[Freeipa-users] Problem joining a windows pc to freeipa realm without an AD server

2023-06-26 Thread fujisan via FreeIPA-users
Hello everyone, Since I upgraded our server to Fedora 38, we cannot access samba shares on that Linux server from windows pc. So i'm trying now to log in to a windows pc using a freeipa user account. I followed instructions I found in the following documentations: https://freeipa.org/page/Window

[Freeipa-users] Freeipa Samba problem: ticket is likely out of date

2022-05-13 Thread fujisan via FreeIPA-users
I'm having trouble accessing a samba share from windows. In the log file, it says "ticket is likely out of date", it is looking for kvno 3 and the output of kvno is 4. How can I update the ticket? Thanks Fuji Server log: [2022/05/13 12:05:35.353907, 1, pid=252383] ../../source3/librpc/crypto/g

[Freeipa-users] Re: trouble running ipa-server-update

2020-08-05 Thread Fujisan via FreeIPA-users
: Servlet [castart] in web application [/ca] threw load() exception On Wed, Aug 5, 2020 at 7:49 PM Rob Crittenden wrote: > Fujisan via FreeIPA-users wrote: > > I ran 'ipactl status' > > - > > # ipactl status > > Directory Service: RUNNING &g

[Freeipa-users] Re: trouble running ipa-server-update

2020-08-04 Thread Fujisan via FreeIPA-users
on > VERSION: 4.8.6, API_VERSION: 2.236 > > So what's the error about? > > > On Tue, Aug 4, 2020 at 4:35 PM Alexander Bokovoy > wrote: > >> On ti, 04 elo 2020, Fujisan via FreeIPA-users wrote: >> >I noticed that there is only one file in /etc/httpd/al

[Freeipa-users] Re: trouble running ipa-server-update

2020-08-04 Thread Fujisan via FreeIPA-users
The IPA version I use is # ipa --version VERSION: 4.8.6, API_VERSION: 2.236 So what's the error about? On Tue, Aug 4, 2020 at 4:35 PM Alexander Bokovoy wrote: > On ti, 04 elo 2020, Fujisan via FreeIPA-users wrote: > >I noticed that there is only one file in /etc/httpd/al

[Freeipa-users] Re: trouble running ipa-server-update

2020-08-04 Thread Fujisan via FreeIPA-users
I noticed that there is only one file in /etc/httpd/alias, therefore giving the error message "certutil: function failed: SEC_ERROR_BAD_DATABASE: security library: bad database" # ll /etc/httpd/alias total 4 -rw--- 1 root root 32 Apr 16 2019 ipasession.key __

[Freeipa-users] trouble running ipa-server-update

2020-08-04 Thread Fujisan via FreeIPA-users
I upgraded my FreeIPA server to F31 and when running ipa-server-update, I get and error message: # ipa-server-upgrade Upgrading IPA:. Estimated time: 1 minute 30 seconds [1/11]: stopping directory server [2/11]: saving configuration [3/11]: disabling listeners [4/11]: enabling DS global

[Freeipa-users] Re: How to move FreeIPA to new server?

2019-04-16 Thread fujisan via FreeIPA-users
to IPA master >> > instead of _srv_ label. If it has both, make sure you keep _srv_ >> > first and replace old server name by the new one there. On IPA masters >> > itself there should be no _srv_ label. >> > >> > - /etc/ipa/default.conf has name of the mast

[Freeipa-users] Re: How to move FreeIPA to new server?

2019-04-16 Thread fujisan via FreeIPA-users
old server as a KDC. It can > > also be updated without any issue. > > > > > > > > >On Tue, Apr 16, 2019 at 11:42 AM Alexander Bokovoy > > > >wrote: > > > > > >> On ti, 16 huhti 2019, fujisan via FreeIPA-users wrote: > > &

[Freeipa-users] Re: How to move FreeIPA to new server?

2019-04-16 Thread fujisan via FreeIPA-users
and then re-install each client with --server=new-server.my.domain? On Tue, Apr 16, 2019 at 11:42 AM Alexander Bokovoy wrote: > On ti, 16 huhti 2019, fujisan via FreeIPA-users wrote: > >Hello, > > > >I just got a new server on which I'd like to install a FreeIPA server

[Freeipa-users] How to move FreeIPA to new server?

2019-04-16 Thread fujisan via FreeIPA-users
Hello, I just got a new server on which I'd like to install a FreeIPA server. Today it is installed on the old server. I just tried to install it with ipa-server-install but of course it complained saying the DNS domain is handled by the old server. What is the best way to install FreeIPA on the

[Freeipa-users] Re: problem access Linux shares from Windows "ticket is likely out of date"

2019-03-13 Thread fujisan via FreeIPA-users
OK, looking forward to seeing your work done. Regards. F On Wed, Mar 13, 2019 at 11:20 AM Alexander Bokovoy wrote: > On ke, 13 maalis 2019, fujisan wrote: > >Hi Alexander, > >Finally succeeded to make it work with the following configuration on the > >freeipa server. > > > >[global] > >work

[Freeipa-users] Re: problem access Linux shares from Windows "ticket is likely out of date"

2019-03-13 Thread fujisan via FreeIPA-users
Hi Alexander, Finally succeeded to make it work with the following configuration on the freeipa server. [global] workgroup = MYDOMAIN.LOCAL netbios name = MYSERVER realm = MYDOMAIN.LOCAL kerberos method = dedicated keytab dedicated keytab file = /etc/samba/samba.keytab crea

[Freeipa-users] Re: problem access Linux shares from Windows "ticket is likely out of date"

2019-03-12 Thread fujisan via FreeIPA-users
This is strange as /data and /tmp are 2 partitions on my server and scratch is a directory in /data /dev/mapper/fedora-data 2832342640 946566920 1741877916 36% /data /dev/mapper/fedora-tmp 153769424 61780 145826940 1% /tmp # ls -l /data/ total 52 drwxrwx---. 5 root staff 4096 Mar

[Freeipa-users] Re: problem access Linux shares from Windows "ticket is likely out of date"

2019-03-12 Thread fujisan via FreeIPA-users
I added a share in smb.conf.regedit then I imported the file with net conf import smb.conf.regedit . I send you another tar file at your email. Regards F # net conf list [global] workgroup = MYDOMAIN.LOCAL netbios name = MYSERVER realm = MYDOMAIN.LOCAL kerberos method = dedicated

[Freeipa-users] problem access Linux shares from Windows "ticket is likely out of date"

2019-03-12 Thread fujisan via FreeIPA-users
I messed up somehow with my samba server. I'm trying to access a linux share from windows and the log on the linux server says: [Unspecified GSS failure. Minor code may provide more information: Request ticket server cifs/myserver.mydomain.local@MYDOMAIN.LOCAL kvno 8 not found in keytab; ticket is