[Freeipa-users] Re: Trusting an AD synchronized towards Azure AD

2021-01-15 Thread Antoine Gatineau via FreeIPA-users
Thanks for the quick and clear response ⁣Télécharger BlueMail pour Android ​ Le 15 janv. 2021 à 19:43, à 19:43, "Vinícius Ferrão via FreeIPA-users" a écrit: >If I understood correct you have a local Windows Server with AD role up >and running and also have Azure AD Sync installed to sync data f

[Freeipa-users] Replication broken

2021-03-08 Thread Antoine Gatineau via FreeIPA-users
Hello, I'm on freeipa 4.9.0 on CentOS Stream. (1 master and 1 replica) I have noticed that my replication is broken. Unfortunatly, I don't know since when... First Question, can it b fixed? Second question, is it possible to peform a restore (on one node, both nodes) to fix the issue. I recentl

[Freeipa-users] Re: Replication broken

2021-03-09 Thread Antoine Gatineau via FreeIPA-users
I could rebuild my cluster from backup before the upgrade to CentOS Stream. So I'll be able to work from there. On Mon, 2021-03-08 at 17:41 +0100, Antoine Gatineau via FreeIPA-users wrote: > Hello, > > I'm on freeipa 4.9.0 on CentOS Stream. (1 master and 1 replica) >

[Freeipa-users] Re: Replication broken

2021-03-12 Thread Antoine Gatineau via FreeIPA-users
On Wed, 2021-03-10 at 16:09 +0100, Florence Blanc-Renaud wrote: > On 3/9/21 10:59 AM, Antoine Gatineau via FreeIPA-users wrote: > > I could rebuild my cluster from backup before the upgrade to CentOS Stream. > > So I'll be able to work from there. > > > > O

[Freeipa-users] ACME under Centos Stream 8 - Bad cert profile

2021-03-21 Thread Antoine Gatineau via FreeIPA-users
Hello, So I'm trying out the new acme feature in freeipa version 4.9.0-1.module_el8.4.0+639+a88aab78 from CentOS Stream 8. My setup is a rebuild from replica (fresh install on centos stream as a replica of a centos 8 non-stream existing replica). I enabled acme using "sudo ipa-acme-manage enab

[Freeipa-users] Re: freeIPA Status Debian/Ubuntu

2021-09-06 Thread Antoine Gatineau via FreeIPA-users
On Mon, 2021-09-06 at 07:52 +0200, Nico Maas via FreeIPA-users wrote: > Dear Ian, > thanks for the infos :) > I did need to migrate to CentOS 8 Stream as it was assured in this group this > would be the best way in the future a few months ago. > Is there an easy way to go from CentOS 8 Stream to R

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-10-17 Thread Antoine Gatineau via FreeIPA-users
On Fri, 2021-09-17 at 12:35 +, pp via FreeIPA-users wrote: > Could you check if your "requiredSecret" value matches the "secret" in > "/etc/pki/pki-tomcat/server.xml"? > I had two lines where they were different and the value has to match the > secret in "/etc/httpd/conf.d/ipa-pki-proxy.conf"

[Freeipa-users] Re: klist Valid and expiry dates problem 01/01/70 10:00:00

2021-11-14 Thread Antoine Gatineau via FreeIPA-users
On Mon, 2021-11-15 at 06:59 +, Tony Delov via FreeIPA-users wrote: > I seem to have an intermittent problem. > When I ssh into it my server,( using sssd and registered to a freeipa > server). I often get dates starting at 1970! I seem to be able to login > without any issue. > I suspect thi

[Freeipa-users] Error replacing a replica with CentOS Stream 9

2021-12-11 Thread Antoine Gatineau via FreeIPA-users
Hello, I have currently a 2 node cluster running on CentOS Stream 8. In order to upgrade to CentOS 9, I have removed one of the replica from the configuration, installed a fresh centos stream 9 and run ipa-replica-install. It fails with this error (full log attached): [22/29]: Importing RA key

[Freeipa-users] Re: Error replacing a replica with CentOS Stream 9

2021-12-15 Thread Antoine Gatineau via FreeIPA-users
Hi, This message was probably missed in all the log4shell exchanges. Any hint on how to rebuild the RA certificate with a newer algorythm before migrating to Centos Stream 9? Many thanks On Sat, 2021-12-11 at 16:56 +0100, Antoine Gatineau via FreeIPA-users wrote: > > Hello, >

[Freeipa-users] Re: Error replacing a replica with CentOS Stream 9

2021-12-15 Thread Antoine Gatineau via FreeIPA-users
On Wed, 2021-12-15 at 10:49 +0200, Alexander Bokovoy via FreeIPA-users wrote: > Hi Antoine, > > On ke, 15 joulu 2021, Antoine Gatineau via FreeIPA-users wrote: > > Hi, > > > > This message was probably missed in all the log4shell exchanges. > > Any hint on how t

[Freeipa-users] Re: Error replacing a replica with CentOS Stream 9

2021-12-15 Thread Antoine Gatineau via FreeIPA-users
Stupid Question... Where should I go to file a bug on centos stream? I know for fedora or rhel, but not this one Thanks On Wed, 2021-12-15 at 09:56 +0100, Antoine Gatineau via FreeIPA-users wrote: > On Wed, 2021-12-15 at 10:49 +0200, Alexander Bokovoy via FreeIPA-users wrote: >

[Freeipa-users] Re: Error replacing a replica with CentOS Stream 9

2021-12-15 Thread Antoine Gatineau via FreeIPA-users
On Wed, 2021-12-15 at 11:22 +0200, Alexander Bokovoy via FreeIPA-users wrote: > On ke, 15 joulu 2021, Antoine Gatineau via FreeIPA-users wrote: > > Stupid Question... Where should I go to file a bug on centos stream? I know > > for fedora or rhel, but not this one > > P

[Freeipa-users] How to change ipaUniqueId

2022-08-06 Thread Antoine Gatineau via FreeIPA-users
Hello all. I am trying to migrate my users from one ipa to another one. I was able to import the users and groups with 'ipa migrate-ds'. However the migration process generates new ipaUniqueIds. IPA is my source of users for keycloak user federation and other applications that use ipaUniqueId t

[Freeipa-users] Re: How to change ipaUniqueId

2022-08-15 Thread Antoine Gatineau via FreeIPA-users
Gatineau via FreeIPA-users wrote: > > Hello all. > > > > I am trying to migrate my users from one ipa to another one. > > I was able to import the users and groups with 'ipa migrate-ds'. However > > the migration process generates new ipaUniqueIds. >

[Freeipa-users] Issue logging to desktop sessions

2022-09-14 Thread Antoine Gatineau via FreeIPA-users
Dear freeipa-users, I recently am having trouble logging into my kde sessions. Client OS: Fedora 36 Kde Plasma (up to date) (freeipa-client 4.10.0-4 , sssd 2.7.4-1) Server: Centos Stream 9 (ipa 4.10.0-6) Here are my symptoms : ipa user on KDE Wayland:kwin_wayland_wrapper crashes ipa user

[Freeipa-users] Re: Issue logging to desktop sessions

2022-09-14 Thread Antoine Gatineau via FreeIPA-users
sssd logs are in the tar.gz file kwin is there just because it was there :) On Wednesday, September 14, 2022 3:48:31 PM CEST Rob Crittenden wrote: > Antoine Gatineau via FreeIPA-users wrote: > > Dear freeipa-users, > > > > I recently am having trouble logging into my kde

[Freeipa-users] Re: Issue logging to desktop sessions

2022-09-16 Thread Antoine Gatineau via FreeIPA-users
the cache was somehow corrupted and logging from a new client renewed it and fixed it. Are there some configurations on the servers that would require to clean the cache? Anyway it seems to be ok now On Wednesday, September 14, 2022 4:17:03 PM CEST Antoine Gatineau via FreeIPA-users wrote

[Freeipa-users] Re: Issue logging to desktop sessions

2022-09-20 Thread Antoine Gatineau via FreeIPA-users
gging > > from a new client renewed it and fixed it. > > > > Are there some configurations on the servers that would require to clean > > the cache? > > > > > > Anyway it seems to be ok now > > > > > > > > On Wednesday, Se

[Freeipa-users] Re: postgres (patroni cluster) certificates for hosts and client

2022-10-02 Thread Antoine Gatineau via FreeIPA-users
Hi, I've played a bit with patroni and my understanding is that you would have each node being a dedicated endpoint/client. That would translate by a HTTP/service per node. As far as I have seen, the host certificate has the client specs. The http cert would not be usable as a client certifica

[Freeipa-users] ACME certs fail to renew

2024-03-28 Thread Antoine Gatineau via FreeIPA-users
Hello, I have a strange issue regarding acme service. My acme certificates fail to renew. `ipa-acme-manage status`fails with error: Failed to authenticate to CA REST API The ipa-acme-manage command failed. certbot client fails with error "Failed to renew certificate office.empire.lan with err

[Freeipa-users] Re: Client install fails with: "Joining realm failed: JSON-RPC call failed: Timeout was reached"

2024-03-31 Thread Antoine Gatineau via FreeIPA-users
iirc port 80 and 443 are needed. 123 is for ntp so if you don't sync time from the ipa servers you woudl not need that port. https://access.redhat.com/solutions/357673 On 3/29/24 13:13, slek kus via FreeIPA-users wrote: Hi, not sure what might be an issue. Clients in the same network join just

[Freeipa-users] Re: ACME certs fail to renew

2024-04-02 Thread Antoine Gatineau via FreeIPA-users
me was available and working on the new replica which rules out the ldap content I guess. I then reinstalled my replicas and everything is working properly now. So fixed, but I still don't know what happened :/ Best regards On 4/1/24 16:46, Rob Crittenden via FreeIPA-users wrote: Antoine G

[Freeipa-users] unable to convert attribute 'cacertificate:binary'

2024-04-30 Thread Antoine Gatineau via FreeIPA-users
Hello, When enrolling a opensuse tumbleweed client, ipa-client-install fails to get the cacertificate from ldap with error: 2024-04-30T11:23:16Z DEBUG Initializing principal adminprincipal using password 2024-04-30T11:23:16Z DEBUG Starting external process 2024-04-30T11:23:16Z DEBUG args=['/

[Freeipa-users] Re: unable to convert attribute 'cacertificate:binary'

2024-04-30 Thread Antoine Gatineau via FreeIPA-users
On 4/30/24 15:50, Alexander Bokovoy wrote: On Аўт, 30 кра 2024, Antoine Gatineau via FreeIPA-users wrote: Hello, When enrolling a opensuse tumbleweed client, ipa-client-install fails to get the cacertificate from ldap with error: 2024-04-30T11:23:16Z DEBUG Initializing principal

[Freeipa-users] Re: unable to convert attribute 'cacertificate:binary'

2024-04-30 Thread Antoine Gatineau via FreeIPA-users
On 4/30/24 15:34, Rob Crittenden wrote: Antoine Gatineau via FreeIPA-users wrote: Hello, When enrolling a opensuse tumbleweed client, ipa-client-install fails to get the cacertificate from ldap with error: 2024-04-30T11:23:16Z DEBUG Initializing principal adminprincipal using password 2024

[Freeipa-users] Re: unable to convert attribute 'cacertificate:binary'

2024-05-03 Thread Antoine Gatineau via FreeIPA-users
On 5/2/24 14:35, Alexander Bokovoy via FreeIPA-users wrote: On Аўт, 30 кра 2024, Antoine Gatineau via FreeIPA-users wrote: On 4/30/24 15:34, Rob Crittenden wrote: Antoine Gatineau via FreeIPA-users wrote: Hello, When enrolling a opensuse tumbleweed client, ipa-client-install fails to get

[Freeipa-users] Re: unable to convert attribute 'cacertificate:binary'

2024-05-03 Thread Antoine Gatineau via FreeIPA-users
On 5/3/24 10:14 AM, Antoine Gatineau via FreeIPA-users wrote: On 5/2/24 14:35, Alexander Bokovoy via FreeIPA-users wrote: On Аўт, 30 кра 2024, Antoine Gatineau via FreeIPA-users wrote: On 4/30/24 15:34, Rob Crittenden wrote: Antoine Gatineau via FreeIPA-users wrote: Hello, When