[Freeipa-users] Re: Freeipa sudo

2024-01-17 Thread Dmitry Krasov via FreeIPA-users
did I do everything right? in journalctl -xe seems like same logs: 11:12:03 desktop22043.dom.loc kernel: audit: type=1400 audit(1705561923.050:266): apparmor="ALLOWED" operation="open" class="file" profile="/usr/sbin/sssd" name="/proc/4471/cmdline" pid=813 comm="sssd_nss" requested_mask="r" de

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Paul Nickerson via FreeIPA-users
I confirmed that users who had an ipaNTSecurityIdentifier attribute could log in to the web UI, and those that did not have the ipaNTSecurityIdentifier attribute could not. I found the error in /var/log/dirsrv/slapd-SEMI-EXAMPLE-NET/errors like you said: [17/Jan/2024:20:28:09.571195828 +] -

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Rob Crittenden via FreeIPA-users
Paul Nickerson via FreeIPA-users wrote: > Thank you for the assistance. I tried running the oddjob without specifying a > NetBIOS name, and it gave a return code of 1, no output, and didn't seem to > do anything. Then I saw your NetBIOS comment. > > First I checked to see if we already had a Net

[Freeipa-users] Re: Is there even one freeipa dev that knows everything about upgrading across major OS releases?

2024-01-17 Thread Harry G Coin via FreeIPA-users
On 1/17/24 12:55, Rob Crittenden wrote: Harry G Coin wrote: On 1/15/24 13:26, Rob Crittenden wrote: Harry G Coin via FreeIPA-users wrote: Hi!   This is meant for the good future of freeipa, a package I've appreciated for some years, so across the user cultures and languages please understand

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Paul Nickerson via FreeIPA-users
Thank you for the assistance. I tried running the oddjob without specifying a NetBIOS name, and it gave a return code of 1, no output, and didn't seem to do anything. Then I saw your NetBIOS comment. First I checked to see if we already had a NetBIOS name configured, and I didn't find anything

[Freeipa-users] Re: Is there even one freeipa dev that knows everything about upgrading across major OS releases?

2024-01-17 Thread Rob Crittenden via FreeIPA-users
Harry G Coin wrote: > > On 1/15/24 13:26, Rob Crittenden wrote: >> Harry G Coin via FreeIPA-users wrote: >>> Hi!   This is meant for the good future of freeipa, a package I've >>> appreciated for some years, so across the user cultures and languages >>> please understand it as supportive and not a

[Freeipa-users] DNS resolution failures

2024-01-17 Thread Tania Hagan via FreeIPA-users
Hi Freeipa-users, We are currently running Freeipa version 4.9.11 on Rocky 8.8. We have noticed over the last few months that external name resolution e.g. google.com fails to resolve on multiple Freeipa replicas even though the service named-pkcs11 remains up and running and journalctl or lo

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 17 сту 2024, Alexander Bokovoy via FreeIPA-users wrote: On Срд, 17 сту 2024, Paul Nickerson via FreeIPA-users wrote: I have two FreeIPA servers in a cluster, both running on RHEL 8.9. They started on RHEL 8.0 I believe, and have been upgrading in-place since then. I recently restarted th

[Freeipa-users] Re: Number of concurrent connections are decreased by replication.

2024-01-17 Thread Jaehwan Kim via FreeIPA-users
Hello Rob, I successfully installed a single FreeIPA server with fedora-39-4.11.0 docker(container) and tested performance with high host_add rate (14 host_add per min) by about 1K clients. Test procedure is like... First, I added 500 hosts successfully and waited for about 10 mins. Then, I tri