[Freeipa-users] Install freeipa client on fedora12

2024-07-01 Thread Elhamsadat Azarian via FreeIPA-users
Hi we have a network contains some Fedora12 and Oracle linux 9 i am going to install FreeIPA server on oracle linux9 and others(Fedora12 and oraclelinux9) connect it as clients. i couldn't find a package for fedora12 as freeipa client! can you guide me is it possible that having FreeIPA in this ne

[Freeipa-users] freeipa client for Fedora 12

2024-07-01 Thread Elhamsadat Azarian via FreeIPA-users
Hi we have a network contains some Fedora12 and Oracle linux 9 i am going to install FreeIPA server on oracle linux9 and others(Fedora12 and oraclelinux9) connect it as clients. i couldn't find a package for fedora12 as freeipa client! can you guide me is it possible that having FreeIPA in this ne

[Freeipa-users] Re: Disable user password expiration immediately after password reset.

2024-07-01 Thread luckydog xf via FreeIPA-users
Thanks. On Tue, Jul 2, 2024 at 9:12 AM Russell Long wrote: > I didn't believe it's possible to change easily, but how I get around it > for service accounts and the like is to change it from the admin side, then > login as the service account using the password set from the admin side. > Then I

[Freeipa-users] Re: Disable user password expiration immediately after password reset.

2024-07-01 Thread Russell Long via FreeIPA-users
I didn't believe it's possible to change easily, but how I get around it for service accounts and the like is to change it from the admin side, then login as the service account using the password set from the admin side. Then I change the password as the user, which will then obey whatever passwor

[Freeipa-users] Disable user password expiration immediately after password reset.

2024-07-01 Thread luckydog xf via FreeIPA-users
Once the admin changes the user password, it will expire immediately. Can we disable this policy? -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedor

[Freeipa-users] Disable user password expiration immediately after password reset.

2024-07-01 Thread luckydog xf via FreeIPA-users
Once the admin changes the user password, it will expire immediately. Can we disable this policy? -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedor

[Freeipa-users] Re: Unable to log into FreeIPA UI or use ipa commands after certificate expiration and replacement

2024-07-01 Thread Rob Crittenden via FreeIPA-users
Toma Morris via FreeIPA-users wrote: > ## Problem and version info > > I recently took over as the sysadmin for a system that was previously set up, > and has not had a sysadmin for 6+ months, plus appears to have been fairly > neglected even before then. It has three FreeIPA nodes that have not

[Freeipa-users] Unable to access FreeIPA UI after certificate expiration and renewal

2024-07-01 Thread Toma Morris via FreeIPA-users
## Problem and version info I recently took over as the sysadmin for a system that was previously set up, and has not had a sysadmin for 6+ months, plus appears to have been fairly neglected even before then. It has three FreeIPA nodes that have not seen a system update in several years, and CentO

[Freeipa-users] Unable to log into FreeIPA UI or use ipa commands after certificate expiration and replacement

2024-07-01 Thread Toma Morris via FreeIPA-users
## Problem and version info I recently took over as the sysadmin for a system that was previously set up, and has not had a sysadmin for 6+ months, plus appears to have been fairly neglected even before then. It has three FreeIPA nodes that have not seen a system update in several years, and Ce

[Freeipa-users] Best way to upgrade FreeIpa version and OS

2024-07-01 Thread Youssef CHTOUROU via FreeIPA-users
Hello I've 3 FreeIpa Servers (version =4.6.8) runned on Centos 7. I'am looking for upgrade these servers like that : Centos 7 to Rocky 8 FreeIpa server to most recent version possible I would like to see your advice : what is the best / secure way to do this upgrade ? Thanks a lot -- _

[Freeipa-users] Best way to upgrade FreeIpa version and OS

2024-07-01 Thread Youssef CHTOUROU via FreeIPA-users
Hello I've 3 FreeIpa Servers (version =4.6.8) runned on Centos 7. I'am looking for upgrade these servers like that : Centos 7 to Rocky 8 FreeIpa server to most recent version possible I would like to see your advice : what is the best / secure way to do this upgrade ? Thanks a lot -- _

[Freeipa-users] Unable to access LDAP server

2024-07-01 Thread Meikel Bloch via FreeIPA-users
Hey everyone, just tried to install freeipa on a hetzner cloud server cause i'm actually looking for alternative to UCS. I still dont get it, why FreeIPA is in need to be reachable on a public net, but thats not the point here. I have a clean, fresh Fedora 40 with running network, hostname resolv

[Freeipa-users] Re: Kerberos / Samba authentication issue after updating to 4.9.13-10

2024-07-01 Thread Julien Rische via FreeIPA-users
Hello Florian, Yes, this is a known issue. We made a mistake while backporting the upstream FreeIPA fix for CVE-2024-3183[1] to CentOS 8 Stream. It was fixed in a later merge request[2]. Upgrading to ipa-4.9.13-11 should fix this issue. If it is not available in your distribution, please ask the

[Freeipa-users] Kerberos / Samba authentication issue after updating to 4.9.13-10

2024-07-01 Thread Florian Spicher via FreeIPA-users
Hello, We experience some problems with Kerberos / Samba authentication after updating our two FreeIPA servers. The issue appeared after updating the following packages: ipa-server-trust-ad-4.9.13-10.module_el8.10.0+3857+9c8da539.x86_64 ipa-server-dns-4.9.13-10.module_el8.10.0+3857+9c8da539.noar

[Freeipa-users] Disable user password expiration immediately after password reset.

2024-07-01 Thread luckydog xf via FreeIPA-users
Once the admin changes the user password, it will expire immediately. Can we disable this policy? -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedor

[Freeipa-users] Re: replica in DMZ with trust-agent

2024-07-01 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Fri, Jun 28, 2024 at 4:58 PM slek kus via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > After some more searching, I see that the client contacts the AD domain > controller, asking for AAA record, then connects to the AD forest > controller, which is _not_ reachable due to