Re: [Freeipa-users] using kerberos

2011-12-09 Thread Sumit Bose
On Fri, Dec 09, 2011 at 02:15:18AM +, Steven Jones wrote: > Hi > > >From the HNAS manual > > 8><- > Kerberos Configuration > Configuring the NAS server requires three steps: > 1. Create the principal and key of the service (the EVS) on the KDC (Key > Distribution Center). > 2. Expo

Re: [Freeipa-users] dns delegated zone issue

2011-12-09 Thread Natxo Asenjo
On Fri, Dec 9, 2011 at 1:55 AM, Simo Sorce wrote: >> If I login using a fqdn instead of the simple one, then it works. The >> funny thing is, I can use the simple dns name to login the kdc server. >> Why? > > Not sure why it work on your kdc, perhaps you have entries in /etc/hosts that > resolve

Re: [Freeipa-users] Limiting group/user visibility

2011-12-09 Thread Lassi Pölönen
On 2011-12-08 17:36, Rob Crittenden wrote: > Lassi Pölönen wrote: >> On 7.12.2011 21:28, Dmitri Pal wrote: So I came in to conclusion I just create a role for each customer, e.g "Customer1" and assign that role to all customer's user groups and hosts (too bad it isn't possible t

Re: [Freeipa-users] CA replication

2011-12-09 Thread Rob Crittenden
Dan Scott wrote: Hi, On Thu, Dec 8, 2011 at 13:29, Rob Crittenden wrote: Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It proceeds to configure the directory server for the CA, but fails when 'configurin

Re: [Freeipa-users] CA replication

2011-12-09 Thread Dan Scott
Hi, On Fri, Dec 9, 2011 at 09:24, Rob Crittenden wrote: > Dan Scott wrote: >> >> Hi, >> >> On Thu, Dec 8, 2011 at 13:29, Rob Crittenden  wrote: >>> >>> Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-in

Re: [Freeipa-users] CA replication

2011-12-09 Thread Rob Crittenden
Dan Scott wrote: Hi, On Fri, Dec 9, 2011 at 09:24, Rob Crittenden wrote: Dan Scott wrote: Hi, On Thu, Dec 8, 2011 at 13:29, Rob Crittendenwrote: Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It