[Freeipa-users] exporting ldap certificate

2013-04-25 Thread Peter Brown
Hi everyone. I am attempting to get Google Apps to sync with FreeIPA and I am having problems getting the sync utility to talk to freeipa. It complains about the ssl cert. I have it setup so it only accepts ssl or tls encrypted connections and I don't want to turn that off. I have imported the ca

Re: [Freeipa-users] Freeipa -ssh keys

2013-04-25 Thread Alexander Bokovoy
On Thu, 25 Apr 2013, naresh reddy wrote: Hi all  my sshd config file #       $OpenBSD: sshd_config,v 1.87 2012/07/10 02:19:15 djm Exp $ # This is the sshd server system-wide configuration file.  See # sshd_config(5) for more information. # This sshd was compiled with PATH=/usr/local/bin:/usr

Re: [Freeipa-users] Freeipa-users Digest, Vol 57, Issue 66

2013-04-25 Thread Brent Clark
I use the following on my CentOS 6.3 servers for the ssh keys to work from IPA. sshd.conf AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys > -- > To: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] Freeipa -ssh ke

Re: [Freeipa-users] deleted ipa admin groups

2013-04-25 Thread Rob Crittenden
Sylvain Angers wrote: Hello Someone did delete the admin group by mistake, how can we recover from this? No one change password, or any other admin task is allow. But we have the Directory server password. the remaining group is "ipausers" and we had only the default group Please any help w

[Freeipa-users] deleted ipa admin groups

2013-04-25 Thread Sylvain Angers
Hello Someone did delete the admin group by mistake, how can we recover from this? No one change password, or any other admin task is allow. But we have the Directory server password. the remaining group is "ipausers" and we had only the default group Please any help will be appreciate -- Sy

Re: [Freeipa-users] Freeipa -ssh keys

2013-04-25 Thread naresh reddy
Hi Jan I tried to flow this https://fedoraproject.org/wiki/QA:Testcase_FreeIPA_realmd_ssh https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Deployment_Guide/openssh-sssd.html still unable to loggin via ssh keys Please kindly suggest OpenSSH_6.1p1, OpenSSL 1.0.

Re: [Freeipa-users] Freeipa -ssh keys

2013-04-25 Thread naresh reddy
Hi Jan yes thats correct clinet is ldap1 and server is ldap1. root@ldap1 ssh]# /usr/bin/sss_ssh_knownhostsproxy -p 22 ldap1.eng.switchlab.net --debug 10 SSH-2.0-OpenSSH_6.1 Protocol mismatch. [root@ldap1 ssh]# /usr/bin/sss_ssh_authorizedkeys test@eng ssh-rsa B3NzaC1yc2EBIwAAAQEAzvp0xx

Re: [Freeipa-users] Issue IPA: AD Users and IPA Users when using SSS/LDAP with SUDO

2013-04-25 Thread Sumit Bose
On Thu, Apr 25, 2013 at 12:38:18PM +0200, Pavel Březina wrote: > On 04/24/2013 07:20 PM, Aly Khimji wrote: > >(Wed Apr 24 13:07:35 2013) [sssd[be[nix.corpnonprd..com]]] > >[be_pam_handler_callback] (0x0100): Backend returned: (0, 0, ) > >[Success] > >(Wed Apr 24 13:07:35 2013) [sssd[be[nix.co

Re: [Freeipa-users] Issue IPA: AD Users and IPA Users when using SSS/LDAP with SUDO

2013-04-25 Thread Pavel Březina
On 04/24/2013 07:20 PM, Aly Khimji wrote: (Wed Apr 24 13:07:35 2013) [sssd[be[nix.corpnonprd..com]]] [be_pam_handler_callback] (0x0100): Backend returned: (0, 0, ) [Success] (Wed Apr 24 13:07:35 2013) [sssd[be[nix.corpnonprd..com]]] [sss_selinux_extract_user] (0x0040): sysdb_search_user

Re: [Freeipa-users] A public interface (aka My account management)

2013-04-25 Thread Arturo Borrero
On 25/04/13 10:30, Martin Kosek wrote: On 04/24/2013 10:30 PM, Chris Evich wrote: On 04/24/2013 08:32 AM, Tomas Babej wrote: On 04/24/2013 01:53 PM, Arturo Borrero wrote: Hi there. I'm wondering if it's possible to get FreeIPA with a 'public user interface'. This is: a place where a standar u

Re: [Freeipa-users] A public interface (aka My account management)

2013-04-25 Thread Martin Kosek
On 04/24/2013 10:30 PM, Chris Evich wrote: > On 04/24/2013 08:32 AM, Tomas Babej wrote: >> On 04/24/2013 01:53 PM, Arturo Borrero wrote: >>> Hi there. >>> >>> I'm wondering if it's possible to get FreeIPA with a 'public user >>> interface'. >>> This is: a place where a standar user can update his p