Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Rob Crittenden
Steven Jones wrote: Ok, However I cant LDAP/Ipa authenticate stillon either client.. So what next? sssd handles logins, you can try turning up the log level on that (though I suspect it wasn't the reboot that fixed this but restarting sssd). As part of ipa-client-install sssd i

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
I rebooted both clients and after the reboot they now do IPA authentication.. So client1 we did some work on and it wouldnt work until a rebootclient2 I did nothing to until I rebooted.then that also worked So I will make a third client and try that Are there rpms & scripts

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
Ok, However I cant LDAP/Ipa authenticate stillon either client.. So what next? regards Steven From: Rob Crittenden [rcrit...@redhat.com] Sent: Thursday, 10 March 2011 10:47 a.m. To: Steven Jones Cc: freeipa-users@redhat.com Subject: Re: [Free

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
8><--- > 4) Install client again > > Everything should work. > If not please send us the logs. Not sure which logs as Im losing track of so many suggestions/threadsbut, On the client the sssd.log is zero length, the sssd_ipa.ac.nz.log is zero length I just tried to add a local user

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Rob Crittenden
Steven Jones wrote: Hi, I have gone into the webgui and manually removed the no1 client/host, it has now joined successfully... So Yes, the next issue regards I'm going to try to consolidate a few things here from some other responses. * You do not need to pre-create the host in order

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Dmitri Pal
On 03/09/2011 03:09 PM, Steven Jones wrote: > On Wed, 2011-03-09 at 14:42 -0500, Dmitri Pal wrote: >> On 03/09/2011 02:21 PM, Steven Jones wrote: >>> Hi, >>> >>> I had/have already done the uninstall...and re-install. >>> >>> Also I registered a brand new 2nd client...that hasnt worked >>> either..

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
Hi, I have gone into the webgui and manually removed the no1 client/host, it has now joined successfully... So Yes, the next issue regards On Wed, 2011-03-09 at 14:51 -0500, Stephen Gallagher wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 03/09/2011 02:45 PM, Steven Jon

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
On Wed, 2011-03-09 at 14:42 -0500, Dmitri Pal wrote: > On 03/09/2011 02:21 PM, Steven Jones wrote: > > Hi, > > > > I had/have already done the uninstall...and re-install. > > > > Also I registered a brand new 2nd client...that hasnt worked > > either.. > > > How did you create the host record f

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/09/2011 02:45 PM, Steven Jones wrote: > I have setup a 2nd client I have the same resultbut it looks like > the keytab is correct? however LDAP logins still dont work... > > > Keytab name: WRFILE:/etc/krb5.keytab > KVNO Principal > >

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
I have setup a 2nd client I have the same resultbut it looks like the keytab is correct? however LDAP logins still dont work... Keytab name: WRFILE:/etc/krb5.keytab KVNO Principal -- 1 host/fed14-64-ipacl02.ipa.a

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Dmitri Pal
On 03/09/2011 02:21 PM, Steven Jones wrote: > Hi, > > I had/have already done the uninstall...and re-install. > > Also I registered a brand new 2nd client...that hasnt worked > either.. > How did you create the host record for it on the server? > regards > > > On Tue, 2011-03-08 at 23:29 -05

Re: [Freeipa-users] Problem with replication after restore

2011-03-09 Thread Rich Megginson
On 03/09/2011 09:15 AM, tomasz.napier...@allegro.pl wrote: On 2011-03-09, at 15:09, Rich Megginson wrote: 8><- [04/Mar/2011:14:59:17 +0100] NSMMReplicationPlugin - agmt="cn=meToMASTER636" (XXX:636): Missing data encountered [04/Mar/2011:14:59:17 +0100] NSMMReplicationPlugin - a

Re: [Freeipa-users] Unable to authenticate a client user against IPA

2011-03-09 Thread Steven Jones
Hi, I had/have already done the uninstall...and re-install. Also I registered a brand new 2nd client...that hasnt worked either.. regards On Tue, 2011-03-08 at 23:29 -0500, Rob Crittenden wrote: > Steven Jones wrote: > > Hi, > > > > Log, > > > > The error is "Host is already joined" so no

Re: [Freeipa-users] Problem with replication after restore

2011-03-09 Thread tomasz.napier...@allegro.pl
On 2011-03-09, at 15:09, Rich Megginson wrote: 8><- >> [04/Mar/2011:14:59:17 +0100] NSMMReplicationPlugin - agmt="cn=meToMASTER636" >> (XXX:636): Missing data encountered >> [04/Mar/2011:14:59:17 +0100] NSMMReplicationPlugin - agmt="cn=meToMASTER636" >> (XXX:636): Incremental up

Re: [Freeipa-users] Problem with replication after restore

2011-03-09 Thread Rich Megginson
On 03/09/2011 06:20 AM, tomasz.napier...@allegro.pl wrote: Hi, Recently we had to move our freeipa master into separate infrastructure. Because we use KVM, server was shutdown, gzipped, scped nad restored on other KVM host. It looks like since then replication stopped completely. On the slave

[Freeipa-users] Problem with replication after restore

2011-03-09 Thread tomasz.napier...@allegro.pl
Hi, Recently we had to move our freeipa master into separate infrastructure. Because we use KVM, server was shutdown, gzipped, scped nad restored on other KVM host. It looks like since then replication stopped completely. On the slave I can see such entries in the logs: [04/Mar/2011:14:59:17 +01