Re: [Freeipa-users] EXTERNAL: Re: ipa-replica-install errors

2013-04-11 Thread Joseph, Matthew (EXP)
Hey, Here is the output; Server-Cert u,u,u I am using nss-3-13.3-6 I am using the IPA CA. Matt -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Jatin Nansi Sent: Wednesday, April 10, 2013 9:36 PM To: freeipa-users@red

Re: [Freeipa-users] EXTERNAL: Re: ipa-replica-install errors

2013-04-11 Thread Joseph, Matthew (EXP)
Hey, Sorry didn't read your full message and realize you wanted all of the information for it. The Signature Algorithm is PKCS #1 SHA-256 with RSA Encryption. Matt -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Jatin Na

Re: [Freeipa-users] EXTERNAL: Re: ipa-replica-install errors

2013-04-11 Thread Rob Crittenden
Joseph, Matthew (EXP) wrote: Hey, Here is the output; Server-Cert u,u,u I am using nss-3-13.3-6 I am using the IPA CA. The thing is, the IPA CA isn't there for some reason, on either side. You should also have something like EXAMPLE.COM IPA CA Ct,C,C You might check the working mast

Re: [Freeipa-users] EXTERNAL: Re: ipa-replica-install errors

2013-04-11 Thread Joseph, Matthew (EXP)
Hey, Yes you are correct. For some reason my IPA CA certs were missing. I've added them back onto both the Server and Client so now I am back to getting the; "Replica Data has a different generation ID than the local data" Matt -Original Message- From: Rob Crittenden [mailto:rcrit...@r

[Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Bartek Moczulski
hi, I've got a problem with using IPA as authentication source over LDAP. Generally there are two approaches to LDAP authentication: 1. bind using admin account and read passwords from user objects (but in ipa you cannot read passwords through ldap, right?) 2. "bind to authenticate" - service tries

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread John Dennis
On 04/11/2013 02:47 PM, Bartek Moczulski wrote: hi, I've got a problem with using IPA as authentication source over LDAP. Generally there are two approaches to LDAP authentication: 1. bind using admin account and read passwords from user objects (but in ipa you cannot read passwords through ldap,

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Rob Crittenden
Bartek Moczulski wrote: hi, I've got a problem with using IPA as authentication source over LDAP. Generally there are two approaches to LDAP authentication: 1. bind using admin account and read passwords from user objects (but in ipa you cannot read passwords through ldap, right?) 2. "bind to aut

[Freeipa-users] FreeIPA Fedora 19 Test Day Announcement

2013-04-11 Thread Dmitri Pal
The FreeIPA team is happy to welcome you to a Fedora Test Day that will be held on Thursday, April 18th. We invite you to take part in testing of the new features that will become available in upcoming FreeIPA 3.2 upstream release and would be a part of Fedora 19. To read more about the test day

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Peter Brown
On 12 April 2013 05:04, John Dennis wrote: > On 04/11/2013 02:47 PM, Bartek Moczulski wrote: > >> hi, >> I've got a problem with using IPA as authentication source over LDAP. >> Generally there are two approaches to LDAP authentication: >> 1. bind using admin account and read passwords from user

[Freeipa-users] User Roles and access in GUI

2013-04-11 Thread Chandan Kumar
Hello, I have a question regarding Uer Roles and Access in GUI. What I have found that irrespective of Role assigned to a user, he gets read only access across the directory. For example, I created one user say "dnsadmin" with only Roles related to DNS such as DNS Servers, DNS Administrator. Now

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Simo Sorce
On Thu, 2013-04-11 at 14:59 -0400, Rob Crittenden wrote: > Bartek Moczulski wrote: > > hi, > > I've got a problem with using IPA as authentication source over LDAP. > > Generally there are two approaches to LDAP authentication: > > 1. bind using admin account and read passwords from user objects (b

Re: [Freeipa-users] EXTERNAL: Re: ipa-replica-install errors

2013-04-11 Thread Jatin Nansi
On 04/11/2013 08:55 PM, Joseph, Matthew (EXP) wrote: Hey, Sorry didn't read your full message and realize you wanted all of the information for it. The Signature Algorithm is PKCS #1 SHA-256 with RSA Encryption. OK, then it was just the CA certificate that was missing, the MD5 hash informatio

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Simon Williams
I use Atlassian products, but use Crowd to provide single signon. This means that Crowd is the only application that needs to authenticate against LDAP. I found that I had to tell Crowd that the server was 389 DS. I could not get it to work set to OpenLDAP. Regards Simon On 11 Apr 2013 23:36, "Pe

Re: [Freeipa-users] LDAP authentication for 3rd party

2013-04-11 Thread Peter Brown
On 12 April 2013 15:51, Simon Williams wrote: > I use Atlassian products, but use Crowd to provide single signon. This > means that Crowd is the only application that needs to authenticate against > LDAP. I found that I had to tell Crowd that the server was 389 DS. I could > not get it to work set

Re: [Freeipa-users] User Roles and access in GUI

2013-04-11 Thread Martin Kosek
On 04/12/2013 01:07 AM, Chandan Kumar wrote: > Hello, > > I have a question regarding Uer Roles and Access in GUI. What I have found > that > irrespective of Role assigned to a user, he gets read only access across the > directory. > > For example, I created one user say "dnsadmin" with only Ro