own CA is it possible to then, at a later point, move/migrate/change IPA t

[Freeipa-users] IPA's CA - from its own to an external

2019-06-20 Thread lejeczek via FreeIPA-users
hi guys, I'm starting to look more thoroughly into CA and something I'm not sure is possible, and hoping you could shed more light onto, is - having IPA deployed with own CA is it possible to then, at a later point, move/migrate/change IPA to subordinate type of CA with AD's CA as root? Is such a

[Freeipa-users] IPA's clients deny password auth to ssh - 6 (Permission denied) - but gssapi works.

2019-06-20 Thread lejeczek via FreeIPA-users
hi guys A Putty ssh off a AD's Win10 client to IPA's client (non-master) works with gssapi but without it and when need to use password I see: pam_sss(sshd:auth): received for user myuser@mine.private: 6 (Permission denied) To make it more bizarre, that same Win10 client does ssh with password(a