Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Simo Sorce
On Wed, 2012-10-31 at 11:34 +1000, Peter Brown wrote: > Hi everyone, > > > I have been trying to work out how to achieve this. > I have freeipa 3.0.0 setup on a Fedora 18 server and I have postfix > and dovecot on my new mail server authenticating against Freeipa. > One last thing I would love to

[Freeipa-users] User's choice: automount or autocreate?

2012-10-31 Thread Bret Wortman
Has anyone set things up so that individual users have the option to automount a homedir or have one autocreated on each system they use for them? I have some users who prefer one way and others who prefer the other. Both have valid reasons and I'd rather not make an authoritarian decision for one

Re: [Freeipa-users] User's choice: automount or autocreate?

2012-10-31 Thread Stephen Gallagher
On Wed 31 Oct 2012 08:56:14 AM EDT, Bret Wortman wrote: Has anyone set things up so that individual users have the option to automount a homedir or have one autocreated on each system they use for them? I have some users who prefer one way and others who prefer the other. Both have valid reasons

Re: [Freeipa-users] User's choice: automount or autocreate?

2012-10-31 Thread Bret Wortman
That's what I needed to know. We'll set a system-wide policy and be done with it. Thanks! On Wed, Oct 31, 2012 at 9:43 AM, Stephen Gallagher wrote: > On Wed 31 Oct 2012 08:56:14 AM EDT, Bret Wortman wrote: > >> Has anyone set things up so that individual users have the option to >> automount a ho

[Freeipa-users] Sudo not working

2012-10-31 Thread Bret Wortman
I'm pretty certain there's a painfully simple solution to this that I'm not seeing, but my current configuration isn't picking up the freeipa sudoer rule that I've set. /etc/nsswitch.conf specifies: sudoers:files ldap /etc/nslcd.conf contains: binddn uid=sudo,cn=sysaccounts,cn=etc,dc=wedge

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Stephen Gallagher
On Wed 31 Oct 2012 11:53:15 AM EDT, Bret Wortman wrote: I'm pretty certain there's a painfully simple solution to this that I'm not seeing, but my current configuration isn't picking up the freeipa sudoer rule that I've set. /etc/nsswitch.conf specifies: sudoers:files ldap /etc/nslcd.conf

[Freeipa-users] Sudo not working

2012-10-31 Thread Bret Wortman
I had enabled debugging of sudo but am not clear on where that debugging is going. It's not stdout, and I'm not seeing anything in /var/log/messages. I'll try switching to SSS and see what that gets me. On Wed, Oct 31, 2012 at 1:33 PM, Stephen Gallagher wrote: > On Wed 31 Oct 2012 11:53:15 AM E

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Rob Crittenden
Bret Wortman wrote: I had enabled debugging of sudo but am not clear on where that debugging is going. It's not stdout, and I'm not seeing anything in /var/log/messages. I'll try switching to SSS and see what that gets me. What distro is this? If it is RHEL 6.3 then put the configuration into

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Bret Wortman
F17. On Wed, Oct 31, 2012 at 2:04 PM, Rob Crittenden wrote: > Bret Wortman wrote: > >> I had enabled debugging of sudo but am not clear on where that debugging >> is going. It's not stdout, and I'm not seeing anything in >> /var/log/messages. >> >> I'll try switching to SSS and see what that get

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Rob Crittenden
Bret Wortman wrote: F17. I think you want /etc/ldap.conf then. The easiest way to be sure the right file is being used is to add sudoers_debug 1 to the file. This will present a lot of extra output so you'll know the file is being read. rob On Wed, Oct 31, 2012 at 2:04 PM, Rob Crittenden

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Bret Wortman
[root@fs1 etc]# more /etc/ldap.conf sudoers_debug: 1 [root@fs1 etc]# ls -l /etc/ldap.conf -rw-r--r--. 1 root root 17 Oct 19 14:54 /etc/ldap.conf Where should I see the extra output? I've had this set since last Friday and I'm not seeing any difference. On Wed, Oct 31, 2012 at 2:20 PM, Rob Critten

Re: [Freeipa-users] Sudo not working

2012-10-31 Thread Rob Crittenden
Bret Wortman wrote: [root@fs1 etc]# more /etc/ldap.conf sudoers_debug: 1 [root@fs1 etc]# ls -l /etc/ldap.conf -rw-r--r--. 1 root root 17 Oct 19 14:54 /etc/ldap.conf Where should I see the extra output? I've had this set since last Friday and I'm not seeing any difference. Move the contents of

Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Dmitri Pal
On 10/30/2012 09:34 PM, Peter Brown wrote: > Hi everyone, > > I have been trying to work out how to achieve this. > I have freeipa 3.0.0 setup on a Fedora 18 server and I have postfix > and dovecot on my new mail server authenticating against Freeipa. > One last thing I would love to do it pull dow

Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Stephen Ingram
On Tue, Oct 30, 2012 at 6:34 PM, Peter Brown wrote: > Hi everyone, > > I have been trying to work out how to achieve this. > I have freeipa 3.0.0 setup on a Fedora 18 server and I have postfix and > dovecot on my new mail server authenticating against Freeipa. > One last thing I would love to do i

Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Stephen Ingram
On Wed, Oct 31, 2012 at 6:25 PM, Peter Brown wrote: > On 1 November 2012 08:20, Stephen Ingram wrote: >> >> On Tue, Oct 30, 2012 at 6:34 PM, Peter Brown wrote: >> > Hi everyone, >> > >> > I have been trying to work out how to achieve this. >> > I have freeipa 3.0.0 setup on a Fedora 18 server an

Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Peter Brown
On 1 November 2012 15:07, Stephen Ingram wrote: > On Wed, Oct 31, 2012 at 6:25 PM, Peter Brown wrote: > > On 1 November 2012 08:20, Stephen Ingram wrote: > >> > >> On Tue, Oct 30, 2012 at 6:34 PM, Peter Brown > wrote: > >> > Hi everyone, > >> > > >> > I have been trying to work out how to achi

Re: [Freeipa-users] Getting virtual aliases and domains via freeipa with Postfix

2012-10-31 Thread Stephen Ingram
On Wed, Oct 31, 2012 at 10:21 PM, Peter Brown wrote: > On 1 November 2012 15:07, Stephen Ingram wrote: >> >> On Wed, Oct 31, 2012 at 6:25 PM, Peter Brown wrote: >> > On 1 November 2012 08:20, Stephen Ingram wrote: >> >> >> >> On Tue, Oct 30, 2012 at 6:34 PM, Peter Brown >> >> wrote: >> >> > Hi