Re: [Freeipa-users] change min and max lifetime of random password

2014-03-27 Thread barrykfl
Found a error today. when browse the cert serices ..is it realte to dog tag system ...how to restart ? Certificate operation cannot be completed: Unable to communicate with CMS (Not Found) ___ Freeipa-users mailing list Freeipa-users@redhat.com https://w

Re: [Freeipa-users] kerberized vsftpd login problem

2014-03-27 Thread Paul Robert Marino
I may be wrong on this but I don't remember an option in vsftps.conf to specify a keytab file which is a good indication that its not supported there is a kerberized ftp server in the krb5 applications rpm however its not widely used and is more likely than not lacking features and may have bugs.--

Re: [Freeipa-users] kerberized vsftpd login problem

2014-03-27 Thread Dmitri Pal
On 03/27/2014 04:47 PM, John Obaterspok wrote: 2014-03-23 19:45 GMT-04:00 Dmitri Pal 2014-03-23 9:01 GMT+01:00 John Obaterspok: Hello, How do I get vsftpd login to work with an existing ticket? I've added ftp as an identity service (ftp/ipaserver.my@my.lan) Is there anything else I need t

Re: [Freeipa-users] change min and max lifetime of random password

2014-03-27 Thread Dmitri Pal
On 03/27/2014 09:28 PM, Rob Crittenden wrote: Stijn De Weirdt wrote: hi alexander, ity would be good anyway to have a script that checks all hosts that have not enrolled yet how old the issued password is (even after expiration). very useful to spot the state of ongoing deployments and to spot

Re: [Freeipa-users] change min and max lifetime of random password

2014-03-27 Thread Rob Crittenden
Stijn De Weirdt wrote: hi alexander, ity would be good anyway to have a script that checks all hosts that have not enrolled yet how old the issued password is (even after expiration). very useful to spot the state of ongoing deployments and to spot problems. how can one obtain the creation time

Re: [Freeipa-users] change min and max lifetime of random password

2014-03-27 Thread Stijn De Weirdt
hi alexander, ity would be good anyway to have a script that checks all hosts that have not enrolled yet how old the issued password is (even after expiration). very useful to spot the state of ongoing deployments and to spot problems. how can one obtain the creation time of the password? fetch

Re: [Freeipa-users] writing IPA plugin

2014-03-27 Thread Stijn De Weirdt
hi rob, i'm trying to write my own FreeIPA plugin (for frontend cli usage), and so far so good, but i'm stuck on 2 issues: - is it possible to have the plugin use a dedicated or additional log file? i can manipulate the log manager, but maybe there's a proper API in freeipa for it; similar to th

Re: [Freeipa-users] kerberized vsftpd login problem

2014-03-27 Thread John Obaterspok
2014-03-23 19:45 GMT-04:00 Dmitri Pal > 2014-03-23 9:01 GMT+01:00 John Obaterspok : > > > > Hello, > > > > How do I get vsftpd login to work with an existing ticket? > > I've added ftp as an identity service (ftp/ipaserver.my@my.lan) > > Is there anything else I need to do to allow ftp login

Re: [Freeipa-users] writing IPA plugin

2014-03-27 Thread Rob Crittenden
Stijn De Weirdt wrote: hi all, i'm trying to write my own FreeIPA plugin (for frontend cli usage), and so far so good, but i'm stuck on 2 issues: - is it possible to have the plugin use a dedicated or additional log file? i can manipulate the log manager, but maybe there's a proper API in freeip

[Freeipa-users] writing IPA plugin

2014-03-27 Thread Stijn De Weirdt
hi all, i'm trying to write my own FreeIPA plugin (for frontend cli usage), and so far so good, but i'm stuck on 2 issues: - is it possible to have the plugin use a dedicated or additional log file? i can manipulate the log manager, but maybe there's a proper API in freeipa for it; similar to

Re: [Freeipa-users] HELP

2014-03-27 Thread Rob Crittenden
Todd Maugh wrote: My Master IPA server has been lost, My replica is still up and functioning. what is the best way to proceed? Do I rebuild my master and add it has a replica? how do I get my master back in line with my IPA env? the Master needs to be rebuilt from scratch red hat 6.5

Re: [Freeipa-users] HELP

2014-03-27 Thread Natxo Asenjo
On Thu, Mar 27, 2014 at 7:58 PM, Todd Maugh wrote: > My Master IPA server has been lost, > > > My replica is still up and functioning. > > > what is the best way to proceed? > > > Do I rebuild my master and add it has a replica? > > > how do I get my master back in line with my IPA env? > >

[Freeipa-users] HELP

2014-03-27 Thread Todd Maugh
My Master IPA server has been lost, My replica is still up and functioning. what is the best way to proceed? Do I rebuild my master and add it has a replica? how do I get my master back in line with my IPA env? the Master needs to be rebuilt from scratch red hat 6.5 latest version of IP

Re: [Freeipa-users] Try to re-import self sign cert fail after used 3rd paty cert

2014-03-27 Thread Rob Crittenden
barry...@gmail.com wrote: Dear all: I did change usin g 3rd party cert and now i tried to reimport the orginal self sign cert i backup before all in p12 format. Server-cert,p12 and ipacert.p12 i follow here and import successful. BUT it show error during restart httpd that say untrust sour

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa

2014-03-27 Thread Petr Spacek
On 27.3.2014 14:36, Sandor Juhasz wrote: Hello, what is the best practice to authenticate samba file sharing with freeipa as auth service. Either version 3 or 4 of samba is fine, as we are looking for this only for filesharing and not domain service. Our ipa service is hosted on CentOS 6.5. Th

[Freeipa-users] UNSUBSCRIBE

2014-03-27 Thread Viktor Mendes
--- LMAX Exchange, Yellow Building, 1A Nicholas Road, London W11 4AN http://www.LMAX.com/ 2013 #15 Fastest Growing Tech Company in the UK - Sunday Times Tech Track 100 2013 Best Margin Sector Platform - Profit & Loss Readers' Choice Awards 2013 Best FX Trading Platform - ECN/MTF - WSL Instit

[Freeipa-users] Try to re-import self sign cert fail after used 3rd paty cert

2014-03-27 Thread barrykfl
Dear all: I did change usin g 3rd party cert and now i tried to reimport the orginal self sign cert i backup before all in p12 format. Server-cert,p12 and ipacert.p12 i follow here and import successful. BUT it show error during restart httpd that say untrust source. even i added to "NSSEnf

Re: [Freeipa-users] IPA - Samba / Redmine / Disable Kerberos?

2014-03-27 Thread Martin Kosek
On 03/27/2014 03:09 PM, צביקה הרמתי wrote: > I have updated the HowTo with suggestions 1 & 2 (after checking them, of > course...) Good! > Regarding suggestion 3 - I'm not sure I understand it. > Isn't that the difference I wrote between "Basic" and "Full" configurations? Ah, I see - you are rig

Re: [Freeipa-users] Badly corrupted IPA

2014-03-27 Thread Bret Wortman
That worked like a champ. As always. Thanks, Rob. Bret On 03/27/2014 10:08 AM, Rob Crittenden wrote: Bret Wortman wrote: BTW, this also fails when using the web UI -- I can see the entry but not delete it. It sounds like you have a replication conflict entry. Try this search: $ ldapsearch

Re: [Freeipa-users] Badly corrupted IPA

2014-03-27 Thread Rob Crittenden
Bret Wortman wrote: BTW, this also fails when using the web UI -- I can see the entry but not delete it. It sounds like you have a replication conflict entry. Try this search: $ ldapsearch -Y GSSAPI -b cn=computers,cn=accounts,dc=example,dc=com fdqdn=myhost.example.com You'll probably get s

Re: [Freeipa-users] IPA - Samba / Redmine / Disable Kerberos?

2014-03-27 Thread צביקה הרמתי
I have updated the HowTo with suggestions 1 & 2 (after checking them, of course...) Regarding suggestion 3 - I'm not sure I understand it. Isn't that the difference I wrote between "Basic" and "Full" configurations? 2014-03-27 9:15 GMT+02:00 Martin Kosek : > Thanks! That helps. I have few sugge

Re: [Freeipa-users] Backup / Restore

2014-03-27 Thread Rob Crittenden
Innes, Duncan wrote: Martin, Did the backup/restore scripts reach more than experimental status? Looks like they were released in FreeIPA 3.2. The problem is few people have experimented with it. We need feedback to know whether it works or not. It worked for me in my contrived environment o

[Freeipa-users] authenticate samba 3 or 4 with freeipa

2014-03-27 Thread Sandor Juhasz
Hello, what is the best practice to authenticate samba file sharing with freeipa as auth service. Either version 3 or 4 of samba is fine, as we are looking for this only for filesharing and not domain service. Our ipa service is hosted on CentOS 6.5. The samba service is preferred to be hos

Re: [Freeipa-users] Backup / Restore

2014-03-27 Thread Innes, Duncan
Martin, Did the backup/restore scripts reach more than experimental status? Looks like they were released in FreeIPA 3.2. It's a problem for me that this kind of functionallity hasn't yet moved into RHEL. Backup/restore from some corporate use perspectives, cannot rely on system snapshotting. W

Re: [Freeipa-users] Badly corrupted IPA

2014-03-27 Thread Bret Wortman
BTW, this also fails when using the web UI -- I can see the entry but not delete it. On 03/27/2014 09:02 AM, Bret Wortman wrote: My IPA corruption continues and I'm afraid I'm going to have to recreate it from scratch since no reasonable me

[Freeipa-users] Badly corrupted IPA

2014-03-27 Thread Bret Wortman
My IPA corruption continues and I'm afraid I'm going to have to recreate it from scratch since no reasonable means of backup exists (which I understand -- that's not my complaint). Here's what I'm facing: # script -c 'ipa host-find mw79.damascusgrp.com' Scri

Re: [Freeipa-users] Backup / Restore

2014-03-27 Thread Martin Kosek
On 03/27/2014 01:09 PM, Andrew Holway wrote: > Hello, > > I am being tasked with setting up freeipa for an organisation. A > replica will be created but they also require a backup / restore > strategy. > > Has anyone implemented backup restore? Ideas? Recommendations? Dragons? > > Thanks, > > A

[Freeipa-users] Backup / Restore

2014-03-27 Thread Andrew Holway
Hello, I am being tasked with setting up freeipa for an organisation. A replica will be created but they also require a backup / restore strategy. Has anyone implemented backup restore? Ideas? Recommendations? Dragons? Thanks, Andrew ___ Freeipa-user

[Freeipa-users] Any coomand can extract the private of the freeipa domain

2014-03-27 Thread barrykfl
i want to extract the private key of the self sign cert ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Configuration backup (before Samba integration)

2014-03-27 Thread Natxo Asenjo
On Thu, Mar 27, 2014 at 7:37 AM, צביקה הרמתי wrote: > Hi. > I have a working network with IdM (FreeIPA). > I'd like to integrate it with Samba, according to > http://techslaves.org/2011/08/24/freeipa-and-samba-3-integration/ > > What's the recommended way to backup current IPA settings and > confi

Re: [Freeipa-users] IPA - Samba / Redmine / Disable Kerberos?

2014-03-27 Thread Martin Kosek
Thanks! That helps. I have few suggestions that would be great if you test: 1) Can we point Redmine to search users directly in the users container? I.e. cn=users,cn=accounts,dc=example,dc=com instead of just dc=example,dc=com. It will narrow down the LDAP search. 2) Can you search over LDAPS? Ju