[Freeipa-users] How to restrict FreeIPA's from registering external IPs on DNS?

2020-02-07 Thread Vinícius Ferrão via FreeIPA-users
Hello, My FreeIPA server have two IP addresses. It registers itself with the internal and the external addresses. There’s a way to only register the IPs from the internal interfaces? Example: ipa-ca A 172.26.255.254 A 146.164.29.90 nodacabeca A 146.164.29.90 A 172.26.255.254 I only want th

[Freeipa-users] Re: Kerberos troubles

2020-02-07 Thread Robbie Harwood via FreeIPA-users
Nicholas DeMarco via FreeIPA-users writes: > Here is better detail: > > We're having issue with kerberos and ipa client. > > While running ipa-client-install, when prompted for user who is authorized > to enroll we enter admin and his password but get "Preauthentication > failed". At no point in

[Freeipa-users] Re: Kerberos troubles

2020-02-07 Thread Nicholas DeMarco via FreeIPA-users
Here is better detail: We're having issue with kerberos and ipa client. While running ipa-client-install, when prompted for user who is authorized to enroll we enter admin and his password but get "Preauthentication failed". Same thing happens when we do "kinit admin". output of klist -ke klist

[Freeipa-users] Kerberos troubles

2020-02-07 Thread Nicholas DeMarco via FreeIPA-users
I'm having trouble with kerberos. On ipa: $ kinit [1625] 1581094928.1017: Response was from master KDC [1625] 1581094928.1018: Processing preauth types: 19 -and- $ kinit admin [1626] 1581094962.274365: Received error from KDC: -1765328360/Preauthentication failed [1626] 1581094962.274368: Pr

[Freeipa-users] Re: Make a certificate for external realm

2020-02-07 Thread Rob Crittenden via FreeIPA-users
iam pollux via FreeIPA-users wrote: > Hello, > > I have: > - a CA with Freeipa > - a sub CA with Freeipa too > - a server with certmonger installed on and connected to the sub CA > - an external client without freeipa neither Certmonger. > > CA, sub CA and server are on the same realm: domaine.f

[Freeipa-users] Make a certificate for external realm

2020-02-07 Thread iam pollux via FreeIPA-users
Hello, I have: - a CA with Freeipa - a sub CA with Freeipa too - a server with certmonger installed on and connected to the sub CA - an external client without freeipa neither Certmonger. CA, sub CA and server are on the same realm: domaine.fr The external client is on a different realm: newdoma

[Freeipa-users] Re: Confusion on LDAP changes for NIS automounts

2020-02-07 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/7/20 1:50 AM, Russell Jones via FreeIPA-users wrote: For those that find this later, these settings will show up if you search cn=config specifically. No idea why it doesn't show up on a full dump. Hi, with the following search: > [root@freeipa4 ~]# ldapsearch -x -D "cn=Directory M