Re: [Freeipa-users] Migration of www.freeipa.org wiki

2013-05-14 Thread Martin Kosek
On 05/13/2013 10:27 AM, Martin Kosek wrote: Hello FreeIPA users! We are now in process of migrating our old mediawiki running on www.freeipa.org to a new hosting which will run an updated mediawiki software along with updated theme and front page (more changes will come in future).

[Freeipa-users] Syncing with AD

2013-05-14 Thread James A
Hello all, I have been playing with trying to set up synchronization between windows AD -- IPA following the instructions at https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/index.html A few questions arise; 1.) The documentation

[Freeipa-users] Automount issues

2013-05-14 Thread Joseph, Matthew (EXP)
Hello, I'm currently having issues using automount from my clients. On my IPA Server and Replica there is no issues trying to mount but when I do it from a client I get some weird results. I have a mount point on a server that shows as the following in the IPA GUI. -rw,soft

Re: [Freeipa-users] Syncing with AD

2013-05-14 Thread Chris Hudson
Hello all, I have been playing with trying to set up synchronization between windows AD -- IPA following the instructions at https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/index.html A few questions arise; 1.) The documentation

Re: [Freeipa-users] Syncing with AD

2013-05-14 Thread Joseph, Matthew (EXP)
Hey James, I configured my IPA server with winsync and I was in the same boat as you. The IPA user that is created for Active Directory does not require write access to AD. My IPA user only has read permissions to the domain and my passwords sync just fine. When I delete a user from IPA it

Re: [Freeipa-users] Syncing with AD

2013-05-14 Thread James A
On Tue, May 14, 2013 at 3:30 PM, Joseph, Matthew (EXP) matthew.jos...@lmco.com wrote: Hey James, ** ** I configured my IPA server with winsync and I was in the same boat as you. ** ** The IPA user that is created for Active Directory does not require write access to AD.

[Freeipa-users] Replicas

2013-05-14 Thread Andrew Tranquada
Hello everyone. Is there a limit to the number of replicas you may have? Are there any documents detailing scaling limits for freeIPA? Thanks! ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] EXTERNAL: Re: Syncing with AD

2013-05-14 Thread Joseph, Matthew (EXP)
Hey James, Like I said the IPA user has read access at the domain level. He is also a member of the domain users group. I don't know why it's only working if you have him part of the administrator group. What does it say in the passync log on the AD server? I tried to do the uni-directional

Re: [Freeipa-users] Syncing with AD

2013-05-14 Thread Rob Crittenden
James A wrote: Hello all, I have been playing with trying to set up synchronization between windows AD -- IPA following the instructions at https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/index.html A few questions arise; 1.) The

Re: [Freeipa-users] EXTERNAL: Re: Syncing with AD

2013-05-14 Thread Joseph, Matthew (EXP)
Hey James, One more thing, what are the values in the registry for your password sync application? The default option for the User Name Field was wrong. It was set to userid (or something similar to that) when it should have been uid. I don't think that's your problem but who knows what else

Re: [Freeipa-users] Replicas

2013-05-14 Thread Rob Crittenden
Andrew Tranquada wrote: Hello everyone. Is there a limit to the number of replicas you may have? Are there any documents detailing scaling limits for freeIPA? The maximum number of masters tested is 20. There is nothing in the code to prevent more, and there are users that have more. For

Re: [Freeipa-users] EXTERNAL: Re: Syncing with AD

2013-05-14 Thread James A
On Tue, May 14, 2013 at 3:56 PM, Joseph, Matthew (EXP) matthew.jos...@lmco.com wrote: Hey James, ** ** One more thing, what are the values in the registry for your password sync application The default option for the User Name Field was wrong. It was set to userid (or

Re: [Freeipa-users] EXTERNAL: Re: Syncing with AD

2013-05-14 Thread James A
Hello again, :-) On Tue, May 14, 2013 at 3:49 PM, Joseph, Matthew (EXP) matthew.jos...@lmco.com wrote: Hey James, ** ** Like I said the IPA user has read access at the domain level. He is also a member of the domain users group. ...I am by no means a windows person but I am

Re: [Freeipa-users] EXTERNAL: Re: Syncing with AD

2013-05-14 Thread Joseph, Matthew (EXP)
On the AD server open up regedit (start -- run -- regedit) and go to HKEY_LOCAL_MACHINE -- Software -- PasswordSync and just copy and paste your parameters that are set. Remove any sensitive information of course. In reference to the other email the PasswordSync log is under C:\Program Files\

Re: [Freeipa-users] Replicas

2013-05-14 Thread Andrew Tranquada
Awesome thank you. From: Rob Crittenden [rcrit...@redhat.com] Sent: Tuesday, May 14, 2013 10:05 AM To: Andrew Tranquada; freeipa-users@redhat.com Subject: Re: [Freeipa-users] Replicas Andrew Tranquada wrote: Hello everyone. Is there a limit to the

Re: [Freeipa-users] Replicas

2013-05-14 Thread Simo Sorce
- Original Message - Awesome thank you. note, we recommend no more than 4 replication agreements per master, so you should create a topology keeping this in mind (IE do not make 19 servers all have a replication agreement with 1). Simo.

Re: [Freeipa-users] Syncing with AD

2013-05-14 Thread Rich Megginson
On 05/14/2013 07:57 AM, Rob Crittenden wrote: James A wrote: Hello all, I have been playing with trying to set up synchronization between windows AD -- IPA following the instructions at

Re: [Freeipa-users] Replicas

2013-05-14 Thread Andrew Tranquada
understood thank you From: Simo Sorce [sso...@redhat.com] Sent: Tuesday, May 14, 2013 10:54 AM To: Andrew Tranquada Cc: Rob Crittenden; freeipa-users@redhat.com Subject: Re: [Freeipa-users] Replicas - Original Message - Awesome thank you. note,

Re: [Freeipa-users] Replicas

2013-05-14 Thread Christian Hernandez
Not sure if anyone noticed that the site is down http://www.freeipa.org/ Thank you, Christian Hernandez 1225 Los Angeles Street Glendale, CA 91204 Phone: 877-782-2737 ext. 4566 Fax: 818-265-3152 christi...@4over.com mailto:christi...@4over.com www.4over.com http://www.4over.com On Tue, May