[Freeipa-users] Fail to restart ipa server after ipa packages updates

2021-11-04 Thread MERCIER Jonathan via FreeIPA-users
Dear, After a package update from ipa-server-4.9.2-4.module+el8.4.0+589+9650b94f.x86_64 to ipa-server-4.9.2-4.module+el8.4.0+664+1636a961.x86_64 I am unable to restart ipa server services indeed the command /usr/sbin/ipa-server-upgrade fail as it is not able to reach 'https://ipa.somewher

[Freeipa-users] Re: Fail to restart ipa server after ipa packages updates

2021-11-04 Thread MERCIER Jonathan via FreeIPA-users
to complete information the named-pkcs11 service is started so it is not a problem to resolv host Here I see that the rest api is down to my understanding # systemctl status named-pkcs11 ● named-pkcs11.service - Berkeley Internet Name Domain (DNS) with native PKCS#11 Loaded: loaded (/us

[Freeipa-users] Re: Fail to restart ipa server after ipa packages updates

2021-11-04 Thread Alexander Bokovoy via FreeIPA-users
On to, 04 marras 2021, MERCIER Jonathan via FreeIPA-users wrote: to complete information the named-pkcs11 service is started so it is not a problem to resolv host Here I see that the rest api is down to my understanding Most likely you need to downgrade a JDK build. It is a known issue that i

[Freeipa-users] Re: Samba4 + FreeIPA

2021-11-04 Thread Cyrus via FreeIPA-users
Well, now that you mention it, I wonder what happens with the POSIX information for the user in the case of crediting all of them in Samba4. Shell, UID, HOME, ssh public key, itt seems I would need to extend the schema on that side. Would those parameters be recognized by machines joined to FreeIP

[Freeipa-users] Re: Samba4 + FreeIPA

2021-11-04 Thread Alexander Bokovoy via FreeIPA-users
On to, 04 marras 2021, Cyrus via FreeIPA-users wrote: Well, now that you mention it, I wonder what happens with the POSIX information for the user in the case of crediting all of them in Samba4. Shell, UID, HOME, ssh public key, itt seems I would need to extend the schema on that side. Would tho

[Freeipa-users] Re: Samba4 + FreeIPA

2021-11-04 Thread Cyrus via FreeIPA-users
Awesome, thanks! On Thu, Nov 4, 2021, 07:47 Alexander Bokovoy wrote: > On to, 04 marras 2021, Cyrus via FreeIPA-users wrote: > >Well, now that you mention it, I wonder what happens with the POSIX > >information for the user in the case of crediting all of them in Samba4. > > > >Shell, UID, HOME,

[Freeipa-users] Re: Samba Freeipa Authentication

2021-11-04 Thread Alexander Bokovoy via FreeIPA-users
On to, 04 marras 2021, Per Qvindesland wrote: Great many thanks, that worked really well. One quick question, I need to add the SRV records after running ad-trust-install  to the DNS but the main WIndows AD corporate DNS is not very usefu

[Freeipa-users] Re: Samba Freeipa Authentication

2021-11-04 Thread Per Qvindesland via FreeIPA-users
Great many thanks, that worked really well.One quick question, I need to add the SRV records after running ad-trust-install  to the DNS but the main WIndows AD corporate DNS is not very useful for those type of SRV records so I would like to install ipa's DNS add on and i found this article  ht

[Freeipa-users] Re: Samba Freeipa Authentication

2021-11-04 Thread Per Qvindesland via FreeIPA-users
Yes that’s correct, it’s not for the corp wide but only for the domain that ipa is using. Sent from my Commodore 64 > 4. nov. 2021 kl. 14:37 skrev Alexander Bokovoy : > > On to, 04 marras 2021, Per Qvindesland wrote: >> Great many thanks, that worked really well.

[Freeipa-users] Re: RA Agent certificate authorisation fails – how to debug?

2021-11-04 Thread Rob Crittenden via FreeIPA-users
Tomasz Torcz via FreeIPA-users wrote: > On Mon, Oct 25, 2021 at 10:09:56AM -0500, Endi Dewata via FreeIPA-users wrote: >> On Mon, Oct 25, 2021 at 7:42 AM Rob Crittenden via FreeIPA-users < >> freeipa-users@lists.fedorahosted.org> wrote: >> >>> Tomasz Torcz via FreeIPA-users wrote: > ACME also h

[Freeipa-users] cannot find name for group ID x when logging in

2021-11-04 Thread Mark Johnson via FreeIPA-users
Got my authentication working and I populated my directory with users and groups and assigned group memberships accordingly. I wasn't getting this issue originally, but now I'm suddenly getting the "cannot find name for group ID 1" when I log in to my test server. The group with GID 1

[Freeipa-users] Re: RA Agent certificate authorisation fails – how to debug?

2021-11-04 Thread Endi Dewata via FreeIPA-users
On Thu, Nov 4, 2021 at 12:32 PM Rob Crittenden via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Tomasz Torcz via FreeIPA-users wrote: > > On Mon, Oct 25, 2021 at 10:09:56AM -0500, Endi Dewata via FreeIPA-users > wrote: > >> On Mon, Oct 25, 2021 at 7:42 AM Rob Crittenden via FreeI

[Freeipa-users] Re: cannot find name for group ID x when logging in

2021-11-04 Thread Sumit Bose via FreeIPA-users
Am Thu, Nov 04, 2021 at 11:07:25PM - schrieb Mark Johnson via FreeIPA-users: > Got my authentication working and I populated my directory with users > and groups and assigned group memberships accordingly. I wasn't > getting this issue originally, but now I'm suddenly getting the > "cannot fin