Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Petr Spacek
On 09/07/2012 12:10 AM, Natxo Asenjo wrote: On Thu, Sep 6, 2012 at 10:31 PM, Sigbjorn Lie sigbj...@nixtra.com mailto:sigbj...@nixtra.com wrote: On 09/05/2012 08:12 PM, Natxo Asenjo wrote: hi, the subject says it all, I guess. I know from another thread that with nexanta it is

Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Sigbjorn Lie
On Fri, September 7, 2012 00:10, Natxo Asenjo wrote: On Thu, Sep 6, 2012 at 10:31 PM, Sigbjorn Lie sigbj...@nixtra.com wrote: On 09/05/2012 08:12 PM, Natxo Asenjo wrote: hi, the subject says it all, I guess. I know from another thread that with nexanta it is possible using

Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Sigbjorn Lie
On Fri, September 7, 2012 09:36, Petr Spacek wrote: On 09/07/2012 12:10 AM, Natxo Asenjo wrote: On Thu, Sep 6, 2012 at 10:31 PM, Sigbjorn Lie sigbj...@nixtra.com mailto:sigbj...@nixtra.com wrote: On 09/05/2012 08:12 PM, Natxo Asenjo wrote: hi, the subject says it all, I guess. I

Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Ondrej Valousek
That is actually the main benefit of the 'ldap.ADdomain' parameter. It will allow you to simplify configuration and allows easy load balancing/failover functionality. We are paying for NetApp support, too so if anyone is going to bug NetApp about this, I am happy to join you. Ondrej On

Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Dmitri Pal
On 09/07/2012 07:33 AM, Ondrej Valousek wrote: That is actually the main benefit of the 'ldap.ADdomain' parameter. It will allow you to simplify configuration and allows easy load balancing/failover functionality. We are paying for NetApp support, too so if anyone is going to bug NetApp about

Re: [Freeipa-users] Desperate help requested.

2012-09-07 Thread Dmitri Pal
On 09/06/2012 09:32 PM, KodaK wrote: Thank you everyone. We finally had our meeting today (it was delayed from Tuesday.) It went much better than I was expecting. Regardless of the email that said we can't authenticate to anything but MS AD, apparently his *actual* concern was having a

Re: [Freeipa-users] errors when one ipa server down

2012-09-07 Thread Dmitri Pal
On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have experienced some odd connectivity issues using MMR with FreeIPA (all systems CentOS 6.3). I have 2 ipa servers (ipaserver / ipaserver2) setup using MMR. [root@ipaserver ~]#ipa-replica-manage list ipaserver.mpls.local: master

Re: [Freeipa-users] ipa host-del

2012-09-07 Thread Dmitri Pal
On 09/05/2012 07:47 PM, Alexander Bokovoy wrote: I did fix this for Fedora with F16 release in past -- in /usr/libexec/freeipa-systemd-update in Fedora packages there is an elaborate code to handle these updates of the symlinks. Perhaps we need to extract that part and add to RHEL6? (RHEL6

Re: [Freeipa-users] errors when one ipa server down

2012-09-07 Thread Michael Mercier
On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have experienced some odd connectivity issues using MMR with FreeIPA (all systems CentOS 6.3). I have 2 ipa servers (ipaserver / ipaserver2) setup using MMR. [root@ipaserver

Re: [Freeipa-users] netapp filer AD + ipa: possible?

2012-09-07 Thread Natxo Asenjo
On Fri, Sep 7, 2012 at 1:33 PM, Ondrej Valousek ondr...@s3group.cz wrote: That is actually the main benefit of the 'ldap.ADdomain' parameter. It will allow you to simplify configuration and allows easy load balancing/failover functionality. We are paying for NetApp support, too so if anyone

Re: [Freeipa-users] Desperate help requested.

2012-09-07 Thread Sigbjorn Lie
Thanks. I believe Rob already created the account. I got some emails regarding a wiki account. Haven't had time to check it out yet. Rgds Siggi Dmitri Pal d...@redhat.com wrote: On 09/06/2012 09:32 PM, KodaK wrote: Thank you everyone. We finally had our meeting today (it was delayed from

Re: [Freeipa-users] openindiana ldap client

2012-09-07 Thread Dmitri Pal
On 09/02/2012 12:58 PM, Sigbjorn Lie wrote: On 09/02/2012 04:37 PM, Natxo Asenjo wrote: hi, Recently I have been playing with the zfs for its native nfs4 acl capabilities. I have used openindiana for this. For those wondering about openindiana, it is a distribution of the former opensolaris

Re: [Freeipa-users] Desperate help requested.

2012-09-07 Thread Dmitri Pal
On 09/07/2012 02:22 PM, Sigbjorn Lie wrote: Thanks. I believe Rob already created the account. I got some emails regarding a wiki account. Haven't had time to check it out yet. Yes. He pinged me before I created the second one for you. Rgds Siggi Dmitri Pal d...@redhat.com wrote: On

Re: [Freeipa-users] errors when one ipa server down

2012-09-07 Thread Dmitri Pal
On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have experienced some odd connectivity issues using MMR with FreeIPA (all systems CentOS 6.3). I have 2 ipa servers (ipaserver / ipaserver2)

Re: [Freeipa-users] RHEV-M + service accounts in IPA

2012-09-07 Thread Dmitri Pal
On 09/05/2012 10:53 AM, Rob Crittenden wrote: Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 05/09/12 13:39, Rob Crittenden wrote: Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Afternoon all I have a demo lab set up with RHEV 3.0 and IPA

Re: [Freeipa-users] errors when one ipa server down

2012-09-07 Thread Michael Mercier
On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have experienced some odd connectivity issues using MMR with FreeIPA (all systems CentOS

Re: [Freeipa-users] winsync msi

2012-09-07 Thread Dmitri Pal
On 07/25/2012 08:32 PM, Steven Jones wrote: Hi, I will ask I am trying to make sure we closed all the loose ends. Steven, is there any update? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272

Re: [Freeipa-users] Active Directory slave zone in FreeIPA DNS (Franklin)

2012-09-07 Thread Dmitri Pal
On 08/27/2012 07:53 AM, Petr Spacek wrote: Hello, On 08/23/2012 07:00 AM, Franklin Catoni wrote: Hi, Hello, Is the zone not transferring at all, or is it just the updates that's not transferred to the AD slave server? It's not transferring at all. If the zone is not transferring at

Re: [Freeipa-users] errors when one ipa server down

2012-09-07 Thread Rob Crittenden
Michael Mercier wrote: On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have experienced some odd connectivity issues using MMR with FreeIPA

Re: [Freeipa-users] 'Request is a replay'

2012-09-07 Thread Dmitri Pal
On 07/26/2012 09:37 AM, Sigbjorn Lie wrote: On 07/26/2012 02:53 PM, Rob Crittenden wrote: Sigbjorn Lie wrote: On Wed, July 25, 2012 09:54, Sigbjorn Lie wrote: On Tue, July 24, 2012 20:29, Simo Sorce wrote: On Tue, 2012-07-24 at 10:22 +0200, Sigbjorn Lie wrote: Hi, I keep seing this

Re: [Freeipa-users] dirsrv@PKI-IPA.service disappeared

2012-09-07 Thread Dmitri Pal
On 07/26/2012 09:57 AM, Tomasz 'Zen' NapieraƂa wrote: Hi, After upgrade from F16 to F17 FreeIPA 2.2.0.1 on secondary servers dirsrv@PKI-IPA.service disappeared. There is an entry for it in systemd, but no config files, etc. /var/log/messages:Jul 24 19:50:56 ldap-XX systemd[1]:

Re: [Freeipa-users] Re-run install script?

2012-09-07 Thread Dmitri Pal
On 08/02/2012 02:58 PM, Simo Sorce wrote: On Thu, 2012-08-02 at 08:22 -0700, Kline, Sara wrote: Copied from below: I get the same error if I try to use ipa host-del although again this works fine for other entries. I have tried everything that the documentation suggested to try and have

Re: [Freeipa-users] unable to logout of IPA

2012-09-07 Thread Dmitri Pal
On 07/27/2012 10:30 AM, Petr Spacek wrote: On 07/27/2012 03:28 PM, John Dennis wrote: On 07/27/2012 02:06 AM, Dan Scott wrote: Hi, I'm not sure if this is relevant, but Firefox preserves session cookies across browser restarts. This was discussed on the Security Now! podcast recently: