[Freeipa-users] Free-IPA in an AWS Base Image

2014-02-10 Thread Steve Severance
I want to create an AWS AMI that when it starts up will register itself with a Free-IPA instance. The issue I have run into so far is every instance when it starts up uses the original instances hostname. What do I need to do to have free-ipa work in a DHCP environment like this? __

[Freeipa-users] Upgrade of Free ipa in CENTOS 6

2014-02-10 Thread barrykfl
Dear all: Any one have exp to upgrade ipa-server-3.0.0-26.el6_4.4.x86_64 to ipa-server-3.0.0-37.el6_4.4.x86_64 ( jus t minor patch/upgrade it think ) Is it just yum install then ok ??? i notice some official document but they are 3.3 free ipa of fedora ...just yum / run the rpm and not necessary

Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-10 Thread Shree
Lucas (sorry my previous email may have got sent improperly edited. My typical command looks like this (domain name changed due to disclosure reasons) # ipa-client-install --domain=mydomain.com --server=ldap2.mydomain.com  --hostname=test500.mydomain.com -d master = ldap.mydomain.com replica

Re: [Freeipa-users] CentOS 6.5 client install failing

2014-02-10 Thread Dave Jablonski
Unfortunately no. I don't have access to the server. On Feb 10, 2014 2:36 PM, "Dmitri Pal" wrote: > On 02/08/2014 08:48 AM, Rob Crittenden wrote: > >> Dave Jablonski wrote: >> >>> FreeIPA Server: Fedora 16, freeipa 2.1.4 >>> Latest CentOS 6.5 client >>> >>> When running: >>> >>> ipa-client-inst

Re: [Freeipa-users] ipa-client-install does not seem to like the ipa's ntp

2014-02-10 Thread Mauricio Tavares
On Mon, Feb 10, 2014 at 3:40 PM, Dmitri Pal wrote: > On 02/09/2014 09:52 PM, Mauricio Tavares wrote: >> >> On Sun, Feb 9, 2014 at 9:07 PM, Steve Dainard >> wrote: >>> >>> I've noticed if ntpd is already running on the client when you run the >>> ipa-client-install, you will get that error. I'm gue

Re: [Freeipa-users] ipa-client-install does not seem to like the ipa's ntp

2014-02-10 Thread Dmitri Pal
On 02/09/2014 09:52 PM, Mauricio Tavares wrote: On Sun, Feb 9, 2014 at 9:07 PM, Steve Dainard wrote: I've noticed if ntpd is already running on the client when you run the ipa-client-install, you will get that error. I'm guessing its using ntpdate IP ADDRESS to sync time, and cannot do so when

Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-10 Thread Dmitri Pal
On 02/09/2014 07:44 AM, Rob Crittenden wrote: Shree wrote: Lukas Perhaps I should explain the design a bit and see if FreeIPA even supports this.Our replica is in a separate network and all the appropriate ports are opened between the master and the replica. The "replica" got created successfull

Re: [Freeipa-users] CentOS 6.5 client install failing

2014-02-10 Thread Dmitri Pal
On 02/08/2014 08:48 AM, Rob Crittenden wrote: Dave Jablonski wrote: FreeIPA Server: Fedora 16, freeipa 2.1.4 Latest CentOS 6.5 client When running: ipa-client-install --mkhomedir --enable-dns-updates The install fails with: trying https:///ipa/xml Forwarding 'env' to server u'https:///ipa/x

Re: [Freeipa-users] RHEL 7 beta trust - slow domain user authentication to Linux hosts

2014-02-10 Thread Steve Dainard
Sure: (Mon Feb 10 10:14:58 2014) [[sssd[krb5_child[9879 [main] (0x0400): krb5_child started. (Mon Feb 10 10:14:58 2014) [[sssd[krb5_child[9879 [unpack_buffer] (0x1000): total buffer size: [125] (Mon Feb 10 10:14:58 2014) [[sssd[krb5_child[9879 [unpack_buffer] (0x0100): cmd [241] uid [7

Re: [Freeipa-users] RHEL 7 beta trust - slow domain user authentication to Linux hosts

2014-02-10 Thread Sumit Bose
On Mon, Feb 10, 2014 at 10:55:33AM -0500, Steve Dainard wrote: > I've setup RHEL 7 beta IPA with a trust to an AD domain. > > When I use an AD domain login it takes roughly 9-14 seconds to get to a > shell after entering a password. Is there any way to speed this process up? > I thought supplement

Re: [Freeipa-users] export user info

2014-02-10 Thread Martin Kosek
On 02/10/2014 12:01 PM, barry...@gmail.com wrote: > Dear all: > > Which command can export /show all users a/c and info? better in table > format . > > Regards > > Barry $ ipa user-find Or in JSON-RPC command: {"method":"user_find","params":[[""],{"sizelimit":0}]} Martin ___

[Freeipa-users] export user info

2014-02-10 Thread barrykfl
Dear all: Which command can export /show all users a/c and info? better in table format . Regards Barry ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Clarifying Pilsner/Beer Exchange/Deferred Trac milestones

2014-02-10 Thread Martin Kosek
Hello, I would to follow up on a core devel team discussion we had last week. Part of it were changes to milestones as we currently use it. 1) "Pilsner/Beer Exchange/Deferred Currently, we have 3 levels of deferring feature request and bug fix tickets to later releases: a) Pilsner barrel: when p