[Freeipa-users] Joining realm failed: SASL Bind failed Local error (-2)

2014-03-07 Thread Rashard . Kelly
Hello all!! I cannot get a RHEL5.10 client to install! [root@hostname ~]# ipa-client-install --hostname=hostname.domain.com --no-ntp --ca-cert-file=/etc/ipa/ca.crt DNS domain 'doman.com' is not configured for automatic KDC address lookup. KDC address will be set to fixed value. Discovery was s

[Freeipa-users] Joining realm failed: SASL Bind failed Local error (-2)

2014-03-07 Thread Rashard . Kelly
Hello all!! I cannot get a RHEL5.10 client to install! [root@hostname ~]# ipa-client-install --hostname=hostname.domain.com --no-ntp --ca-cert-file=/etc/ipa/ca.crt DNS domain 'doman.com' is not configured for automatic KDC address lookup. KDC address will be set to fixed value. Discovery was s

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Nordgren, Bryce L -FS
> You *could* build a system that can work w/o synchronization, if you > carefully restrict what protocols and applications you use (think about > distributed filesystems) although you'd still need a local persistent map at > least. Backups and restore to other machines would need to be done > care

Re: [Freeipa-users] Using external KDC

2014-03-07 Thread Dmitri Pal
On 03/07/2014 05:26 PM, Trey Dockendorf wrote: On Thu, Mar 6, 2014 at 7:20 PM, Dmitri Pal wrote: On 03/05/2014 06:24 PM, Trey Dockendorf wrote: Correction from my email, the condition that sets if a 389DS user is proxied to pam_krb5 is the "pamFilter", sorry. On Wed, Mar 5, 2014 at 5:22 PM, T

Re: [Freeipa-users] Change user login name? (uid in LDAP)

2014-03-07 Thread Rob Crittenden
Will Sheldon wrote: Hello all :) We have an internal process that requires the renaming of users from time to time (user gets married, changes name). This requires changing the "login name” as it’s called in the GUI, (or uid in LDAP). There doesn’t currently appear to be any method for doing s

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Simo Sorce
On Fri, 2014-03-07 at 20:38 +, Nordgren, Bryce L -FS wrote: > > > >>UID/GID solution > > > >>https://fedorahosted.org/sssd/ticket/1715 > > > >> > > > >>Chaining access providers: > > > >>https://fedorahosted.org/sssd/ticket/1326 > > > >I'm not sure these two are enough for a thesis.. > > > > >

Re: [Freeipa-users] Using external KDC

2014-03-07 Thread Trey Dockendorf
On Thu, Mar 6, 2014 at 7:20 PM, Dmitri Pal wrote: > On 03/05/2014 06:24 PM, Trey Dockendorf wrote: >> >> Correction from my email, the condition that sets if a 389DS user is >> proxied to pam_krb5 is the "pamFilter", sorry. >> >> On Wed, Mar 5, 2014 at 5:22 PM, Trey Dockendorf >> wrote: >>> >>> On

[Freeipa-users] Change user login name? (uid in LDAP)

2014-03-07 Thread Will Sheldon
Hello all :) We have an internal process that requires the renaming of users from time to time (user gets married, changes name). This requires changing the "login name” as it’s called in the GUI, (or uid in LDAP). There doesn’t currently appear to be any method for doing so other than to del

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Nordgren, Bryce L -FS
> > >>UID/GID solution > > >>https://fedorahosted.org/sssd/ticket/1715 > > >> > > >>Chaining access providers: > > >>https://fedorahosted.org/sssd/ticket/1326 > > >I'm not sure these two are enough for a thesis.. > > > > I think at least the first one is. > > You change UID and/or GID on the serve

Re: [Freeipa-users] JSON interface

2014-03-07 Thread Petr Viktorin
On 03/07/2014 05:31 PM, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/07/2014 08:57 AM, Petr Viktorin wrote: On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] The ipa command line tools use RPC, but they use XML. If you run ipa -vv dnsrecord-add ... you can

Re: [Freeipa-users] JSON interface (Was: IPA DNS command line tools and ~)

2014-03-07 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/07/2014 08:57 AM, Petr Viktorin wrote: > On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] >> The ipa command line tools use RPC, but they use XML. If you run >> ipa -vv dnsrecord-add ... you can see the XML sent and received. >> There is a bi

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Jakub Hrozek
On Fri, Mar 07, 2014 at 11:04:45AM -0500, Dmitri Pal wrote: > On 03/07/2014 10:59 AM, Jakub Hrozek wrote: > >On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: > >>We need to check if those are still relevant > >>* > >>https://thesis-managementsystem.rhcloud.com/topic/show/179/java-loginm

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Alexander Bokovoy
On Fri, 07 Mar 2014, Dmitri Pal wrote: On 03/06/2014 10:55 AM, Petr Spacek wrote: On 6.3.2014 14:32, Petr Spacek wrote: now it is the right time to propose topics for theses in the next university year. I propose "[RFE] IPA should support and manage DNS sites" https://fedorahosted.org/freeip

Re: [Freeipa-users] JSON interface (Was: IPA DNS command line tools and ~)

2014-03-07 Thread Petr Viktorin
On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] The ipa command line tools use RPC, but they use XML. If you run ipa -vv dnsrecord-add ... you can see the XML sent and received. There is a bit of work converting from XML to JSON. e.g. testdomain.com.testdomain.com is ["testdomain.com.", "

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Dmitri Pal
On 03/07/2014 10:59 AM, Jakub Hrozek wrote: On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: We need to check if those are still relevant * https://thesis-managementsystem.rhcloud.com/topic/show/179/java-loginmodule-using-gssapi <- I heard JBoss guys are fixing it * We are talking to

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Dmitri Pal
On 03/07/2014 10:29 AM, artj...@free.fr wrote: Selon Petr Spacek: > On 7.3.2014 14:16,artj...@free.fr wrote: > > I want to install ipa server with a replica. The replica has 2 NICs : the > ipa > > server is connected on the first interface and all the clients are > connected on >

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Jakub Hrozek
On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: > We need to check if those are still relevant > * > https://thesis-managementsystem.rhcloud.com/topic/show/179/java-loginmodule-using-gssapi > <- I heard JBoss guys are fixing it > * We are talking to Mongo about this: > https://thesis-

[Freeipa-users] IPA DNS command line tools and JSON interface

2014-03-07 Thread Rich Megginson
tl;dr - A lot of detail about working with the IPA DNS command line interfaces and JSON interfaces. I'm working on integrating IPA with OpenStack Designate (DNSaaS), using the /ipa/json interface. I've had some Q&A with the IPA DNS developer (Thanks Petr Spacek!) that I thought would be usefu

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread artjazz
Selon Petr Spacek : > On 7.3.2014 14:16, artj...@free.fr wrote: > > I want to install ipa server with a replica. The replica has 2 NICs : the > ipa > > server is connected on the first interface and all the clients are > connected on > > the second interface. The two networks are completely separa

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Dmitri Pal
On 03/06/2014 10:55 AM, Petr Spacek wrote: On 6.3.2014 14:32, Petr Spacek wrote: now it is the right time to propose topics for theses in the next university year. I propose "[RFE] IPA should support and manage DNS sites" https://fedorahosted.org/freeipa/ticket/2008 It is rotting in the back

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Martin Kosek
On 03/07/2014 03:45 PM, Petr Spacek wrote: > On 7.3.2014 14:16, artj...@free.fr wrote: >> I want to install ipa server with a replica. The replica has 2 NICs : the ipa >> server is connected on the first interface and all the clients are connected >> on >> the second interface. The two networks ar

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Petr Spacek
On 7.3.2014 14:16, artj...@free.fr wrote: I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are completely separated, 2 subnets and not routed. I'm c

[Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread artjazz
Hi, I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are completely separated, 2 subnets and not routed. I'am wondering if this kind of configuratio

Re: [Freeipa-users] Patch for ipa-sam: ipa-server-trust-ad samba server valid users =@groupname

2014-03-07 Thread Jason Woods
Hi, On 6.3.2014 23:06, Alexander Bokovoy wrote: > For the record, it is ipa-adtrust-install --add-sids and the task is > called sidgen task. Absolutely. Sorry for the confusion - too late and swimming in the code had me mix up the terminology :-) All sorted for the bugzilla ticket. On 6.3.2014

Re: [Freeipa-users] incompatibility Operative systems

2014-03-07 Thread Martin Kosek
On 03/06/2014 05:09 PM, Juan Antonio wrote: > > > > > I have a conflict with a configuration of free-ipa. > The problem is an incompatibility between the client operating system with > fedora 19 and the ipa server with Red hat 6.4 operating system. > When executing the command: > > ipa add-

Re: [Freeipa-users] F19 -> F20 yum upgrade success report (WAS: Re: WARNING: Do not upgrade FreeIPA deployments to Fedora 20 final (yet))

2014-03-07 Thread Martin Kosek
On 03/03/2014 09:54 PM, Anthony Messina wrote: > On Saturday, March 01, 2014 04:18:11 AM Anthony Messina wrote: >> I've been waiting patiently for F20 to "settle" before upgrading my two >> VM installations of FreeIPA: >> >> ipa1 (original master) ipa2 (clone) >> >> I'm considering doing a "yum u

Re: [Freeipa-users] HTTP Service: STOPPED

2014-03-07 Thread Martin Kosek
On 03/04/2014 07:41 PM, Dmitri Pal wrote: > On 03/04/2014 01:28 PM, Shree wrote: >> Not sure what is going on? >> >> I get the following error. >> --- >> Starting httpd: (98)Address already in use: make_sock: could not bind to >> address [::]:443 >> --- >> >> I have a feelin

Re: [Freeipa-users] Patch for ipa-sam: ipa-server-trust-ad samba server valid users =@groupname

2014-03-07 Thread Petr Spacek
On 6.3.2014 23:06, Alexander Bokovoy wrote: On Thu, 06 Mar 2014, Jason Woods wrote: Hi all, I am quite aware that installing ipa-server-trust-ad and using the samba as a file server is as unsupported as one can get... but I really needed a Samba server integrated with IPA (damn Mac OS and Windo

Re: [Freeipa-users] winsync and new users

2014-03-07 Thread Martin Kosek
On 02/27/2014 11:11 PM, Alexander Bokovoy wrote: > On Thu, 27 Feb 2014, Michal Zacek wrote: >> Hi, >> >> I have successfully completed agreement between Windows and IPA and it >> works. When I create user in Windows, it's synchronized to IPA and when I >> change something on IPA for this user, i