[Freeipa-users] FreeIPA Active Directory trust configuration issues

2021-03-09 Thread iulian roman via FreeIPA-users
Hello, I try to configure trust between a FreeIPA domain and Active Directory. They are both in different domains (ipa domain: ipadev.test.local , ad domain: iam.intern ) and use external DNS. I have configured/verified all prerequisites, but when I run ipa trust-add command, I get the followi

[Freeipa-users] Re: FreeIPA Active Directory trust configuration issues

2021-03-09 Thread Alexander Bokovoy via FreeIPA-users
On ti, 09 maalis 2021, iulian roman via FreeIPA-users wrote: Hello, I try to configure trust between a FreeIPA domain and Active Directory. They are both in different domains (ipa domain: ipadev.test.local , ad domain: iam.intern ) and use external DNS. I have configured/verified all prerequisit

[Freeipa-users] Re: FreeIPA Active Directory trust configuration issues

2021-03-09 Thread iulian roman via FreeIPA-users
Thank you for clarifications Alexander. OS version: Ubuntu 18.04.2 LTS samba version : Version 4.7.6-Ubuntu FreeIPA version: 4.7.4 If I understand correctly does not make any sense to continue troubleshooting as long as AD trust is not supported with this OS version. I'll try to see what are

[Freeipa-users] Re: Replication broken

2021-03-09 Thread Antoine Gatineau via FreeIPA-users
I could rebuild my cluster from backup before the upgrade to CentOS Stream. So I'll be able to work from there. On Mon, 2021-03-08 at 17:41 +0100, Antoine Gatineau via FreeIPA-users wrote: > Hello, > > I'm on freeipa 4.9.0 on CentOS Stream. (1 master and 1 replica) > I have noticed that my replic

[Freeipa-users] Re: FreeIPA Active Directory trust configuration issues

2021-03-09 Thread François Cami via FreeIPA-users
On Tue, Mar 9, 2021 at 10:52 AM iulian roman via FreeIPA-users wrote: > > Thank you for clarifications Alexander. > > OS version: Ubuntu 18.04.2 LTS > samba version : Version 4.7.6-Ubuntu > FreeIPA version: 4.7.4 > > If I understand correctly does not make any sense to continue > troubleshootin

[Freeipa-users] Re: FreeIPA Active Directory trust configuration issues

2021-03-09 Thread Alexander Bokovoy via FreeIPA-users
On ti, 09 maalis 2021, iulian roman via FreeIPA-users wrote: Thank you for clarifications Alexander. OS version: Ubuntu 18.04.2 LTS samba version : Version 4.7.6-Ubuntu FreeIPA version: 4.7.4 If I understand correctly does not make any sense to continue troubleshooting as long as AD trust is n

[Freeipa-users] uninstall - Deleting this server will leave your installation without a CRL generation master

2021-03-09 Thread lejeczek via FreeIPA-users
Hi guys. I'm trying to remove a master from my domain and I get: -> $ ipa-server-install --uninstall --unattended Deleting this server will leave your installation without a CRL generation master. ipapython.admintool: ERROR    Aborting uninstall operation. ipapython.admintool: ERROR    The ipa

[Freeipa-users] Re: uninstall - Deleting this server will leave your installation without a CRL generation master

2021-03-09 Thread François Cami via FreeIPA-users
On Tue, Mar 9, 2021 at 6:16 PM lejeczek via FreeIPA-users wrote: > > Hi guys. > > I'm trying to remove a master from my domain and I get: > > -> $ ipa-server-install --uninstall --unattended > Deleting this server will leave your installation without a > CRL generation master. > ipapython.admintoo

[Freeipa-users] Old users cannot login to new freeIPA client machine

2021-03-09 Thread Sam Bell via FreeIPA-users
I have a small FreeIPA setup and user login works ok on the client systems. Recently, I wanted to add a new machine as a client. I loaded Fedora 33 on the machine and installed freeipa-client. Installation seems to be ok and I can see all users with find-user on the client system. However, when e

[Freeipa-users] Re: Old users cannot login to new freeIPA client machine

2021-03-09 Thread Sumit Bose via FreeIPA-users
On Wed, Mar 10, 2021 at 03:48:34AM -, Sam Bell via FreeIPA-users wrote: > I have a small FreeIPA setup and user login works ok on the client systems. > Recently, I wanted to add a new machine as a client. > I loaded Fedora 33 on the machine and installed freeipa-client. Installation > seems t

[Freeipa-users] Re: Old users cannot login to new freeIPA client machine

2021-03-09 Thread Sam Bell via FreeIPA-users
Thanks for the reply. Following are the details: Server ip: 192.168.0.245 Client : 192.168.0.248 krb5_child.log content: (2021-03-10 15:47:06): [krb5_child[3066]] [main] (0x0400): krb5_child started. (2021-03-10 15:47:06): [krb5_child[3066]] [unpack_buffer] (0x1000): total buffer size: [96] (2021-