[Freeipa-users] Re: Managing FreeIPA installations without Trusts between them

2023-09-18 Thread Alexander Bokovoy via FreeIPA-users
On Суб, 16 вер 2023, dweller dweller via FreeIPA-users wrote: We have a requirement to segregate different types of users, including customers, administrators, clients, and infrastructure hosts, into separate realms or unique IPA installations. While this is potentially feasible through the Trust

[Freeipa-users] Re: Another Cert Expiration Problem

2023-09-18 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Fri, Sep 15, 2023 at 7:43 PM Russ Long via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > I have a single-server IPA environment in my homelab. I noticed today > that I was unable to delete a host from IPA, and found that pki-tomcatd was > down and unable to start. > > I f

[Freeipa-users] Re: Another Cert Expiration Problem

2023-09-18 Thread Russell Long via FreeIPA-users
Re-sending this as I forgot to send to the list itself, sorry. On Mon, Sep 18, 2023 at 6:55 AM Florence Blanc-Renaud wrote: > Hi, > > On Fri, Sep 15, 2023 at 7:43 PM Russ Long via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > >> I have a single-server IPA environment in my hom

[Freeipa-users] Kerberos logs / TGS

2023-09-18 Thread Ole Froslie via FreeIPA-users
Hi, I am working on getting the logging for FreeIPA set-up properly. I have a test server (testy) running. This server/host is under control of FreeIPA. I have a user group defined for test users, and a host group for test servers. There is a HBAC rule to ensure that the members of testing group ha

[Freeipa-users] Re: Kerberos logs / TGS

2023-09-18 Thread Sam Morris via FreeIPA-users
On 18/09/2023 14:19, Ole Froslie via FreeIPA-users wrote: Scenario 2: User : test2 is not a member of testusergroup anymore and should not be granted access to the test server. This also works as expected, when logging in with correct password, test2 is denied service with message "Connection c

[Freeipa-users] Re: Kerberos logs / TGS

2023-09-18 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 18 вер 2023, Ole Froslie via FreeIPA-users wrote: Hi, I am working on getting the logging for FreeIPA set-up properly. I have a test server (testy) running. This server/host is under control of FreeIPA. I have a user group defined for test users, and a host group for test servers. There i

[Freeipa-users] Re: Kerberos logs / TGS

2023-09-18 Thread Ole Froslie via FreeIPA-users
Hi and thank you for good clarification of my misunderstanding. I will rely on logging on the clients to see the complete picture. Regards, Ole Frøslie Com4 ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an emai

[Freeipa-users] Disable all sssd caching

2023-09-18 Thread Ranbir via FreeIPA-users
Hello Everyone, Is there a flag to disable all caching in sssd? I know we shouldn't disable the various caches. However, I'm working on isolating a problem we're seeing between our firewall and AD. The firewall has a plugin that monitors AD for session information. When a login occurs, the firewa

[Freeipa-users] RedHat and 2FA Problem

2023-09-18 Thread Sirio Sannipoli via FreeIPA-users
Hello everyone, I've already done searches without success, I need someone to point me in the direction of resolving a strange behavior I'm experiencing on servers with the RedHat/Centos operating system. I have installed FreeIPA 4.10.1 on Oracle Linux 9 and all users by default have Radius auth

[Freeipa-users] IdM/IPA id: no such user

2023-09-18 Thread Jeremy Tourville via FreeIPA-users
I have cross posted a message as I am not sure where the post should go for best support. We are having issues with several IPA client machines. See post - https://lists.fedorahosted.org/archives/list/sssd-us...@lists.fedorahosted.org/thread/UF7MB6TVANYX3HEOHAOLZKXIN44MWNZD/ Thanks!

[Freeipa-users] Migration of FreeIPA from one virtualization environment to another.

2023-09-18 Thread Srikanth Reddy via FreeIPA-users
Currently our FreeIPA is running as a container on a virtual machine in VmWare environment. Now we are changing the virtualization environment from VmWare to Cloudstack, As part of this we need to migrate our FreeIPA from VmWare to Cloudstack environment. I need the best approach to do this Free

[Freeipa-users] Re: Disable all sssd caching

2023-09-18 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 18, 2023 at 11:34:28AM -0400 schrieb Ranbir via FreeIPA-users: > Hello Everyone, > > Is there a flag to disable all caching in sssd? I know we shouldn't > disable the various caches. However, I'm working on isolating a problem > we're seeing between our firewall and AD. Hi, no, cachi

[Freeipa-users] Re: RedHat and 2FA Problem

2023-09-18 Thread Sumit Bose via FreeIPA-users
Am Mon, Sep 18, 2023 at 03:55:32PM - schrieb Sirio Sannipoli via FreeIPA-users: > Hello everyone, > I've already done searches without success, I need someone to point me > in the direction of resolving a strange behavior I'm experiencing on > servers with the RedHat/Centos operating system. >