Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread JR Aquino
On May 11, 2011, at 12:25 PM, JR Aquino wrote: >> >> These are all workarounds, I assume having the functionality available >> trough the native sssd >> would be of an advantage. But this way you would the mentioned extra >> functionality of SSSD without >> having to do the work of supporting yo

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread JR Aquino
On May 11, 2011, at 10:51 AM, Sigbjorn Lie wrote: > On Wed, May 11, 2011 14:42, Stephen Gallagher wrote: >> On Tue, 2011-05-10 at 23:42 +0200, Sigbjorn Lie wrote: >> >>> Hi, >>> >>> >>> I would like to see the ipa client scripts and possibly the admin tools >>> in a nice Solaris package. This w

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Dmitri Pal
On 05/11/2011 02:12 PM, Sigbjorn Lie wrote: > Is the nfs/* kerberos service required for all nfs4+krb clients? If so, that > should be added to > the script as well. > AFAIK the service is needed only on the NFS server side but the NFS client should be configured for Kerberos and be able to authen

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Dmitri Pal
On 05/11/2011 01:51 PM, Sigbjorn Lie wrote: > On Wed, May 11, 2011 14:42, Stephen Gallagher wrote: >> On Tue, 2011-05-10 at 23:42 +0200, Sigbjorn Lie wrote: >> >>> Hi, >>> >>> >>> I would like to see the ipa client scripts and possibly the admin tools >>> in a nice Solaris package. This would make

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Sigbjorn Lie
Excellent, thanks. I would add to this ticket: "Retreiving the kerberos keytab and storing in the clients's krb5.keytab", as that's my main issue, not the actual distribution of the common client configuration files. I do this with CFengine today. Is the nfs/* kerberos service required for all

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Stephen Gallagher
- Original Message - From: "Sigbjorn Lie" To: "Stephen Gallagher" Cc: freeipa-users@redhat.com Sent: Wednesday, May 11, 2011 1:51:54 PM Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment On Wed, May 11, 2011 14:42, Stephen Gallagher wrote: > On Tue, 2011-05-10 at 23:42 +

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Sigbjorn Lie
On Wed, May 11, 2011 14:42, Stephen Gallagher wrote: > On Tue, 2011-05-10 at 23:42 +0200, Sigbjorn Lie wrote: > >> Hi, >> >> >> I would like to see the ipa client scripts and possibly the admin tools >> in a nice Solaris package. This would make my job a lot easier as we have a >> lot of customers

Re: [Freeipa-users] fatal error for ipa with dns.

2011-05-11 Thread Adam Young
On 05/11/2011 11:00 AM, Rob Crittenden wrote: Steven Jones wrote: Hi, Nope looks like DNS is barfed big time... == [root@vuwunicoipamt01 ~]# host vuwunicoipamt01.unix.vuw.ac.nz vuwunicoipamt01.unix.vuw.ac.nz has address 130.195.81.236 [root@vuwunicoipamt01 ~]# ipa dns-resolve

Re: [Freeipa-users] fatal error for ipa with dns.

2011-05-11 Thread Rob Crittenden
Steven Jones wrote: Hi, Nope looks like DNS is barfed big time... == [root@vuwunicoipamt01 ~]# host vuwunicoipamt01.unix.vuw.ac.nz vuwunicoipamt01.unix.vuw.ac.nz has address 130.195.81.236 [root@vuwunicoipamt01 ~]# ipa dns-resolve vuwunicoipamt01.unix.vuw.ac.nz ipa: ERROR: Kerb

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-11 Thread Stephen Gallagher
On Tue, 2011-05-10 at 23:42 +0200, Sigbjorn Lie wrote: > Hi, > > I would like to see the ipa client scripts and possibly the admin tools > in a nice Solaris package. This would make my job a lot easier as we > have a lot of customers running Solaris. :) > > For the server part I agree with you,