[Freeipa-users] Re: performance tuning IPA 4.5 and SSD for large AD integration

2018-07-31 Thread Alexandre Pitre via FreeIPA-users
Hi Jakub, I understand that cache_first=true is set in the [nss] section of /etc/sssd/sssd.conf but what about the negative cache setting you are referring to ? Could you please give an example ? Looking at https://jhrozek.fedorapeople.org/sssd/1.16.2/man/sssd.conf.5.html , there's a few settings

[Freeipa-users] Re: Trusted AD users can no longer authenticate via SSH

2018-02-14 Thread Alexandre Pitre via FreeIPA-users
Thanks Alexander that was it. On Wed, Feb 14, 2018 at 6:06 AM, Alexander Bokovoy wrote: > On ke, 14 helmi 2018, Alexandre Pitre via FreeIPA-users wrote: > >> Earlier this week, users reported they could no longer ssh to freeipa >> joined servers using their AD login. After s

[Freeipa-users] Trusted AD users can no longer authenticate via SSH

2018-02-14 Thread Alexandre Pitre via FreeIPA-users
Earlier this week, users reported they could no longer ssh to freeipa joined servers using their AD login. After some inverstigation, it was discovered if krb5_validate was set to false in the sssd.conf, AD ssh login would start working again. One of our IPA server is showing these errors in /var/

[Freeipa-users] Re: Login failed due to unknow reason on the WebUI on new FreeIPA 4.5 installation

2018-01-18 Thread Alexandre Pitre via FreeIPA-users
Crittenden wrote: > Alexandre Pitre via FreeIPA-users wrote: > > Hi, > > > > I recently deployed a new FreeIPA domain running on CentOS 7.4 and > > FreeIPA 4.5 > > > > The installation went without hiccups but the WebUI isn't working as > > expe

[Freeipa-users] Re: Login failed due to unknow reason on the WebUI on new FreeIPA 4.5 installation

2018-01-17 Thread Alexandre Pitre via FreeIPA-users
SELinux is disabled in our CentOS template. Good hypothesis tho. On Jan 18, 2018 01:36, "Tony Brian Albers via FreeIPA-users" < freeipa-users@lists.fedorahosted.org> wrote: > On 01/18/2018 02:24 AM, Alexandre Pitre via FreeIPA-users wrote: > > Hi, > > > > I r

[Freeipa-users] Login failed due to unknow reason on the WebUI on new FreeIPA 4.5 installation

2018-01-17 Thread Alexandre Pitre via FreeIPA-users
Hi, I recently deployed a new FreeIPA domain running on CentOS 7.4 and FreeIPA 4.5 The installation went without hiccups but the WebUI isn't working as expected. Logging in with admin failed with this error: Login failed due to an unknow reason. I've seen this issue with every FreeIPA 4.5 repli

[Freeipa-users] Re: User login is slow to get password prompt

2017-12-19 Thread Alexandre Pitre via FreeIPA-users
e Is this a good practice ? Thanks, Alex On Tue, Dec 19, 2017 at 5:13 AM, Jakub Hrozek via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > On Mon, Dec 18, 2017 at 06:59:25PM -0500, Alexandre Pitre via > FreeIPA-users wrote: > > Hi, > > > > While troubles

[Freeipa-users] User login is slow to get password prompt

2017-12-18 Thread Alexandre Pitre via FreeIPA-users
Hi, While troubleshooting "slow login" with ipa users we discovered that adding these two lines to our clients sssd.conf file fixed our issue for ipa users. ldap_search_base = cn=accounts,dc=ipa,dc=domain,dc=com ldap_user_search_base = cn=users,cn=accounts,dc=ipa,dc=domain,dc=com On the freeipa

[Freeipa-users] Re: Directory service stop and won't stay up when restarted

2017-11-29 Thread Alexandre Pitre via FreeIPA-users
anges the data generation and other replicas have > to be reinitialized for replication to work again > > Ludwig > > On 11/28/2017 04:37 AM, Alexandre Pitre via FreeIPA-users wrote: > > I managed to remove the replication conflicts but the orignal issue > persist. I found a

[Freeipa-users] Re: Directory service stop and won't stay up when restarted

2017-11-26 Thread Alexandre Pitre via FreeIPA-users
t Bose via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > On Fri, Nov 24, 2017 at 07:04:10PM -0500, Alexandre Pitre via > FreeIPA-users wrote: > > Hi, > > > > I had two freeipa replica servers up and running in our german DC for > > nearly 2 months and this morning

[Freeipa-users] Directory service stop and won't stay up when restarted

2017-11-24 Thread Alexandre Pitre via FreeIPA-users
Hi, I had two freeipa replica servers up and running in our german DC for nearly 2 months and this morning out of the blue they stopped working. Looking at ipactl status, both servers are reporting that their directory service is stopped. Trying to restart ipa only works from 2 minutes to an hour

[Freeipa-users] Re: ipa sudorule-add-user SUDORULE-NAME doesn't support multiple groups

2017-10-24 Thread Alexandre Pitre via FreeIPA-users
Would you look at that! Problem solved.Thanks. On Tue, Oct 24, 2017 at 12:08 PM, Rob Crittenden wrote: > Alexandre Pitre via FreeIPA-users wrote: > > Hi, > > > > I noticed that on FreeIPA 4.5.0 on CentOS I can't specify multiple > > groups with the sudorule-a

[Freeipa-users] ipa sudorule-add-user SUDORULE-NAME doesn't support multiple groups

2017-10-24 Thread Alexandre Pitre via FreeIPA-users
Hi, I noticed that on FreeIPA 4.5.0 on CentOS I can't specify multiple groups with the sudorule-add-user command. Example: ipa sudorule-add-user sudorule --groups=group1,group2 Failed users/groups: member user: member group: group1,group2 - Number of members add

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-15 Thread Alexandre Pitre via FreeIPA-users
could specify my AD.COM realm in /etc/krb5.conf with my local site AD DC ? Big thanks to you and Jakub, my employer and I are very glad that this issue is finally resolved =) On Tue, Aug 15, 2017 at 3:45 AM, Alexander Bokovoy wrote: > On ma, 14 elo 2017, Alexandre Pitre via FreeIPA-users wrote:

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-14 Thread Alexandre Pitre via FreeIPA-users
Although, the explanation from Alexander Bokovoy made perfect sense, I'm still facing the issue after I re-established the AD trust successfully: (Tue Aug 15 02:23:40 2017) [sssd[be[domain.ad.com]]] [sdap_cli_auth_step] (0x1000): the connection will expire at 1502764720 (Tue Aug 15 02:23:40 2017)

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-09 Thread Alexandre Pitre via FreeIPA-users
t; On 7 Aug 2017, at 20:02, Alexandre Pitre via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > > The client is in the IPA domain. Although it's sub-domain of ad.com, I > did delegate it and configure the IPA servers as name servers. It uses a > differ

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-07 Thread Alexandre Pitre via FreeIPA-users
ode may provide more information (Server krbtgt/ad@ipa.ad.com not > found in Kerberos database)] > > Is your client hostname in the AD domain (centos.domain.ad.com) or in the > IPA domain (ipa.ad.com) ? > > Thanks, > Alex > > > > > > > > > On

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-07 Thread Alexandre Pitre via FreeIPA-users
ooks healthy.AD trust agent/controller server role are installed on both. ipa trustdomain-find ad.com does return all of my AD domains on both IPA servers. Thanks, Alex On Sun, Aug 6, 2017 at 11:07 AM, Jakub Hrozek wrote: > > On 4 Aug 2017, at 23:08, Alexandre Pitre via FreeIPA-us

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-08-04 Thread Alexandre Pitre via FreeIPA-users
Turns out, I'm still getting the same problem. It works right away after I force clean the sssd cache: systemctl stop sssd ; rm -f /var/lib/sss/db/* /var/log/sssd/* ; systemctl start sssd After some time, trying to log back on the same system I see the login prompt is much quicker when I type adu.

[Freeipa-users] Unable to re-join CentOS client to FreeIPA

2017-08-03 Thread Alexandre Pitre via FreeIPA-users
I'm unable to rejoin a CentOS client to my FreeIPA realm. I ran the uninstall command on my client: ipa-client-install --uninstall As far as I know the uninstall was successful. It asked me to reboot. After rebooting if I try to rerun the install command: ipa-client-install -U -p admin -w P@ssw0r

[Freeipa-users] Re: Can’t SSH with AD user to freeipa joined Centos client

2017-07-31 Thread Alexandre Pitre via FreeIPA-users
believe that's all I need. Thanks, Alex On Jul 27, 2017 04:08, "Jakub Hrozek via FreeIPA-users" < freeipa-users@lists.fedorahosted.org> wrote: > On Thu, Jul 27, 2017 at 02:34:06AM -0400, Alexandre Pitre via > FreeIPA-users wrote: > > I uploaded krb5_child.log and ld

[Freeipa-users] Can’t SSH with AD user to freeipa joined Centos client

2017-07-26 Thread Alexandre Pitre via FreeIPA-users
I’ve been struggling to get SSH to work with an AD user for over 3 weeks now. I've scraped the bowels of the internet for answers, still no dice. The issue is pretty simple in itself, I can’t SSH to a freeipa joined Centos client 7.3 with an AD user. However, kinit with any AD users as well as su