Re: [Freeipa-users] IPA Query Tuning and a Recovery Question

2013-09-16 Thread Charlie Derwent
Hi Update on the errors kinit charlesd kinit: Generic error (see e-text) while getting initial credentials krb5kdc.log - LOOKING_UP_CLIENT: charl...@example.com for krbtg/ example@example.com, Server Error Starting the IPA service (dirsrv in particular) gives Failed to read data from

[Freeipa-users] Elliptic curves with the CA

2013-09-16 Thread mees virk
Hello all, Is it possible to setup the FreeIPA's CA use ECC cryptographic methods (ECDSA co) instead of RSA? That includes generating ECC CA certificates, and so on. I don't think I was given any option towards this in the default installation process. Would appreciate instructions

Re: [Freeipa-users] Incorrect user information

2013-09-16 Thread Jakub Hrozek
On Sat, Sep 14, 2013 at 01:11:36PM -0400, Brian Lindblom wrote: Of course, I would imagine that since the GECOS field is set upon account creation based on the values provided for first and last name, and since GECOS is not a provided field in the UI for user attributes, that GECOS should be

[Freeipa-users] remove me from list

2013-09-16 Thread Ainsworth, Thomas
please remove* tainswo...@vsi-corp.com* from the distro email list. Thanks, Tom Ainsworth ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] remove me from list

2013-09-16 Thread Petr Viktorin
On 09/16/2013 12:43 PM, Ainsworth, Thomas wrote: please remove tainswo...@vsi-corp.com from the distro email list. Thanks, Tom Ainsworth Hello, This list is managed by Mailman. You can unsubscribe yourself at https://www.redhat.com/mailman/listinfo/freeipa-users (bottom of the page), or by

Re: [Freeipa-users] Date of last access attribute

2013-09-16 Thread Rob Crittenden
Dmitri Pal wrote: On 09/13/2013 01:46 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-09-13 at 10:58 -0400, Rob Crittenden wrote: Dmitri Pal wrote: On 09/13/2013 05:16 AM, Marina Moreda wrote: Hi all, I need to add in my LDAP an attribute to save the date of last access to mail

Re: [Freeipa-users] Date of last access attribute

2013-09-16 Thread Simo Sorce
On Mon, 2013-09-16 at 08:44 -0400, Rob Crittenden wrote: Dmitri Pal wrote: On 09/13/2013 01:46 PM, Rob Crittenden wrote: Simo Sorce wrote: On Fri, 2013-09-13 at 10:58 -0400, Rob Crittenden wrote: Dmitri Pal wrote: On 09/13/2013 05:16 AM, Marina Moreda wrote: Hi all, I need to add

Re: [Freeipa-users] IPA Query Tuning and a Recovery Question

2013-09-16 Thread Rich Megginson
On 09/16/2013 03:21 AM, Charlie Derwent wrote: Hi Update on the errors kinit charlesd kinit: Generic error (see e-text) while getting initial credentials krb5kdc.log - LOOKING_UP_CLIENT: charl...@example.com mailto:charl...@example.com for krbtg/example@example.com

Re: [Freeipa-users] Incorrect user information

2013-09-16 Thread cbul...@gmail.com
Brian, Simo and Jakub, Thanks so much for your help. I will create a ticket for this problem. Thanks! On 09/16/2013 05:31 AM, Jakub Hrozek wrote: On Sat, Sep 14, 2013 at 01:11:36PM -0400, Brian Lindblom wrote: Of course, I would imagine that since the GECOS field is set upon account

Re: [Freeipa-users] IPA Query Tuning and a Recovery Question

2013-09-16 Thread Rob Crittenden
Rich Megginson wrote: On 09/16/2013 03:21 AM, Charlie Derwent wrote: Hi Update on the errors kinit charlesd kinit: Generic error (see e-text) while getting initial credentials krb5kdc.log - LOOKING_UP_CLIENT: charl...@example.com mailto:charl...@example.com for krbtg/example@example.com

[Freeipa-users] Timeout (?) issues

2013-09-16 Thread KodaK
Yet another AIX related problem: The AIX LDAP client is called secldapclntd (sure, they could make it more awkward, but the budget ran out.) I'm running into the issue detailed here: http://www-01.ibm.com/support/docview.wss?uid=isg1IV11344 If an LDAP server fails to answer an LDAP query,

[Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Ondrej Valousek
Hi list, Is there any howto describing Firefox (or IE, if possible) authenticating against Apache web server using GSSAPI/Kerberos? Both client server in the same IPA domain. Ideally I would like to know FF and Apache setup + compatibility info (i.e. does IE + IIS use the same thing or not)

Re: [Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Ondrej Valousek
Thanks, Is the article about http principals for apache still relevant? I would guess that with gss-proxy (F19) it is much simpler. Ondrej Odesláno ze Samsung Mobile Původní zpráva Od: Christian Horn ch...@fluxcoil.net Datum: Komu: freeipa-users@redhat.com Předmět: Re:

Re: [Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Simo Sorce
On Mon, 2013-09-16 at 18:35 +, Ondrej Valousek wrote: Thanks, I hoped that with gssproxy I could use a single central /etc/krb5.keytab (with all necessary principals) for nfs, apache, dhcpd,... and not worrying about file permissions. The beauty would be saved work with copying principals

Re: [Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Ondrej Valousek
Thanks, I hoped that with gssproxy I could use a single central /etc/krb5.keytab (with all necessary principals) for nfs, apache, dhcpd,... and not worrying about file permissions. The beauty would be saved work with copying principals to separate files. Is it true? Ondrej Odesláno ze Samsung

Re: [Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Simo Sorce
On Mon, 2013-09-16 at 17:04 +, Ondrej Valousek wrote: Thanks, Is the article about http principals for apache still relevant? I would guess that with gss-proxy (F19) it is much simpler. You still need a princiapl and a keytab yes. Here instructions if you want to use iot with GSS-Proxy:

Re: [Freeipa-users] Elliptic curves with the CA

2013-09-16 Thread Simo Sorce
On Mon, 2013-09-16 at 13:05 +0300, mees virk wrote: Hello all, Is it possible to setup the FreeIPA's CA use ECC cryptographic methods (ECDSA co) instead of RSA? That includes generating ECC CA certificates, and so on. At the moment our code (dogtag and nss) does not support ECC crypto. I

Re: [Freeipa-users] FreeIPA integrating samba4 + AD

2013-09-16 Thread Christovam Paynes Silva
2013/9/12 Dmitri Pal d...@redhat.com On 09/11/2013 11:27 PM, Christovam Paynes Silva wrote: 2013/9/11 Dmitri Pal d...@redhat.com On 09/11/2013 04:02 PM, Christovam Paynes Silva wrote: It is a pity! Thank you! I did not get a feeling that we understand the whole picture

Re: [Freeipa-users] IE or Firefox Apache Kerberos authentication

2013-09-16 Thread Christian Horn
Hi, On Mon, Sep 16, 2013 at 04:04:49PM +, Ondrej Valousek wrote: Is there any howto describing Firefox (or IE, if possible) authenticating against Apache web server using GSSAPI/Kerberos? Both client server in the same IPA domain. Ideally I would like to know FF and Apache setup +

Re: [Freeipa-users] Elliptic curves with the CA

2013-09-16 Thread Dmitri Pal
On 09/16/2013 06:05 AM, mees virk wrote: Hello all, Is it possible to setup the FreeIPA's CA use ECC cryptographic methods (ECDSA co) instead of RSA? That includes generating ECC CA certificates, and so on. I don't think I was given any option towards this in the default installation

Re: [Freeipa-users] Timeout (?) issues

2013-09-16 Thread Dmitri Pal
On 09/16/2013 12:02 PM, KodaK wrote: Yet another AIX related problem: The AIX LDAP client is called secldapclntd (sure, they could make it more awkward, but the budget ran out.) I'm running into the issue detailed here: http://www-01.ibm.com/support/docview.wss?uid=isg1IV11344 If an LDAP