[Freeipa-users] Need a howto for "Service Account done correctly"

2019-03-20 Thread Will Kay via FreeIPA-users
Hi, I'm working on binding a Fortinet FW to FreeIPA LDAP for VPN authentication. I did quite some Google searches and found only a few leads. I want make sure I will do this correctly. 1. Setup a "system account" per this FreeIPA Howto https://www.freeipa.org/page/HowTo/LDAP 2. In the

[Freeipa-users] Re: freeipa client on Ubuntu SSH fails

2019-03-11 Thread Will Kay via FreeIPA-users
I knew we are close because there wasn't much to check anymore. =) The sshd configuration was updated by the installation. On 18.04, somehow there was only one line in one pam files. I added what Alex suggested and followed up with pam-auth-update. It is good on 18.04 now. 16.04 is also

[Freeipa-users] Re: freeipa client on Ubuntu SSH fails

2019-03-08 Thread Will Kay via FreeIPA-users
Thanks for the tip. I made the nsswitch.conf just like yours. I also look at the files on a CentOS7 client and make changes on the Ubuntu. But it is still no good. As more suggestion? The test user ID are on the system, I can su to them. However I cant' ssh it. I also notice when I try

[Freeipa-users] freeipa client on Ubuntu SSH fails

2019-03-06 Thread Will Kay via FreeIPA-users
Hi all, Issue: We have freeipa servers set and tests are good with CentOS 7.6 clients. We are trying to test Ubuntu 16.04 and 18.04 clients. After running ipa-client-install, we can't ssh login the Ubuntu's with ipa user accounts. If we login as root, `ipa user-show xxx` looks fine on the