Re: [Freeipa-users] Trying To Connect FreeIPA with OKTA/OneLogin/Bitium

2014-08-12 Thread Martin Kosek
Thank you! I liked this page to http://www.freeipa.org/page/HowTos#Authentication and also improved formatting of the page. I am not sure about the role section though, we do not use role objectclass, so Okta's search probably returns no results anyway. It may be better to keep that blank IMO.

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash:

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon, Aug 11, 2014 at 05:18:03PM +0300, Alexander Bokovoy wrote: On Sat, 09 Aug 2014, Erinn Looney-Triggs

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon,

Re: [Freeipa-users] Trying To Connect FreeIPA with OKTA/OneLogin/Bitium

2014-08-12 Thread Chris Whittle
Thanks Martin! On Tue, Aug 12, 2014 at 9:50 AM, Martin Kosek mko...@redhat.com wrote: Thank you! I liked this page to http://www.freeipa.org/page/HowTos#Authentication and also improved formatting of the page. I am not sure about the role section though, we do not use role objectclass, so

[Freeipa-users] Replicating o=ipaca

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 The documentation seems to be a little fuzzy on setting up two CAs, some parts indicate this is a bad idea because the CRLs can clobber each other, other parts, such as the migration guide from RHEL 6.5 to 7 seem to indicate that it is ok, albeit

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 09:21 AM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/11/2014 09:08 AM, Martin Kosek wrote: On 08/11/2014 04:24 PM, Jakub Hrozek wrote: On Mon,

Re: [Freeipa-users] Replicating o=ipaca

2014-08-12 Thread Rob Crittenden
Erinn Looney-Triggs wrote: The documentation seems to be a little fuzzy on setting up two CAs, some parts indicate this is a bad idea because the CRLs can clobber each other, other parts, such as the migration guide from RHEL 6.5 to 7 seem to indicate that it is ok, albeit maybe that is just

Re: [Freeipa-users] Adding permissions to a service account.

2014-08-12 Thread Rob Crittenden
William wrote: Hi, I am trying to allow a radius service account the ability to read ipaNTHash. I carried out the following steps: ipa permission-add 'ipaNTHash service read' --attrs=ipaNTHash --type=user --permissions=read - Added permission

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Alexander Bokovoy
On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I understand, that TLS or some security be used for the connection. I currently have minssf set to 56 and am able to

Re: [Freeipa-users] MinSSF suggestions?

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 12:33 PM, Alexander Bokovoy wrote: On Tue, 12 Aug 2014, Erinn Looney-Triggs wrote: I guess the part I don't get here, is that this setting does not disable anonymous access to rootdse it just requires, as far as I understand, that

Re: [Freeipa-users] Replicating o=ipaca

2014-08-12 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 08/12/2014 11:49 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: The documentation seems to be a little fuzzy on setting up two CAs, some parts indicate this is a bad idea because the CRLs can clobber each other, other parts, such as the

Re: [Freeipa-users] Replicating o=ipaca

2014-08-12 Thread Rob Crittenden
Erinn Looney-Triggs wrote: On 08/12/2014 11:49 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: The documentation seems to be a little fuzzy on setting up two CAs, some parts indicate this is a bad idea because the CRLs can clobber each other, other parts, such as the migration guide from

Re: [Freeipa-users] Adding permissions to a service account.

2014-08-12 Thread William
On Tue, 2014-08-12 at 13:51 -0400, Rob Crittenden wrote: William wrote: Hi, I am trying to allow a radius service account the ability to read ipaNTHash. I carried out the following steps: You can't delegate permissions to a service. See

[Freeipa-users] check access log of when a user login integrated system

2014-08-12 Thread barrykfl
Hi all: I have a buzilla intgrated with ldap ,,,is it poosible to check when the user login through the access log of ldap free ipa server .. What sentence should it look like ? thks barry -- Manage your subscription for the Freeipa-users mailing list: