Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-20 Thread Shree
Dmitri, Rob, Lucas et al. Thank you for all your help and patience and pointing me to the right direction. I was able to fix  most of my issues. My setup is a little complex where I am trying to have a master and the replica in different networks and are in sync + each of them is serving a diffe

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Sigbjorn Lie
On 20/02/14 23:08, Rob Crittenden wrote: Sigbjorn Lie wrote: On 20/02/14 21:38, Rob Crittenden wrote: I am surprised too. I dumped the PKI CA certificate from /etc/pki/nssdb before and after I updated it into text files, and diff'ed them. No differences was reported. I can't think of a rea

Re: [Freeipa-users] Issues creating trust with AD.

2014-02-20 Thread Genadi Postrilko
Update: For some reason the AD server has rebooted himself. After the reboot i couldn't preform kinit with AD users. I found a bugzilla that describes the symptoms that i experienced : https://bugzilla.redhat.com/show_bug.cgi?id=878564 Not sure if it is the same bug - the bugzilla reports bug in sa

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Rob Crittenden
Sigbjorn Lie wrote: On 20/02/14 21:38, Rob Crittenden wrote: I am surprised too. I dumped the PKI CA certificate from /etc/pki/nssdb before and after I updated it into text files, and diff'ed them. No differences was reported. I can't think of a reason it would be using the sqlite database at

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Sigbjorn Lie
On 20/02/14 21:38, Rob Crittenden wrote: Sigbjorn Lie wrote: On 20/02/14 21:19, Rob Crittenden wrote: Sigbjorn Lie wrote: On Wed, February 19, 2014 13:45, Sigbjorn Lie wrote: On Tue, February 18, 2014 20:45, Rob Crittenden wrote: Sigbjorn Lie wrote: On what machine are you trying

Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-20 Thread Dmitri Pal
On 02/20/2014 02:58 PM, Shree wrote: Can you help me figure out, below is some info on the existing working configuration one one of the clients 1)Sudo version 1.7.4p5 2)[root@test500 ~]# sssd --version 1.9.2 3)These are the uncommented lines in /etc/sssd/sssd.conf [sssd] config_file_version =

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Rob Crittenden
Sigbjorn Lie wrote: On 20/02/14 21:19, Rob Crittenden wrote: Sigbjorn Lie wrote: On Wed, February 19, 2014 13:45, Sigbjorn Lie wrote: On Tue, February 18, 2014 20:45, Rob Crittenden wrote: Sigbjorn Lie wrote: On what machine are you trying to use the ipa tool? Is it one of the mas

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Sigbjorn Lie
On 20/02/14 21:19, Rob Crittenden wrote: Sigbjorn Lie wrote: On Wed, February 19, 2014 13:45, Sigbjorn Lie wrote: On Tue, February 18, 2014 20:45, Rob Crittenden wrote: Sigbjorn Lie wrote: On what machine are you trying to use the ipa tool? Is it one of the masters, all of them, en

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Rob Crittenden
Sigbjorn Lie wrote: On Wed, February 19, 2014 13:45, Sigbjorn Lie wrote: On Tue, February 18, 2014 20:45, Rob Crittenden wrote: Sigbjorn Lie wrote: On what machine are you trying to use the ipa tool? Is it one of the masters, all of them, enrolled clients? It's the same error mes

Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-20 Thread Shree
Can you help me figure out, below is some info on the existing working configuration one one of the clients 1)Sudo version 1.7.4p5 2)[root@test500 ~]# sssd --version 1.9.2 3)These are the uncommented lines in /etc/sssd/sssd.conf [sssd] config_file_version = 2 services = nss, pam domains = mydoma

Re: [Freeipa-users] Certificate system unavailable

2014-02-20 Thread Sigbjorn Lie
On Wed, February 19, 2014 13:45, Sigbjorn Lie wrote: > > > On Tue, February 18, 2014 20:45, Rob Crittenden wrote: > >> Sigbjorn Lie wrote: >> >> On what machine are you trying to use the ipa tool? Is it one of the masters, all of them, enrolled clients? >>> >>> It's the same erro

[Freeipa-users] Installing client on Amazon Linux EC2

2014-02-20 Thread Hendri Morris
I want have IPA clients that are on Amazon Linux (CentOS Derivative). I will be using CentOS for the IPA server but I can't seem to get the IPA client to install on Amazon Linux . The packages conflict and send me on to "dependency hell" Does anyone have experience installing FreeIPA or IPA clie

Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-02-20 Thread Dmitri Pal
On 02/19/2014 06:52 PM, Shree wrote: Rob You were right. After upgrading the client to the ipa-client-3.0.0-37.el6.x86_64 version I started seeing a warning during the client install that went something like = Autodiscovery of servers for failover cannot work with this configur

Re: [Freeipa-users] Setting up samba with IPA

2014-02-20 Thread Dmitri Pal
On 02/20/2014 07:25 AM, Johan Petersson wrote: I do not have access to my lab environment at the moment to help you completely but this should put you on the right track i hope. This config enables Home Directories shared through NFS to IPA Linux Clients to also be accessible to Windows Client

Re: [Freeipa-users] About Windows client

2014-02-20 Thread Alexander Bokovoy
On Thu, 20 Feb 2014, Dmitri Pal wrote: On 02/20/2014 05:55 AM, Alexander Bokovoy wrote: On Thu, 20 Feb 2014, Jan Pazdziora wrote: On Wed, Feb 19, 2014 at 05:23:15PM -0500, Dmitri Pal wrote: I want to summarize our position regarding joining Windows systems into IPA. 1) If you already have

Re: [Freeipa-users] About Windows client

2014-02-20 Thread Dmitri Pal
On 02/20/2014 05:55 AM, Alexander Bokovoy wrote: On Thu, 20 Feb 2014, Jan Pazdziora wrote: On Wed, Feb 19, 2014 at 05:23:15PM -0500, Dmitri Pal wrote: I want to summarize our position regarding joining Windows systems into IPA. 1) If you already have AD we recommend using this system with A

[Freeipa-users] Unofficial SSSD 1.9.x repository for RHEL 5

2014-02-20 Thread Stephen Gallagher
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Due to popular request, I am offering a completely unofficial and unsupported repository of the latest 1.9.x LTM bits for RHEL 5 and derivatives. The latest official version supported by the distribution is 1.5.x. These packages are built from the ups

Re: [Freeipa-users] Allow freeipa send password to user

2014-02-20 Thread Simo Sorce
On Thu, 2014-02-20 at 11:29 +0100, Jan Pazdziora wrote: > On Tue, Feb 18, 2014 at 04:44:30PM -0500, Dmitri Pal wrote: > > On 02/17/2014 10:51 PM, barry...@gmail.com wrote: > > >Is it possible to set allow password to send to user after user request. > > > > > >I used one of the self password servic

Re: [Freeipa-users] Setting up samba with IPA

2014-02-20 Thread Johan Petersson
I do not have access to my lab environment at the moment to help you completely but this should put you on the right track i hope. This config enables Home Directories shared through NFS to IPA Linux Clients to also be accessible to Windows Clients through SAMBA when having a sync configuration

Re: [Freeipa-users] Allow freeipa send password to user

2014-02-20 Thread Alexander Bokovoy
On Thu, 20 Feb 2014, Jan Pazdziora wrote: On Tue, Feb 18, 2014 at 04:44:30PM -0500, Dmitri Pal wrote: On 02/17/2014 10:51 PM, barry...@gmail.com wrote: >Is it possible to set allow password to send to user after user request. > >I used one of the self password service pwm but it seem it is not >

Re: [Freeipa-users] About Windows client

2014-02-20 Thread Alexander Bokovoy
On Thu, 20 Feb 2014, Jan Pazdziora wrote: On Wed, Feb 19, 2014 at 05:23:15PM -0500, Dmitri Pal wrote: I want to summarize our position regarding joining Windows systems into IPA. 1) If you already have AD we recommend using this system with AD and using trusts between AD and IPA. 2) If you do

Re: [Freeipa-users] About Windows client

2014-02-20 Thread Jan Pazdziora
On Wed, Feb 19, 2014 at 05:23:15PM -0500, Dmitri Pal wrote: > > I want to summarize our position regarding joining Windows systems into IPA. > > 1) If you already have AD we recommend using this system with AD and > using trusts between AD and IPA. > 2) If you do not have AD then use Samba 4 inst

Re: [Freeipa-users] Allow freeipa send password to user

2014-02-20 Thread Jan Pazdziora
On Tue, Feb 18, 2014 at 04:44:30PM -0500, Dmitri Pal wrote: > On 02/17/2014 10:51 PM, barry...@gmail.com wrote: > >Is it possible to set allow password to send to user after user request. > > > >I used one of the self password service pwm but it seem it is not > >compatible to retriveal of password

Re: [Freeipa-users] Free-IPA in an AWS Base Image

2014-02-20 Thread Jan Pazdziora
On Mon, Feb 10, 2014 at 10:02:53PM -0800, Steve Severance wrote: > I want to create an AWS AMI that when it starts up will register itself > with a Free-IPA instance. The issue I have run into so far is every > instance when it starts up uses the original instances hostname. What do I > need to do

Re: [Freeipa-users] Unexpected error at the end of ipa-replica-install

2014-02-20 Thread Martin Kosek
On 02/19/2014 08:47 PM, Shree wrote: > Everything seems to be going well for all the 17 of 17 steps and then this > > [15/17]: configure clone certificate renewals > [16/17]: configure Server-Cert certificate renewal > [17/17]: Configure HTTP to proxy connections > Done configuring certificat