Re: [Freeipa-users] Have existing wildcard SSL from RapidSSL how to implement?

2014-05-19 Thread Martin Kosek
On 05/17/2014 04:22 AM, Chris Whittle wrote: I have an existing key and crt that has be successfully installed on other subdomain servers... Where is the best place to start? To start what? :-) Without knowing what you want to achieve, I would like to point you to our training presentation

Re: [Freeipa-users] Theming FreeIPA

2014-05-19 Thread Martin Kosek
On 05/17/2014 04:27 PM, Christopher Swingler wrote: Short and to the point, but I have the same question. :) On May 16, 2014, at 9:08 PM, Chris Whittle cwhi...@gmail.com wrote: Is there a doc anywhere? CC-ing Petr Vobornik to help with that. You can already achieve some theming with

Re: [Freeipa-users] Have existing wildcard SSL from RapidSSL how to implement?

2014-05-19 Thread Chris Whittle
All I am trying to fix right now is so when the user comes to the web ui they have a valid cert. On May 19, 2014 2:01 AM, Martin Kosek mko...@redhat.com wrote: On 05/17/2014 04:22 AM, Chris Whittle wrote: I have an existing key and crt that has be successfully installed on other subdomain

[Freeipa-users] IPA down hard. Kerberos?

2014-05-19 Thread Bret Wortman
Happy Monday to me -- I came in this morning to find all 3 of my IPA replicas are down. When I tried to start one of them, I got this: [root@ipa1 ~]# ipactl start Existing service file detected! Assuming stale, cleaning and proceeding Starting Directory Service Starting krb5kdc Service Job for

Re: [Freeipa-users] AD trust showing offline after reboot

2014-05-19 Thread Supratik Goswami
Hi Let me start from the beginning once again. Let me explain you what steps I followed during the setup. I am setting up the environment in Amazon AWS, both Windows AD server and Linux IPA configured in EC2. For configuring Windows 2008 I selected

Re: [Freeipa-users] AD trust showing offline after reboot

2014-05-19 Thread Sumit Bose
On Mon, May 19, 2014 at 04:29:24PM +0530, Supratik Goswami wrote: Hi Let me start from the beginning once again. Let me explain you what steps I followed during the setup. I am setting up the environment in Amazon AWS, both Windows AD server and Linux IPA configured in EC2. For

Re: [Freeipa-users] Theming FreeIPA

2014-05-19 Thread Petr Vobornik
On 19.5.2014 09:05, Martin Kosek wrote: On 05/17/2014 04:27 PM, Christopher Swingler wrote: Short and to the point, but I have the same question. :) On May 16, 2014, at 9:08 PM, Chris Whittle cwhi...@gmail.com wrote: Is there a doc anywhere? CC-ing Petr Vobornik to help with that. You can

Re: [Freeipa-users] Theming FreeIPA

2014-05-19 Thread Chris Whittle
I'm mostly interested in making it responsive and logos, colors and such. So it sounds like I'll be covered in 4 On May 19, 2014 6:30 AM, Petr Vobornik pvobo...@redhat.com wrote: On 19.5.2014 09:05, Martin Kosek wrote: On 05/17/2014 04:27 PM, Christopher Swingler wrote: Short and to the

Re: [Freeipa-users] AD trust showing offline after reboot

2014-05-19 Thread Supratik Goswami
Initially after configuring the setup I rebooted once and I was thinking that it worked before the reboot but unfortunately it didn't work the first time itself. Still failing after running the commands. [root@ipaserver ~]# net conf setparm global client min protocol smb2_02 [root@ipaserver ~]#

Re: [Freeipa-users] Have existing wildcard SSL from RapidSSL how to implement?

2014-05-19 Thread Simo Sorce
On Sun, 2014-05-18 at 20:58 -0500, Chris Whittle wrote: Actually is this it? http://www.freeipa.org/page/Using_3rd_part_certificates_for_HTTP/LDAP I think so, yeah. Simo. On Sun, May 18, 2014 at 8:31 PM, Chris Whittle cwhi...@gmail.com wrote: Thanks Simo, I'm finding a lot of posts on

Re: [Freeipa-users] Free IPA and Google Apps

2014-05-19 Thread Simo Sorce
On Sun, 2014-05-18 at 20:40 -0500, Chris Whittle wrote: Anything new on ipsilon? I released 0.2.3: https://fedorahosted.org/ipsilon/ It is still a bit rough on the edges, but can be used. Simo. On Fri, Apr 25, 2014 at 9:18 AM, Simo Sorce s...@redhat.com wrote: On Fri, 2014-04-25 at 10:00

Re: [Freeipa-users] DNS SOA Records

2014-05-19 Thread Loris Santamaria
El mar, 13-05-2014 a las 14:12 -0400, Bob escribió: I ran ipa dnszone-mod vh1.vzwnet.com --update-policy=grant bob-key name test.vh1.vzwnet.com.; I then execute the nsupdate: [root@nj51rhidms16v ~]# ./bobtest.sh ; TSIG error with server: tsig indicates error update failed: