Re: [Freeipa-users] Insufficient access during winsync agreement

2011-06-21 Thread Attila Bogár
On 20/06/11 16:37, Attila Bogár wrote: I'm trying to set up the AD-FreeIPA sync agreement and I'm always getting this error: # ipa-replica-manage connect --winsync --binddn cn="IPA Sync",cn=Users,dc=win,dc=example,dc=com --bindpw JamesBond007 --cacert /root/dc1.cer --passsync JamesBond007 dc1.w

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Adam Tkac
On 06/16/2011 09:38 PM, Loris Santamaria wrote: > El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: >> On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: >>> Hi, >>> >>> I would like to use my freeIPA v2 server as my master name server and >>> have other normal (non ldap based) bin

Re: [Freeipa-users] Insufficient access during winsync agreement

2011-06-21 Thread Simo Sorce
On Tue, 2011-06-21 at 10:01 +0100, Attila Bogár wrote: > On 20/06/11 16:37, Attila Bogár wrote: > > I'm trying to set up the AD-FreeIPA sync agreement and I'm always > > getting this error: > > # ipa-replica-manage connect --winsync --binddn cn="IPA > > Sync",cn=Users,dc=win,dc=example,dc=com --bi

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Simo Sorce
On Tue, 2011-06-21 at 12:12 +0200, Adam Tkac wrote: > On 06/16/2011 09:38 PM, Loris Santamaria wrote: > > El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: > >> On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: > >>> Hi, > >>> > >>> I would like to use my freeIPA v2 server as my m

[Freeipa-users] syncing custom attributes from AD

2011-06-21 Thread Attila Bogár
Dear List, I'd like to sync extra attributes from AD -> FreeIPA. These are namely: employeeNumber and employeeType. The following .ldif is always adding value unknown instead of syncing the value in AD. -- 8< -- dn: cn=ipa-winsync,cn=plugins,cn=config changetype: modify add: ipaWinSyncUserAttr

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Loris Santamaria
El mar, 21-06-2011 a las 12:12 +0200, Adam Tkac escribió: > On 06/16/2011 09:38 PM, Loris Santamaria wrote: > > El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: > >> On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: > >>> Hi, > >>> > >>> I would like to use my freeIPA v2 server a

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Adam Tkac
On 06/21/2011 03:51 PM, Loris Santamaria wrote: > El mar, 21-06-2011 a las 12:12 +0200, Adam Tkac escribió: >> On 06/16/2011 09:38 PM, Loris Santamaria wrote: >>> El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: > Hi, >>>

[Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
Hi, I'm still running a FreeIPA 1.2 server but have started installing Fedora 15 clients and am trying to figure out how to manually setup the Krb/LDAP configuration. I've run the 'authconfig-tui' command and manually setup Krb authentication and LDAP authorisation, using DNS discovery for the se

[Freeipa-users] ipa-winsync account disable

2011-06-21 Thread Attila Bogár
Dear List, winsync is working between AD and FreeIPA. If I disable a user in FreeIPA, it automatically disables on the AD side. Though, if I disable on the AD side, nothing happens on the FreeIPA side. Moreover, if I get a kerberos ticket for the disabled (only in AD) user from freeipa, then i

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: > Hi, > > I'm still running a FreeIPA 1.2 server but have started installing > Fedora 15 clients and am trying to figure out how to manually setup > the Krb/LDAP configuration. > > I've run the 'authconfig-tui' command and manually setup Krb > a

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
Hi, On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher wrote: > On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: >> Hi, >> >> I'm still running a FreeIPA 1.2 server but have started installing >> Fedora 15 clients and am trying to figure out how to manually setup >> the Krb/LDAP configuration. >

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: > Hi, > > On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher wrote: > > On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: > >> Hi, > >> > >> I'm still running a FreeIPA 1.2 server but have started installing > >> Fedora 15 clients and am trying

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher wrote: > On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: >> Hi, >> >> On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher wrote: >> > On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: >> >> Hi, >> >> >> >> I'm still running a FreeIPA 1.2 server

Re: [Freeipa-users] syncing custom attributes from AD

2011-06-21 Thread Rich Megginson
On 06/21/2011 07:24 AM, Attila Bogár wrote: Dear List, I'd like to sync extra attributes from AD -> FreeIPA. These are namely: employeeNumber and employeeType. The following .ldif is always adding value unknown instead of syncing the value in AD. -- 8< -- dn: cn=ipa-winsync,cn=plugins,cn=conf

Re: [Freeipa-users] ipa-winsync account disable

2011-06-21 Thread Rich Megginson
On 06/21/2011 09:17 AM, Attila Bogár wrote: Dear List, winsync is working between AD and FreeIPA. If I disable a user in FreeIPA, it automatically disables on the AD side. Though, if I disable on the AD side, nothing happens on the FreeIPA side. Sounds like a bug. Moreover, if I get a kerber

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:58 -0400, Dan Scott wrote: > On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher wrote: > > On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: > >> Hi, > >> > >> On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher > >> wrote: > >> > On Tue, 2011-06-21 at 11:06 -0400, Dan Scot

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 14:19, Stephen Gallagher wrote: > On Tue, 2011-06-21 at 11:58 -0400, Dan Scott wrote: >> On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher wrote: >> > On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: >> >> Hi, >> >> >> >> On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 14:41 -0400, Dan Scott wrote: > > Excellent! Thanks - that makes much more sense. I've been using > authconfig-tui all this time and had no idea that it was doing things > incorrectly. > > One small issue that I found, if I switch on the "Use DNS to resolve > hosts to realms