[Freeipa-users] Replacing IPA v3.0.0-51 on OEL6 with IPA v4.6.4-10 on OEL7: Making the newest replica the master

2019-08-01 Thread Auerbach, Steven via FreeIPA-users
I am struggling through this. I have a new server built and IPA 4.6.4-10 installed. I made it a replica from the v3.0.0-51 master. Ipa-replica-manage shows 3 ipa servers, the original 2 v3.0.0-51 servers and the new ipa v4.6.4-10 server. But when I poll for replication agreements I get no ans

[Freeipa-users] Re: ipa-replica-install ERROR

2019-08-01 Thread Boudjoudad Abdelkader via FreeIPA-users
I fixed the error by adding '.' to the reverse entry (freeipa.example.com.) and adding a reverse entry for replica (freeipa-replica.example.com.) On Thu, Aug 1, 2019 at 10:22 AM Boudjoudad Abdelkader wrote: > Hi Rob, > Thank you for the reply, > Here below the output of dig command, it looks lik

[Freeipa-users] Re: ipa-replica-install ERROR

2019-08-01 Thread Boudjoudad Abdelkader via FreeIPA-users
Hi Rob, Thank you for the reply, Here below the output of dig command, it looks like is returing the right hostname of ipa server in SECTION SERVER: #dig -x 172.16.x.y ; <<>> DiG 9.9.4-RedHat-9.9.4-74.el7_6.1 <<>> -x 172.16.x.y ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, s

[Freeipa-users] Re: How to get IPA client log data

2019-08-01 Thread Florence Blanc-Renaud via FreeIPA-users
On 8/1/19 2:06 PM, Boyd Ako via FreeIPA-users wrote: Anybody know how to get more log information on what the IPA client does? I already know about the stuff in /var/log/sssd, but I'm looking for something in regards to dynamic dns updates failing. When I ran `ipa-client-install` with the --en

[Freeipa-users] Re: Create kerberos keytab

2019-08-01 Thread Alexander Bokovoy via FreeIPA-users
On to, 01 elo 2019, Boyd Ako via FreeIPA-users wrote: I did as admin and still == [binary@ipa ~]$ klist Ticket cache: KEYRING:persistent:1000:1000 Default principal: ad...@neverland.ddns.me Valid starting Expires Service principal 08/01/2019 02:09:35 08/02/2019 02:0

[Freeipa-users] Re: [Announce] FreeIPA 4.7.3 released

2019-08-01 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > On 01/08/2019 07:10, Alexander Bokovoy wrote: >> On to, 01 elo 2019, lejeczek via FreeIPA-users wrote: > maybe push 4.6.6 to corp centos 7 too? It would be great > if that was > there for 7.6. I cannot comment on future Red Hat activities. >

[Freeipa-users] Re: How to get IPA client log data

2019-08-01 Thread François Cami via FreeIPA-users
On Thu, Aug 1, 2019 at 2:07 PM Boyd Ako via FreeIPA-users wrote: > > Anybody know how to get more log information on what the IPA client does? I > already know about the stuff in /var/log/sssd, but I'm looking for something > in regards to dynamic dns updates failing. Which version of sssd, ipa

[Freeipa-users] Re: [Announce] FreeIPA 4.7.3 released

2019-08-01 Thread lejeczek via FreeIPA-users
On 01/08/2019 07:10, Alexander Bokovoy wrote: > On to, 01 elo 2019, lejeczek via FreeIPA-users wrote: maybe push 4.6.6 to corp centos 7 too? It would be great if that was there for 7.6. >>> >>> I cannot comment on future Red Hat activities. >>> >> I'm talking about this - >> https://

[Freeipa-users] Re: Create kerberos keytab

2019-08-01 Thread Boyd Ako via FreeIPA-users
I did as admin and still == [binary@ipa ~]$ klist Ticket cache: KEYRING:persistent:1000:1000 Default principal: ad...@neverland.ddns.me Valid starting Expires Service principal 08/01/2019 02:09:35 08/02/2019 02:09:28 krbtgt/neverland.ddns...@neverland.ddns.me [binar

[Freeipa-users] How to get IPA client log data

2019-08-01 Thread Boyd Ako via FreeIPA-users
Anybody know how to get more log information on what the IPA client does? I already know about the stuff in /var/log/sssd, but I'm looking for something in regards to dynamic dns updates failing. When I ran `ipa-client-install` with the --enable-dns-updates option it kicked out an error saying

[Freeipa-users] Re: ipa ca renewal master and ipa replica

2019-08-01 Thread Florence Blanc-Renaud via FreeIPA-users
On 7/31/19 3:42 PM, Rob Verduijn via FreeIPA-users wrote: Hi Thanx for the answer, sadly i've experienced that filing a bug with Red hat can be a real challenge when you know your stuff. Since I'm not very familiar with the rewrite rules in combination with freeipa I won't be able to answer

[Freeipa-users] Re: AD -> FreeIPA sync incomplete

2019-08-01 Thread Theodor van Nahl via FreeIPA-users
> How are you trying to set this? I don't know of any active measures to > ensure this is disabled. Be aware that group sync hasn't been tested in > IPA for many years now, probably close to a decade. It may well work > fine but I'd test in a separate environment to be sure first. > Since the F