[Freeipa-users] Re: Can't Add Replica: The changelog directory CLDB already exists and is not empty

2020-07-08 Thread Florence Blanc-Renaud via FreeIPA-users
Hi Andrey, it looks really similar to the issue https://bugzilla.redhat.com/show_bug.cgi?id=1590974 Can you check the access log and error log on the IPA server server-01.example.com? It seems that the issue happens when the replica installer tries to create the entry cn=changelog5,cn=config

[Freeipa-users] freshly installed FreeIPA server dies

2020-07-08 Thread Tony Brian Albers via FreeIPA-users
Hi guys, This is a new install, software used is: ipa-server.x86_644.8.4-7.module+el8.2.0+6046+aaa49f96 389-ds-base.x86_64 1.4.2.4-8.module+el8.2.0+5959+cfcaedbd I followed the install instructions in the documentation, and everything went fine. I haven't added any users or groups yet. I h

[Freeipa-users] Re: Options to deploy FreeIPA without domain delegation

2020-07-08 Thread Rob Crittenden via FreeIPA-users
john doe via FreeIPA-users wrote: > Are there any options to deploy it within an existing domain with the > constraints being: > > - no domain delegation DNS domain delegation? Do you mean it doesn't delegate any domains or it doesn't require delegation? > - write access to the applicable zone

[Freeipa-users] Options to deploy FreeIPA without domain delegation

2020-07-08 Thread john doe via FreeIPA-users
Are there any options to deploy it within an existing domain with the constraints being: - no domain delegation - write access to the applicable zone file prohibited - registering/using an external domain impossible; also no external nameserver access - FreeIPA allowing for no single label doma

[Freeipa-users] Re: OTP Radius 5 seconds timeout

2020-07-08 Thread Jochen Kellner via FreeIPA-users
Sergiy Genyuk via FreeIPA-users writes: > Thank you for your reply, I do have ipv6 disabled and in capture do not see > failed attempts. > In capture it is only ipv4: > > 1 0.0 xx.xx.xx.xx -> yy.yy.yy.yy RADIUS 117 Access-Request(1) > (id=214, l=75) > 2 7.889686902 yy.yy.yy.yy ->

[Freeipa-users] Re: FreeIPA/PKI CA/KRA Subsystem Certificate Renewal Failure (not yet expired)

2020-07-08 Thread Ilya Kogan via FreeIPA-users
Thanks for that info, I don't see any suspicious errors in startup that I haven't seen before. Just the following: - Token named "NSS Generic Crypto Services", not "NSS Certificate DB", skipping. - Error opening "/etc/httpd/alias/pwdfile.txt": No such file or directory. I don't think either of th

[Freeipa-users] Re: Logging of ipa migrate-ds

2020-07-08 Thread Rob Crittenden via FreeIPA-users
Alfred Victor via FreeIPA-users wrote: > Hi FreeIPA, > > We are testing an IPA deployment and regularly using expect to perform > ipa migrate-ds commands to keep the IPA environment refreshed. However, > I cannot seem to get any log trail of the migrates...it is proving > difficult in expect to ca

[Freeipa-users] Re: FreeIPA/PKI CA/KRA Subsystem Certificate Renewal Failure (not yet expired)

2020-07-08 Thread Rob Crittenden via FreeIPA-users
Ilya Kogan wrote: > Wow ok, that was easy. `getcert list` now reports correct expiration > dates for those certificates and they're all in MONITORING. It still has > that ca-error field although it's no longer trying to renew. Is that > going to be an issue or is it just going to try again when it'

[Freeipa-users] Logging of ipa migrate-ds

2020-07-08 Thread Alfred Victor via FreeIPA-users
Hi FreeIPA, We are testing an IPA deployment and regularly using expect to perform ipa migrate-ds commands to keep the IPA environment refreshed. However, I cannot seem to get any log trail of the migrates...it is proving difficult in expect to capture/log the output, and there appears to be no lo

[Freeipa-users] Re: [EXTERNAL] Re: Re: Password Policy Question

2020-07-08 Thread Rob Crittenden via FreeIPA-users
White, Daniel E. (GSFC-770.0)[NICS] wrote: > For your amusement: > > Red Hat Support referred me to > >   > > https://bugzilla.redhat.com/show_bug.cgi?id=1273040 (A RHEL 7 RFE) > >   > > and > >   > > https://bugzilla.redhat.com/show_bug.cgi?id=1654395 (The same RFE, > pushed to RHEL 8) IMH

[Freeipa-users] Re: Can't Add Replica: The changelog directory CLDB already exists and is not empty

2020-07-08 Thread Andrey Ptashnik via FreeIPA-users
Florence, Thank you for answering this. Still no luck yet, out of options where to look at: BEFORE: [root@server-02 ~]# ipa-server-install --uninstall ---8<--8<--8<--- Client uninstall complete. The ipa-client-install command was successful [root@ipa-server-02 ~]# [root@ipa-server-02 ~]#

[Freeipa-users] Re: FreeIPA/PKI CA/KRA Subsystem Certificate Renewal Failure (not yet expired)

2020-07-08 Thread Ilya Kogan via FreeIPA-users
Wow ok, that was easy. `getcert list` now reports correct expiration dates for those certificates and they're all in MONITORING. It still has that ca-error field although it's no longer trying to renew. Is that going to be an issue or is it just going to try again when it's time to renew and succee

[Freeipa-users] Re: [EXTERNAL] Re: Re: Password Policy Question

2020-07-08 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
For your amusement: Red Hat Support referred me to https://bugzilla.redhat.com/show_bug.cgi?id=1273040 (A RHEL 7 RFE) and https://bugzilla.redhat.com/show_bug.cgi?id=1654395 (The same RFE, pushed to RHEL 8) …, saying, "You can also set a policy to automatically disable an account if the pas

[Freeipa-users] Re: OTP Radius 5 seconds timeout

2020-07-08 Thread Sergiy Genyuk via FreeIPA-users
Hi Jochen, Thank you for your reply, I do have ipv6 disabled and in capture do not see failed attempts. In capture it is only ipv4: 1 0.0 xx.xx.xx.xx -> yy.yy.yy.yy RADIUS 117 Access-Request(1) (id=214, l=75) 2 7.889686902 yy.yy.yy.yy -> xx.xx.xx.xx RADIUS 90 Access-Accept(2) (i

[Freeipa-users] Re: OTP Radius 5 seconds timeout

2020-07-08 Thread Jochen Kellner via FreeIPA-users
Hello Sergiy, Sergiy Genyuk via FreeIPA-users writes: > I have setup radius proxy (DUO) and associate user with it. Everything works > except radius > timeout. It is 5 seconds and you have to be blazing fast to push the button > :-) > I did adjust radius timeout in freeipa to 30 seconds but

[Freeipa-users] OTP Radius 5 seconds timeout

2020-07-08 Thread Sergiy Genyuk via FreeIPA-users
Hello I have setup radius proxy (DUO) and associate user with it. Everything works except radius timeout. It is 5 seconds and you have to be blazing fast to push the button :-) I did adjust radius timeout in freeipa to 30 seconds but it is still 5 seconds. As well I have tried a trick with krb.

[Freeipa-users] Re: FreeIPA/PKI CA/KRA Subsystem Certificate Renewal Failure (not yet expired)

2020-07-08 Thread Florence Blanc-Renaud via FreeIPA-users
On 7/6/20 7:59 PM, Ilya Kogan via FreeIPA-users wrote: Hi, Thanks for the help so far! I've actually run `ipa-cert-fix` on both nodes, it says everything is ok on both nodes. When I run it with verbose mode, it spits out the command it's running and the certificate it got, for example:

[Freeipa-users] idm ad integration question

2020-07-08 Thread Rob Verduijn via FreeIPA-users
Hello, I've been working with idm ad integration for some time now. But one thing has always confused me. In all the docs it will tell you to check the dns to see if the dns records resolve. dig +short -t SRV _kerberos._udp.idm.example.com. dig +short -t SRV _ldap._tcp.idm.example.com. dig +short