[Freeipa-users] Re: IPA Client / access from another domain and realm possible ?

2022-11-09 Thread Karim Bourenane via FreeIPA-users
est way to do ? > > I need to configure the sssd.conf with other domain's ? > Merge the krb5 keytab file for the kerberos management ticket ? > > Thank you for your help. > Bien à vous > Mr Karim Bourenane > > > > > > Le mar. 8 nov. 2022 à 22:29, Rob Critten

[Freeipa-users] Re: IPA Client / access from another domain and realm possible ?

2022-11-09 Thread Karim Bourenane via FreeIPA-users
ticket ? Thank you for your help. Bien à vous Mr Karim Bourenane Le mar. 8 nov. 2022 à 22:29, Rob Crittenden a écrit : > Karim Bourenane via FreeIPA-users wrote: > > Hello Team > > > > Im on CentOS 7.9, with IPA server under 4.6.8. > > My IPA server manages a domain

[Freeipa-users] IPA Client / access from another domain and realm possible ?

2022-11-07 Thread Karim Bourenane via FreeIPA-users
Hello Team Im on CentOS 7.9, with IPA server under 4.6.8. My IPA server manages a domain/realm AAA.com. I would like it to be accessible also via ssh from another domain/realm BBB.com and also to use Kerberos token from BBB.com to use sudo management. It possible ? How should I proceed? If you

[Freeipa-users] Re: Certificat REVOKED_EXPIRED / How to suppress ?

2022-02-23 Thread Karim Bourenane via FreeIPA-users
We have v4.6.8 API: 2.237 platform Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54 Le mer. 23 févr. 2022 à 16:05, Karim Bourenane a écrit : > Hello Team > > How to delete expired certificats from IPA PKI and Dogtag definitively. > We haven't found any help to do that. > > Can

[Freeipa-users] Certificat REVOKED_EXPIRED / How to suppress ?

2022-02-23 Thread Karim Bourenane via FreeIPA-users
Hello Team How to delete expired certificats from IPA PKI and Dogtag definitively. We haven't found any help to do that. Can you help ? Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54 ___ FreeIPA-users mailing list --

[Freeipa-users] Password avability before change

2021-06-28 Thread Karim Bourenane via FreeIPA-users
Hello Team I have a small question, about a new password reseted. I have into policy password: Min availability 1 days and max 90 days That means, if I reset a password, the temporary is available 24h ? Can you confirm? FreeIPA : 4.6.5 Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63

[Freeipa-users] Access LOG Files / configuration - zip ?

2021-01-01 Thread Karim Bourenane via FreeIPA-users
Hello Team Its possible to know where the access log files in /var/log/dirsrv/slapd./ are configured. Its possible to active the gzip process for this files ? Happy holidays Bien à vous Mr Karim Bourenane ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Partial replication of LDAP branch

2020-12-16 Thread Karim Bourenane via FreeIPA-users
not the case today. > > François > > On Tue, Dec 15, 2020 at 6:07 PM Karim Bourenane via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > >> Hello Team >> >> I have a special question, about a partial replication branch domain LDAP >> into a F

[Freeipa-users] Partial replication of LDAP branch

2020-12-15 Thread Karim Bourenane via FreeIPA-users
Hello Team I have a special question, about a partial replication branch domain LDAP into a FreeIPA v. 4.6.2 on Centos 7.7.1908. I want to deploy several FreeIPA into several network zones. Its possible to only replicate a branch of data, to manage only an ipa client / dns / certificat to this

[Freeipa-users] Re: Add User attributes into the shemas & UI

2020-08-25 Thread Karim Bourenane via FreeIPA-users
Hello Rob, Team Thank you for your answer. I found a pdf link (old version of IPA ): https://www.freeipa.org/images/5/5b/FreeIPA33-extending-freeipa.pdf Can you confirm the steps ? Regard Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54

[Freeipa-users] Re: Add User attributes into the shemas & UI

2020-08-24 Thread Karim Bourenane via FreeIPA-users
Hello Team I have already added attributes in the User ObjectClass. But unable to see it in the FreeIPA UI. Can you help me, to know what I must do, to add section attributes/ into FreeIPA UI ? Regard Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54

[Freeipa-users] Add User attributes into the shemas & UI

2020-08-20 Thread Karim Bourenane via FreeIPA-users
Hello Team I want to know how easily I can add new attributes/objectclass into my FreeIpa platform, version 4.6.4. I see that I must create a new schema in ldif format beginning by cn=config Thanks you for your help Bien à vous / Regard Mr Karim Bourenane +33686464439 +32 493 86 63 54

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-18 Thread Karim Bourenane via FreeIPA-users
39 > > +32 493 86 63 54 > > > > > > Le jeu. 11 juin 2020 à 10:02, Florence Blanc-Renaud > <mailto:f...@redhat.com>> a écrit : > > > > On 6/9/20 10:04 AM, Karim Bourenane via FreeIPA-users wrote: > > > Hello Florence, all > >

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-09 Thread Karim Bourenane via FreeIPA-users
arim Le lun. 8 juin 2020 à 08:58, Florence Blanc-Renaud a écrit : > On 6/6/20 11:42 AM, Karim Bourenane via FreeIPA-users wrote: > > Hello Team > > > > I have some questions : > > 1°) I need your help, to find the better way to upgrade my 3 servers > > linked (re

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
n a écrit : > Karim Bourenane via FreeIPA-users wrote: > > Hello François, All > > > > Thanks you for your answer / update > > > > Here's what I did: > > All process RUNNING with : ipactl status > > yum update > > > > *I have several erro

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
;/usr/lib/python2.7/site-packages/ipalib/base.py", line 134, in >>> __setattr__ >>> SET_ERROR % (self.__class__.__name__, name, value) >>> >>> 2020-06-08T09:39:42Z DEBUG The ipa-server-upgrade command failed, >>> exception: AttributeError: locked: cannot

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
> for details: > AttributeError: locked: cannot set ra_certprofile.override_port to 8443 > 2020-06-08T09:39:42Z ERROR The ipa-server-upgrade command failed. See > /var/log/ipaupgrade.log for more information > > > Regards > > > Bien à vous > Mr Karim Bourenane > +33686

[Freeipa-users] Re: Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-08 Thread Karim Bourenane via FreeIPA-users
g/ipaupgrade.log for more information Regards Bien à vous Mr Karim Bourenane +33686464439 +32 493 86 63 54 Le lun. 8 juin 2020 à 08:56, François Cami a écrit : > Hi, > > On Sun, Jun 7, 2020 at 11:13 PM Karim Bourenane via FreeIPA-users > wrote: > > > > Hello Team > >

[Freeipa-users] Better way to upgrade IPAServer4.6.4 to 4.6.5 + OS 7.6 to 7.7?

2020-06-07 Thread Karim Bourenane via FreeIPA-users
Hello Team I have some questions : 1°) I need your help, to find the better way to upgrade my 3 servers linked (replicat). I want to upgrade servers from CentOS 7.6 to CentOS7.7 with update in same time the IPAServer (or separately ?) After searching on Freeipa.org and other site, i find :

[Freeipa-users] Re: Enroll & Install IPA Client on Redhat 5.4 with IPA Server on 4.6.4

2019-08-08 Thread Karim Bourenane via FreeIPA-users
Hello Rob, All Can you help me to find it on Internet repo, because i havent find it or direct download please. Regards Bien à vous Mr Karim Bourenane +33686464439 +32493866354 Le lun. 29 juil. 2019 à 17:26, Rob Crittenden a écrit : > Karim Bourenane via FreeIPA-users wrote: > &

[Freeipa-users] Re: [IPA4.6.4 with VCSA6.7] LDAP Authentification

2019-08-06 Thread Karim Bourenane via FreeIPA-users
Thank you Alexander, The case has been opened to the vendor. I come back if he have correct solution. Regard Bien à vous Mr Karim Bourenane +33686464439 +32493866354 Le mar. 6 août 2019 à 15:10, Alexander Bokovoy a écrit : > On ti, 06 elo 2019, Karim Bourenane via FreeIPA-users wr

[Freeipa-users] Re: [IPA4.6.4 with VCSA6.7] LDAP Authentification

2019-08-06 Thread Karim Bourenane via FreeIPA-users
have already the ObjectClass : groupOfUniqueNames vSphere don't want to authenticate the user. Do you have any idea, please ? Bien à vous Mr Karim Bourenane Le lun. 5 août 2019 à 16:59, Rob Crittenden a écrit : > Karim Bourenane via FreeIPA-users wrote: > > Hello All, > > > &

[Freeipa-users] Re: [IPA4.6.4 with VCSA6.7] LDAP Authentification

2019-08-05 Thread Karim Bourenane via FreeIPA-users
Thanks you Rob for your quick reply I will study the answer. Bien à vous Mr Karim Bourenane +33686464439 +32493866354 Le lun. 5 août 2019 à 16:59, Rob Crittenden a écrit : > Karim Bourenane via FreeIPA-users wrote: > > Hello All, > > > > Do someone know i must co

[Freeipa-users] [IPA4.6.4 with VCSA6.7] LDAP Authentification

2019-08-05 Thread Karim Bourenane via FreeIPA-users
Hello All, Do someone know i must configure my IPA server + the VCenter VSCA to authenticate in LDAP ? I found several demo, but nothing run. Thanks you in advance. Regard Mr Karim Bourenane ___ FreeIPA-users mailing list --

[Freeipa-users] Enroll & Install IPA Client on Redhat 5.4 with IPA Server on 4.6.4

2019-07-29 Thread Karim Bourenane via FreeIPA-users
Hello Team Can you tell me, if i can enroll a old Redhat 5.4 Tikanga i386 (kernel v:2.6.18-164) to IPA Server 4.6.4 ? I yes, can you please give the steps or link to do please ? Thanks you Mr Karim Bourenane ___ FreeIPA-users mailing list --

[Freeipa-users] Replication-install Tomcat error stage 1:/28 / Need help

2019-06-28 Thread Karim Bourenane via FreeIPA-users
Hello All I have follow the step from stepes from Freeipa web + Redhat to prepare the replicat by commands : DNS+Reverse : OK On IPA Master : ipa-replica-prepare --password=X replicat.example.com Scp the Gpg file from the Master to slave/replicat as root to /var/lib/ipa On IPA Replicat :

[Freeipa-users] Better to Backup / Restore to new server ?

2019-06-20 Thread Karim Bourenane via FreeIPA-users
Hello I need your recommandation about the upgrade/restore from FreeIPA server actually in V 4.5.0 APIV 2.228 to V4.6.4 API 2.230 or last. Is better to Backup / Restore from the old to New IPA server, or to start ipa-server-upgrade from the old server ? As you know my old IPA version use the

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
. > > I thought about roundrobin dns, but sharing service is not mastered for > effective sharing and the life test is not present. > > Bien à vous > > Mr Karim Bourenane > +33686464439 > +32493866354 > > > > Le mar. 11 juin 2019 à 14:03, François Cami a écrit :

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
Bourenane +33686464439 +32493866354 Le mar. 11 juin 2019 à 14:03, François Cami a écrit : > Hi Karim, > > On Tue, Jun 11, 2019 at 1:56 PM Karim Bourenane via FreeIPA-users > wrote: > > > > Hello team > > > > Hope you are well. > > > > After

[Freeipa-users] [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
Hello team Hope you are well. After an existing installation, we decide to implement a Haproxy + Keepalive in all our IPA's servers. The haproxy / keepalive work weel but now the IPA doent run weel, because he want to listen on all interface in the servers. Ho i can to modify the IPA (+ all

[Freeipa-users] Re: ILO Card IPA authentication

2019-06-06 Thread Karim Bourenane via FreeIPA-users
e LDAP authentication and point it to IPA. > > John > > On 6 Jun 2019, at 10:57, Karim Bourenane via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > > Hello All > > I want to authenticate Users into our ILO 4 card HP by Freeipa. > The ESXI server is not enrol

[Freeipa-users] ILO Card IPA authentication

2019-06-06 Thread Karim Bourenane via FreeIPA-users
Hello All I want to authenticate Users into our ILO 4 card HP by Freeipa. The ESXI server is not enrolled into the IPA, only the DNS was defined. Also i can't extract any keytab for easy user authentication. Can you help me with this? Regards Karim Bourenane

[Freeipa-users] Re: Add a new ObjectClass / Attributes / Help

2019-05-13 Thread Karim Bourenane via FreeIPA-users
Hello Alexander Thank you. I will start with this. About attributes création i will on it too ? Regard Karim Bourenane +33686464439 +32475753687 Le lun. 13 mai 2019 à 14:08, Alexander Bokovoy a écrit : > On la, 11 touko 2019, Karim Bourenane via FreeIPA-users wrote: > >

[Freeipa-users] Re: Add a new ObjectClass / Attributes / Help

2019-05-13 Thread Karim Bourenane via FreeIPA-users
: > Karim Bourenane via FreeIPA-users wrote: > > Hello > > > > I would like to authenticate applications with users via IPA. I can't > > find a Redhat tutorial (unless I'm wrong ??). > > > > Can you give me a link with a tutorial please ? > > > > My fr

[Freeipa-users] Add a new ObjectClass / Attributes / Help

2019-05-10 Thread Karim Bourenane via FreeIPA-users
Hello I would like to authenticate applications with users via IPA. I can't find a Redhat tutorial (unless I'm wrong ??). Can you give me a link with a tutorial please ? My freeipa version is 4.5.4 Mr Karim Bourenane ___ FreeIPA-users mailing list

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
thank you for confirmations on that. I have another request, but I will open another post, to separate the pb. Karim Bourenane Le lun. 29 avr. 2019 à 23:09, François Cami a écrit : > On Mon, Apr 29, 2019 at 10:32 PM Karim Bourenane via FreeIPA-users > wrote: > > >

[Freeipa-users] Nfs server deleted from GUI. Need help

2019-04-30 Thread Karim Bourenane via FreeIPA-users
Hello , Our dedicat NFS server was removed from the IPA GUI. The service does'nt work since this time ONLY for new users. How to restore service for all users without losing the data and the hand ? Can you please help me to correct this state ? Regards Karim Bourenane

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
ture ? or i must manage by > localisation ? > > We can only recommend the tight cell topology. > See "Figure 4.5. Topology Example" and "4.2.2.1. Tight Cell Topology" > in the documentation I mentioned earlier. > > > Bien à vous > > > > Mr Karim Bo

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
branch of network. You think that its the better architecture ? or i must manage by localisation ? Bien à vous Mr Karim Bourenane Le lun. 29 avr. 2019 à 23:09, François Cami a écrit : > On Mon, Apr 29, 2019 at 10:32 PM Karim Bourenane via FreeIPA-users > wrote: > > >

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-30 Thread Karim Bourenane via FreeIPA-users
, why i haven't the GUI Management, its normal ? if yes, is not possible to have ? Regard Bien à vous Mr Karim Bourenane Le lun. 29 avr. 2019 à 23:09, François Cami a écrit : > On Mon, Apr 29, 2019 at 10:32 PM Karim Bourenane via FreeIPA-users > wrote: > > > > Hello Jochen

[Freeipa-users] Re: Multi Enrollment possible ?

2019-04-29 Thread Karim Bourenane via FreeIPA-users
Hello Jochen Thanks you or your reply. My goal, is to authenticate differents users from each client network interface. If the first ipa server goes down (or network unreachable), then the admin user can access to the second network interface to make change/correct . The goals also, is

[Freeipa-users] Multi Enrollment possible ?

2019-04-20 Thread Karim Bourenane via FreeIPA-users
Hello All, I need your help. I have a small projet, finale design no fixed yet : 2 IPA server in dedicat network (no link between), but with the same REALM: IPA.EXAMPLE.COM I want to deploy some IPA-client with 2 interfaces, each host interface managed by each IPA server. Can you confirm me,