[Freeipa-users] Dogtag cert for Active Directory users?

2022-10-01 Thread Sami Hulkko via FreeIPA-users
Hi, Is it possible to provide certificate (Dogtag) for AD trusted user that has login rights to IPA trough ID override? -- Me worry? That's why my first CD was Peter Gabriel SO Sami Hulkko sahul...@gmail.com sahul...@icloud.com samihul...@quantum-black-hole.com +358 45 85693 919 BEGIN:VCA

[Freeipa-users] Re: Freeipa docker with Traefik docker

2022-09-24 Thread Sami Hulkko via FreeIPA-users
Replying to my own, https://docs.docker.com/config/daemon/systemd/#httphttps-proxy The setting up of Docker daemon to support proxy server did not appear in _any_of_the_12_hour_searches. The reason for failures is most likely this. SH On 24/09/2022 09:53, Sami Hulkko via FreeIPA-users

[Freeipa-users] Freeipa docker with Traefik docker

2022-09-23 Thread Sami Hulkko via FreeIPA-users
Hi, Is there anyone who could point me into some info about this matter of having Freeipa Docker behind Traefik Docker reverse proxy? I could not make it work with both dockers on same machine. I got 404 from Traefik and with extensive search found only one post chain about the problem. My wi

[Freeipa-users] Re: ipa-client-automount troubles

2022-09-06 Thread Sami Hulkko via FreeIPA-users
To Clarify and Correct: On 04/09/2022 17:22, Sami Hulkko via FreeIPA-users wrote: If one will: service-add nfs/ Missing ipa command in front. ipa service-add-host --hosts= nfs/ add client hosts same manner. Install certificate for the nfs service: Create group certadmin and add

[Freeipa-users] Re: ipa-client-automount troubles

2022-09-04 Thread Sami Hulkko via FreeIPA-users
/ --pac-type=none pac type NONE was recommended for NFS in: ipa help service -documentation And after that ipa-client automount - works! SH On 04/09/2022 14:41, Sami Hulkko via FreeIPA-users wrote: What I can dig from log: kern.log Sep  4 14:37:14 mail kernel: [ 8464.142473] show_signal_msg: 2

[Freeipa-users] Re: ipa-client-automount troubles

2022-09-04 Thread Sami Hulkko via FreeIPA-users
kernel: [ 8523.353132] Code: Unable to access opcode bytes at RIP 0x7fbb8e8d5286. Seems to be segfault. SH On 04/09/2022 09:51, Sami Hulkko via FreeIPA-users wrote: Hi, I lately have tried to get the autofs working with bit of trouble. I have a following setup: ipa-autofs: default

[Freeipa-users] ipa-client-automount troubles

2022-09-03 Thread Sami Hulkko via FreeIPA-users
Hi, I lately have tried to get the autofs working with bit of trouble. I have a following setup: ipa-autofs: default - auto.master   -   auto.home - auto.home   -*    /& nfs-server: gss/krb5i(rw,sync,no_subtree_check,no_root_squash) ipa: service nfs/ service nfs/ and copied to ser

[Freeipa-users] Re: Ubuntu 22 and sssd 2.6.3

2022-08-24 Thread Sami Hulkko via FreeIPA-users
'TRIED' vs 'TIRED' I do not do this kind of spelling mistakes. That is the reason nothing works on your system. SH On 25/08/2022 09:42, Sami Hulkko via FreeIPA-users wrote: Hi, No probs in Ubuntu 22.04.1 thats for shore. Ever tired with real thing? SH On 25/08/20

[Freeipa-users] Re: Ubuntu 22 and sssd 2.6.3

2022-08-24 Thread Sami Hulkko via FreeIPA-users
Hi, No probs in Ubuntu 22.04.1 thats for shore. Ever tired with real thing? SH On 25/08/2022 07:41, Ranbir via FreeIPA-users wrote: Hello All, Has anyone successfully enrolled an Ubuntu 22 client into an AlmaLinux 9 IdM or Rocky Linux 9 IdM domain in a trust with AD _and_ managed to have cons

[Freeipa-users] Re: Freeipa automount fails on login.

2022-08-09 Thread Sami Hulkko via FreeIPA-users
To add: If mounted with -S (no sssd) upon login the mount is not accepted and error: key has expired: /home/foo.org/foouser though with klist: non expired krb5 key. SH On 10/08/2022 09:33, Sami Hulkko via FreeIPA-users wrote: I can add that with: ipa-client-automount -S (no sssd) it

[Freeipa-users] Re: Freeipa automount fails on login.

2022-08-09 Thread Sami Hulkko via FreeIPA-users
I can add that with: ipa-client-automount -S (no sssd) it works. On 10/08/2022 09:23, Sami Hulkko wrote: Hi, I have a home folders shared at server.foo.org on folder /srv/home/foo.org and I can mount this share on client.foo.org with kerberos security. /etc/export is: /srv/home/foo.org

[Freeipa-users] Freeipa automount fails on login.

2022-08-09 Thread Sami Hulkko via FreeIPA-users
Hi, I have a home folders shared at server.foo.org on folder /srv/home/foo.org and I can mount this share on client.foo.org with kerberos security. /etc/export is: /srv/home/foo.org *(rw,sec=krb5:krb5i:krb5p,sync,no_root_squash,no_subtree_check) On Freeipa server under Network Services I