[Freeipa-users] Re: Unable to login to IPA console

2019-11-07 Thread Nikita Deeksha via FreeIPA-users
Thanks for the update Alexander will check this and get back to you, wanted to check on another thing as well. Can you please help us to understand this error that we see for the cert in pki [root@ipa1 nikita.d]# for i in $(certutil -d /etc/pki/pki-tomcat/alias -L | grep cert-pki-ca | awk '{print

[Freeipa-users] Re: IPA healthcheck for older versions

2019-11-07 Thread Petros Triantafyllidis via FreeIPA-users
Thanks for healthcheck Rob, In our setup (2 CentOS 7.7 servers, running ipa-server-4.6.5-11.el7.centos.3.x86_64) I get the output below when ipa-healthcheck runs at the replica. The output is identical at master too, except the first warning ("No DNA range defined. If no masters define a rang

[Freeipa-users] Re: IPA healthcheck for older versions

2019-11-07 Thread Rob Crittenden via FreeIPA-users
Petros Triantafyllidis wrote: > Thanks for healthcheck Rob, > > In our setup (2 CentOS 7.7 servers, running > ipa-server-4.6.5-11.el7.centos.3.x86_64) I get the output below when > ipa-healthcheck runs at the replica. The output is identical at master > too, except the first warning ("No DNA range

[Freeipa-users] Re: Could not login with AD user

2019-11-07 Thread Ronald Wimmer via FreeIPA-users
On one of the IPA servers themselves a getent passwd myadu...@bau.mydomain.at is working. On the system where I cannot login with this user I do not get a result. What do I have to look for in which sssd log file in order to find out what the problem is? Cheers, Ronald

[Freeipa-users] Re: Unable to login to IPA console

2019-11-07 Thread Alexander Bokovoy via FreeIPA-users
On to, 07 marras 2019, Nikita Deeksha via FreeIPA-users wrote: Thanks for the update Alexander will check this and get back to you, wanted to check on another thing as well. Can you please help us to understand this error that we see for the cert in pki [root@ipa1 nikita.d]# for i in $(certutil

[Freeipa-users] Re: Could not login with AD user

2019-11-07 Thread Ronald Wimmer via FreeIPA-users
Simply increasing the krb5_auth_timeout in the client's sssd.conf did the trick. Thanks for the good troubleshooting guide at https://docs.pagure.org/SSSD.sssd/users/troubleshooting.html Cheers, Ronald ___ FreeIPA-users mailing list -- freeipa-users@l