[Freeipa-users] Re: Unable to create AD trust

2022-03-30 Thread Jeremy Tourville via FreeIPA-users
Yes, already did that as part of my troubleshooting. See my 1st post. I have the logs but correctly interpreting them is a different matter. I am hoping the experts can assist with that. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahos

[Freeipa-users] Re: upgrade to FreeIPA 4.7+ from 4.6

2022-03-30 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, the official Red Hat Enterprise Linux documentation recommends to install a RHEL8 replica (in place upgrade is not supported), ensure everything works properly and then decommission the RHEL7 server: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/migrating_to_ide

[Freeipa-users] Re: Unable to create AD trust

2022-03-30 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, you can follow the debugging guidelines from https://www.freeipa.org/page/Active_Directory_trust_setup#Debugging_trust. The *ipa trust-add* logs will be visible in /var/log/httpd/error_log and in the /var/log/samba directory. flo On Wed, Mar 30, 2022 at 7:17 PM Jeremy Tourville via FreeIPA-u

[Freeipa-users] Re: Unable to create AD trust

2022-03-30 Thread Jeremy Tourville via FreeIPA-users
I think I got a little further in troubleshooting this after looking at /var/log/httpd/error_log I reviewed the Operations performed from an IdM trust controller towards AD domain controllers in table 6.7 from https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/plan

[Freeipa-users] upgrade to FreeIPA 4.7+ from 4.6

2022-03-30 Thread Ivars Strazdins via FreeIPA-users
Hello, I am planning FreeIPA servers’ upgrade from Centos 7 with FreeIPA 4.6.8 to Alma Linux 8.5. Can I just take out replicas one by one and install fresh Alma Linux, then add back with latest FreeIPA on that replica? Or do I have to take some special precautions? If FreeIPA version compatibili

[Freeipa-users] Re: DNS record with all IPA servers

2022-03-30 Thread Boris Behrens via FreeIPA-users
Oh great. Thanks a lot. That solved my problem very fast. Cheers Boris Am Mi., 30. März 2022 um 10:19 Uhr schrieb Alexander Bokovoy < aboko...@redhat.com>: > On ke, 30 maalis 2022, Boris Behrens via FreeIPA-users wrote: > >Hi, > >I am currently trying to cleanup our IPA installation and saw tha

[Freeipa-users] Re: DNS record with all IPA servers

2022-03-30 Thread Alexander Bokovoy via FreeIPA-users
On ke, 30 maalis 2022, Boris Behrens via FreeIPA-users wrote: Hi, I am currently trying to cleanup our IPA installation and saw that all our clients only got a single server configured, which doesn't sound good. (we've currently got two IPA servers). Is there some sort of record that can be used

[Freeipa-users] DNS record with all IPA servers

2022-03-30 Thread Boris Behrens via FreeIPA-users
Hi, I am currently trying to cleanup our IPA installation and saw that all our clients only got a single server configured, which doesn't sound good. (we've currently got two IPA servers). Is there some sort of record that can be used? root@host1:/etc/ipa# cat /etc/ipa/default.conf #File modified

[Freeipa-users] Re: How to retrieve user's credentials from IPA database?

2022-03-30 Thread Roger Seguin via FreeIPA-users
Many thanks to Alexander Bokovoy and Sam Morris. I think that pam_authenticate(3) will do the job! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora