[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-20 Thread Florence Blanc-Renaud via FreeIPA-users
On 4/20/20 8:39 PM, Andreas Bulling via FreeIPA-users wrote: Andreas Bulling via FreeIPA-users wrote: You have a chicken and egg problem. When replacing your certs on an existing infrastructure you first have to add your new CA certs using ipa-cacert-manage, then run ipa-certupdate on all enroll

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-20 Thread Andreas Bulling via FreeIPA-users
I noticed a weird "ipa" directly appended to the host URL. Not sure where this is coming from... ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-20 Thread Andreas Bulling via FreeIPA-users
This is what the Apache error log shows: [Mon Apr 20 20:40:32.719986 2020] [wsgi:error] [pid 24934:tid 139866966574848] [remote 141.58.21.12:59320] ipa: INFO: 401 Unauthorized: HTTPSConnectionPool(host='Xipa', port=443): Max retries exceeded with url: /session/cookie (Caused by NewConnectionEr

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-20 Thread Andreas Bulling via FreeIPA-users
> Andreas Bulling via FreeIPA-users wrote: > > You have a chicken and egg problem. When replacing your certs on an > existing infrastructure you first have to add your new CA certs using > ipa-cacert-manage, then run ipa-certupdate on all enrolled machines, > including masters, then you can run ip

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-20 Thread Rob Crittenden via FreeIPA-users
Andreas Bulling via FreeIPA-users wrote: > Dear all, > > I have recently started using FreeIPA (4.8.1 on Ubuntu) and now wanted to > replace the original SSL certificates for the web UI and the LDAP server with > official ones issued by our university. > > I've followed the procedure described

[Freeipa-users] Problems after replacing SSL certificates

2020-04-20 Thread Andreas Bulling via FreeIPA-users
Dear all, I have recently started using FreeIPA (4.8.1 on Ubuntu) and now wanted to replace the original SSL certificates for the web UI and the LDAP server with official ones issued by our university. I've followed the procedure described here (no errors): https://www.freeipa.org/page/Using_3r

[Freeipa-users] Re: Sudo command not working

2020-04-20 Thread Elhamsadat Azarian via FreeIPA-users
Hi i had this problem too. i studied all of these pages but it doesnt work and i had to stop working with IPA On Mon, 20 Apr 2020, 18:45 Rob Crittenden via FreeIPA-users, < freeipa-users@lists.fedorahosted.org> wrote: > Faraz Younus via FreeIPA-users wrote: > > Hi Team, > > I'm getting error when

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread thierry bordaz via FreeIPA-users
On 4/20/20 3:35 PM, Kees Bakker wrote: On 20-04-2020 15:16, thierry bordaz wrote: On 4/20/20 3:02 PM, Kees Bakker wrote: On 20-04-2020 14:51, Rob Crittenden wrote: Kees Bakker via FreeIPA-users wrote: On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: On 20-04-2020 09:09, Florence B

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Kees Bakker via FreeIPA-users
On 20-04-2020 15:35, Kees Bakker via FreeIPA-users wrote: > On 20-04-2020 15:16, thierry bordaz wrote: >> On 4/20/20 3:02 PM, Kees Bakker wrote: >>> On 20-04-2020 14:51, Rob Crittenden wrote: Kees Bakker via FreeIPA-users wrote: > On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: >

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Kees Bakker via FreeIPA-users
On 20-04-2020 15:16, thierry bordaz wrote: > On 4/20/20 3:02 PM, Kees Bakker wrote: >> On 20-04-2020 14:51, Rob Crittenden wrote: >>> Kees Bakker via FreeIPA-users wrote: On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: > On 20-04-2020 09:09, Florence Blanc-Renaud wrote: >> On

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread thierry bordaz via FreeIPA-users
On 4/20/20 3:02 PM, Kees Bakker wrote: On 20-04-2020 14:51, Rob Crittenden wrote: *** EXTERNAL E-MAIL *** Kees Bakker via FreeIPA-users wrote: On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: On 20-04-2020 09:09, Florence Blanc-Renaud wrote: On 4/20/20 8:28 AM, Kees Bakker via Fr

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Kees Bakker via FreeIPA-users
On 20-04-2020 14:51, Rob Crittenden wrote: > *** EXTERNAL E-MAIL *** > > > Kees Bakker via FreeIPA-users wrote: >> On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: >>> On 20-04-2020 09:09, Florence Blanc-Renaud wrote: On 4/20/20 8:28 AM, Kees Bakker via FreeIPA-users wrote: > Hey,

[Freeipa-users] Re: Sudo command not working

2020-04-20 Thread Rob Crittenden via FreeIPA-users
Faraz Younus via FreeIPA-users wrote: > Hi Team, > I'm getting error when executing sudo su on client server what can be > the issue sudo command is there  > > [faraz.younus@england-web-dev ~]$ sudo su > > [sudo] password for faraz.younus:  > > faraz.younus is not allowed to run sudo on england-

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Rob Crittenden via FreeIPA-users
Kees Bakker via FreeIPA-users wrote: > On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: >> On 20-04-2020 09:09, Florence Blanc-Renaud wrote: >>> On 4/20/20 8:28 AM, Kees Bakker via FreeIPA-users wrote: Hey, I'm looking for advice how to analyse/debug this. On one o

[Freeipa-users] Sudo command not working

2020-04-20 Thread Faraz Younus via FreeIPA-users
Hi Team, I'm getting error when executing sudo su on client server what can be the issue sudo command is there [faraz.younus@england-web-dev ~]$ sudo su [sudo] password for faraz.younus: faraz.younus is not allowed to run sudo on england-web-dev. This incident will be reported.

[Freeipa-users] Re: ipa: ERROR: CIFS server communication error: code "3221225506", message "{Access Denied} A process has requested access to an object but has not been granted those access rights."

2020-04-20 Thread Alexander Becker via FreeIPA-users
Hello, I know the thread is old, but I have the same problem. Were you able to find a solution? Any help would be helpful. Thank you! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Kees Bakker via FreeIPA-users
On 20-04-2020 09:58, Kees Bakker via FreeIPA-users wrote: > On 20-04-2020 09:09, Florence Blanc-Renaud wrote: >> On 4/20/20 8:28 AM, Kees Bakker via FreeIPA-users wrote: >>> Hey, >>> >>> I'm looking for advice how to analyse/debug this. >>> >>> On one of the masters the dirsrv is unresponsive. It r

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Kees Bakker via FreeIPA-users
On 20-04-2020 09:09, Florence Blanc-Renaud wrote: > On 4/20/20 8:28 AM, Kees Bakker via FreeIPA-users wrote: >> Hey, >> >> I'm looking for advice how to analyse/debug this. >> >> On one of the masters the dirsrv is unresponsive. It runs, but every >> attempt to connect it hangs. >> >> The command "

[Freeipa-users] Re: Bizarre behavior (SSO+MFA) asking for credentials on some servers, but with extra "specialness"

2020-04-20 Thread Sumit Bose via FreeIPA-users
On Thu, Apr 16, 2020 at 12:19:57AM -0400, Michael S. Moody via FreeIPA-users wrote: > Good evening, > > First, thank you, again, for FreeIPA. I know I say it every time I send a > message to the list, but it's magic. > > We're running into an interesting situation where some of our hosts are > r

[Freeipa-users] Re: dirsrv hangs soon after reboot

2020-04-20 Thread Florence Blanc-Renaud via FreeIPA-users
On 4/20/20 8:28 AM, Kees Bakker via FreeIPA-users wrote: Hey, I'm looking for advice how to analyse/debug this. On one of the masters the dirsrv is unresponsive. It runs, but every attempt to connect it hangs. The command "systemctl status" does not show anything alarming ● dirsrv@EXAMPLE-COM