Re: [Freeipa-users] Fwd: replica read-only

2012-11-14 Thread Simo Sorce
On Wed, 2012-11-14 at 16:47 -0200, Andre Rodrigues wrote: > thanks for the info Simo! > I work at a university and the current structure is: > a meta-directory that feeds a master 389-ds, and the master replicates > the data to two read-only directories, that are accessible to > customers. > any ch

[Freeipa-users] Fwd: replica read-only

2012-11-14 Thread Andre Rodrigues
thanks for the info Simo! I work at a university and the current structure is: a meta-directory that feeds a master 389-ds, and the master replicates the data to two read-only directories, that are accessible to customers. any changes in the directory should be sent to the meta-directory, which wil

Re: [Freeipa-users] replica read-only

2012-11-14 Thread Simo Sorce
On Wed, 2012-11-14 at 10:26 -0800, Brian Cook wrote: > Having a read-only replica would be ideal for placement in a DMZ. See > active directory's read-only domain controller introduced in 2008 R2 > for just that use case. Hi Brian, yes we know about the DMZ use case, but that one goes beyond just

Re: [Freeipa-users] replica read-only

2012-11-14 Thread Brian Cook
Having a read-only replica would be ideal for placement in a DMZ. See active directory's read-only domain controller introduced in 2008 R2 for just that use case. -Brian On Nov 14, 2012, at 6:07 AM, Simo Sorce wrote: > On Wed, 2012-11-14 at 11:54 -0200, Andre Rodrigues wrote: >> Hi, >> I'm

Re: [Freeipa-users] ipa and cronjob

2012-11-14 Thread Anthony Messina
On Wednesday, November 14, 2012 08:30:48 AM Simo Sorce wrote: > > > Just FYI, this is not strictly true, look at the -P, --password option > > > of ipa-getkeytab > > > > > > > > Thanks. I didn't notice that option since I'd been using this method > > since before I started using IPA. > > > > >

Re: [Freeipa-users] ipa and cronjob

2012-11-14 Thread Anthony Messina
On Wednesday, November 14, 2012 09:42:03 AM Petr Spacek wrote: > >> Just FYI, this is not strictly true, look at the -P, --password option > >> of ipa-getkeytab > > > > Thanks. I didn't notice that option since I'd been using this method > > since > > before I started using IPA. > > > > Is the p

Re: [Freeipa-users] sssd/pam login issues after upgrade to 2.2.1 on Fedora 17

2012-11-14 Thread Anthony Messina
On Wednesday, November 14, 2012 09:06:20 AM Martin Kosek wrote: > >> See https://fedorahosted.org/freeipa/ticket/3253 > > > > > > > > Thanks Anthony for this bug report! I added some info to the Trac ticket, > > but> > > I will rather repeat here: > > > > > > This is indeed a bug in a code proces

Re: [Freeipa-users] replica read-only

2012-11-14 Thread Simo Sorce
On Wed, 2012-11-14 at 11:54 -0200, Andre Rodrigues wrote: > Hi, > I'm trying to setup replicas from my ipa server and > "ipa-replica-install" is based on multimaster replication. > Is there a way to set a ipa replica to be a slave/read-only? > No,at the moment replicas are full masters, we are inv

[Freeipa-users] replica read-only

2012-11-14 Thread Andre Rodrigues
Hi, I'm trying to setup replicas from my ipa server and "ipa-replica-install" is based on multimaster replication. Is there a way to set a ipa replica to be a slave/read-only? -- Thanks a lot, -Andre ___ Freeipa-users mailing list Freeipa-users@redhat.c

Re: [Freeipa-users] ipa and cronjob

2012-11-14 Thread Simo Sorce
On Wed, 2012-11-14 at 00:22 -0600, Anthony Messina wrote: > On Wednesday, November 14, 2012 05:00:29 AM Simo Sorce wrote: > > On Tue, 2012-11-13 at 21:53 -0600, Anthony Messina wrote: > > > 1. Using automatic login with the lightdm display manager, I have it > > > run the > > > following script to

Re: [Freeipa-users] ipa and cronjob

2012-11-14 Thread Petr Spacek
On 11/14/2012 07:22 AM, Anthony Messina wrote: On Wednesday, November 14, 2012 05:00:29 AM Simo Sorce wrote: On Tue, 2012-11-13 at 21:53 -0600, Anthony Messina wrote: 1. Using automatic login with the lightdm display manager, I have it run the following script to remove any old Kerberos ccaches

Re: [Freeipa-users] sssd/pam login issues after upgrade to 2.2.1 on Fedora 17

2012-11-14 Thread Martin Kosek
On 11/13/2012 02:01 PM, Martin Kosek wrote: > On 11/12/2012 05:44 PM, Anthony Messina wrote: >> On Monday, November 12, 2012 09:51:14 AM Anthony Messina wrote: >>> On Monday, November 12, 2012 09:17:17 AM Anthony Messina wrote: >> I also find that when I do a manual ldapsearch for the >> no