[Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
hi, The systems are uptodate F19 KVM guests. I'm trying to login the web ui with no success: Your session has expired. Please re-login. To login with Kerberos, please make sure you have valid tickets (obtainable via kinit) and configured http://ipa31.bph.cxn/ipa/config/unauthorized.html the

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Alexander Bokovoy
On Tue, 05 Nov 2013, Tamas Papp wrote: hi, The systems are uptodate F19 KVM guests. I'm trying to login the web ui with no success: Your session has expired. Please re-login. To login with Kerberos, please make sure you have valid tickets (obtainable via kinit) and configured

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rich Megginson
On 11/05/2013 06:04 AM, Alexander Bokovoy wrote: On Tue, 05 Nov 2013, Tamas Papp wrote: hi, The systems are uptodate F19 KVM guests. I'm trying to login the web ui with no success: Your session has expired. Please re-login. To login with Kerberos, please make sure you have valid tickets

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rich Megginson
On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication to proceed despite excessive clock skew - what is your 389-ds-base version and platform?

[Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread EP
Hi, I'm pushing to get password and user synchronization from AD to FreeIPA at the company I work for. Our windows administrators are very nervous about installing the PassSync service on their AD-controllers, and have asked me to provide a reference contact, meaning someone they could ask

Re: [Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread Rich Megginson
On 11/05/2013 08:05 AM, EP wrote: Hi, I'm pushing to get password and user synchronization from AD to FreeIPA at the company I work for. Our windows administrators are very nervous about installing the PassSync service on their AD-controllers, and have asked me to provide a reference

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication to proceed despite excessive clock skew - what is your 389-ds-base version and platform? What is the clock skewed? The date and

[Freeipa-users] Got a minute to help a n00b w/IPA server on CentOS 6.4?

2013-11-05 Thread Pablo Carranza
Greetings! I only recently stumbled upon FreeIPA and am salivating at the mouth (sorry for the gross mental picture!) in excitement. Twice now, I've tried to install IPA server on a Centos 6.4 VPS at DigitalOceanhttps://www.digitalocean.com/price-comparison-chart/?refcode=47494ed444e1; only to

[Freeipa-users] FreeIPA and AD, pass sync, different cn

2013-11-05 Thread Антон Костенко
Hello everyone! Please, explain me a one thing. I have a that kind situation: In our company we have two domains - AD for everyone and FreeIPA for developers and servers. They have a different dn. Freeipa have dn=privatedomain,dn=loc, AD have dn=publicdomain,dn=com. But we have a same users login.

Re: [Freeipa-users] FreeIPA and AD, pass sync, different cn

2013-11-05 Thread Rich Megginson
On 11/05/2013 08:29 AM, Антон Костенко wrote: Hello everyone! Please, explain me a one thing. I have a that kind situation: In our company we have two domains - AD for everyone and FreeIPA for developers and servers. They have a different dn. Freeipa have dn=privatedomain,dn=loc, AD have

Re: [Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread EP
Hi, They had a phone session with Red Hat first line support, so they are feeling quite safe with the solution itself (in theory). What they're after now is more or less some end user testimonials... perhaps a few of you PassSync users out there could write a couple of lines about your

Re: [Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread Rich Megginson
On 11/05/2013 08:45 AM, EP wrote: Hi, They had a phone session with Red Hat first line support, so they are feeling quite safe with the solution itself (in theory). What they're after now is more or less some end user testimonials... perhaps a few of you PassSync users out there could write

Re: [Freeipa-users] FreeIPA and AD, pass sync, different cn

2013-11-05 Thread Simo Sorce
On Tue, 2013-11-05 at 08:36 -0700, Rich Megginson wrote: On 11/05/2013 08:29 AM, Антон Костенко wrote: Question: Can I sync password between AD and FreeIPA by password synchronization tool? Yes. To give a little bit more guidance, you may read on it here:

Re: [Freeipa-users] Got a minute to help a n00b w/IPA server on CentOS 6.4?

2013-11-05 Thread Rob Crittenden
Pablo Carranza wrote: Greetings! I only recently stumbled upon FreeIPA and am salivating at the mouth (sorry for the gross mental picture!) in excitement. Twice now, I've tried to install IPA server on a Centos 6.4 VPS at DigitalOcean

Re: [Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread Dmitri Pal
On 11/05/2013 10:45 AM, EP wrote: Hi, They had a phone session with Red Hat first line support, so they are feeling quite safe with the solution itself (in theory). What they're after now is more or less some end user testimonials... perhaps a few of you PassSync users out there could

Re: [Freeipa-users] Requesting contact with users running PassSync AD - FreeIPA

2013-11-05 Thread EP
Thanks for your answers so far. A question about cross realm trusts though: This requires the AD servers to be available when doing a login via FreeIPA, right? Or is FreeIPA caching information from AD? We don't want Linux logins to be dependent on a windows server being available, that won't

[Freeipa-users] Revisiting ILO

2013-11-05 Thread KodaK
I'm attempting to get HP ILO authenticating against IPA again. I've configured the user context in ILO as: cn=users,cn=accounts,dc=unix,dc=magellanhealth,dc=com When ILO tries to connect, it sends the string: CN=jebalicki,cn=users,cn=accounts,dc=unix,dc=magellanhealth,dc=com Which, of course,

Re: [Freeipa-users] Revisiting ILO

2013-11-05 Thread KodaK
If I use the whole connection string: uid=jebalicki,cn=users,cn=accounts,dc=unix,dc=magellanhealth,dc=com I can authenticate. On Tue, Nov 5, 2013 at 1:40 PM, KodaK sako...@gmail.com wrote: I'm attempting to get HP ILO authenticating against IPA again. I've configured the user context in

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication to proceed despite excessive clock skew -

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 09:09 PM, Rob Crittenden wrote: Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rich Megginson
On 11/05/2013 01:03 PM, Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rob Crittenden
Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication to proceed despite

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 09:20 PM, Tamas Papp wrote: On 11/05/2013 09:09 PM, Rob Crittenden wrote: Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 09:25 PM, Rich Megginson wrote: On 11/05/2013 01:03 PM, Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Tamas Papp
On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: https://fedorahosted.org/389/ticket/47516 This has been fixed upstream and in some releases - to allow replication to proceed despite excessive clock skew -

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rich Megginson
On 11/05/2013 04:23 PM, Tamas Papp wrote: On 11/05/2013 09:25 PM, Rich Megginson wrote: On 11/05/2013 01:03 PM, Tamas Papp wrote: On 11/05/2013 03:58 PM, Rich Megginson wrote: On 11/05/2013 07:53 AM, Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote:

Re: [Freeipa-users] ui login error and questions about replication

2013-11-05 Thread Rob Crittenden
Tamas Papp wrote: On 11/05/2013 03:17 PM, Rich Megginson wrote: 2. What is the difference between 'primary' and 'secondary'. What does happen, if the primary machine gets destroyed? In IPA all replicas are the same, they only would differ by the paths they sync with each other and by

[Freeipa-users] External CA

2013-11-05 Thread William Leese
Hi, Trying to install freeIPA and have it a sub-ca of an existing one. Sadly I'm not getting anywhere. The version I have installed: ipa-server-3.0.0-26.el6_4.4.x86_64 This is what I run: ipa-server-install -U -a testtest -p testtest --external_cert_file=/root/server.pem

Re: [Freeipa-users] reverse DNS and replicas

2013-11-05 Thread Brett Foster
Of course, as soon as I send this I notice the --no-host-dns. Figures. On Tue, Nov 5, 2013 at 11:33 PM, Brett Foster fost...@edgeandvertex.orgwrote: Alright -- I'm stumped. What is the motivation for requiring reverse lookups for replicas? Is there a way to turn the check off? Others ideas?