Re: [Freeipa-users] PKI-CA fails to start (broken config after update?)

2014-09-23 Thread Martin Kosek
On 09/23/2014 03:59 AM, Ade Lee wrote: On Mon, 2014-09-22 at 13:39 -0600, swartz wrote: On 9/22/2014 9:14 AM, Ade Lee wrote: Another question - what is the output of ls -l /etc/pki-ca/CS.cfg ? ls -l /etc/pki-ca/CS.cfg -rw-r-. 1 pkiuser pkiuser 49196 Sep 19 11:29 /etc/pki-ca/CS.cfg In

[Freeipa-users] Announcing bind-dyndb-ldap version 6.0

2014-09-23 Thread Petr Spacek
The FreeIPA team is proud to announce bind-dyndb-ldap version 6.0. It can be downloaded from https://fedorahosted.org/released/bind-dyndb-ldap/ The new version has also been built for Fedora 21+ and and is on its way to updates-testing:

[Freeipa-users] syslog

2014-09-23 Thread alireza baghery
hi i have configured ipa (ipa on centos 6.5) and configure rsyslog for send log to syslog server (juniper strm) in strm get error unknown generic log event or log linux (on server install ipa client) but with another server linux not problem -- Manage your subscription for the Freeipa-users

[Freeipa-users] What should we do with upstream guide?

2014-09-23 Thread Martin Kosek
Hello everyone! It's been over a year now since we announced [1] that the Technical Writer working on FreeIPA upstream guide [2] can no longer maintain the upstream version of it. FreeIPA project developers wanted to carry the torch and forked the outdated documentation in a new repository [3]

Re: [Freeipa-users] weak and null ciphers detected on ldap ports

2014-09-23 Thread Martin Kosek
On 09/22/2014 10:07 PM, Nathan Kinder wrote: On 09/22/2014 05:03 AM, Murty, Ajeet (US - Arlington) wrote: Security scan of FreeIPA server ports uncovered weak, medium and null ciphers on port 389 and 636. We are running ‘ipa-server-3.0.0-37.el6.i686’. How can I disable/remove these

[Freeipa-users] Compat tree and group membership in a trust environment

2014-09-23 Thread Loris Santamaria
Querying for group membership in the compat tree within a trust environment seems to be rather flaky: * userA and userB are members of admins@ad. admins@ad is member of internet_access@ad * internet_access@ad is member of internet_access_external@ad *

[Freeipa-users] Squid negotiate auth and trust relationship

2014-09-23 Thread Loris Santamaria
Hi, I'm setting up a squid proxy in a environment with a trust relationship between IPA and AD. The machine where squid is running belongs to the IPA domain, users may belong to AD or to IPA and in each one of the domains there are groups that define the level of internet access of their

Re: [Freeipa-users] Compat tree and group membership in a trust environment

2014-09-23 Thread Jakub Hrozek
On Tue, Sep 23, 2014 at 11:05:31AM -0430, Loris Santamaria wrote: Querying for group membership in the compat tree within a trust environment seems to be rather flaky: * userA and userB are members of admins@ad. admins@ad is member of internet_access@ad *

Re: [Freeipa-users] Compat tree and group membership in a trust environment

2014-09-23 Thread Alexander Bokovoy
On Tue, 23 Sep 2014, Loris Santamaria wrote: Querying for group membership in the compat tree within a trust environment seems to be rather flaky: * userA and userB are members of admins@ad. admins@ad is member of internet_access@ad * internet_access@ad is member of

Re: [Freeipa-users] Client Certificate

2014-09-23 Thread Walid
Yes Dmitri these two hints would definitely help, the servers are not 4.x yet though. On 19 September 2014 23:14, Dmitri Pal d...@redhat.com wrote: On 09/19/2014 04:03 PM, Walid wrote: Thank you all, will investigate the requirements of host keytabs, and if there is a way around it by

[Freeipa-users] Disable Anonymous LDAP another way...

2014-09-23 Thread Tommy McNeely
Hi all, I have seen the documentation on how to disable anonymous access *completely* at http://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/disabling-anon-binds.html However, I think that those base rootdse queries are probably important. I originally thought they only happened

Re: [Freeipa-users] PKI-CA fails to start (broken config after update?)

2014-09-23 Thread swartz
On 9/22/2014 7:59 PM, Ade Lee wrote: If you scroll to the end of the CS.cfg, does it look like it has been truncated? I'd have to say no. It doesn't look truncated to me. At least there are no obvious signs. But then again I don't know everything that is suppose to be there. I know that the

Re: [Freeipa-users] PKI-CA fails to start (broken config after update?)

2014-09-23 Thread swartz
On 9/22/2014 7:59 PM, Ade Lee wrote: If you scroll to the end of the CS.cfg, does it look like it has been truncated? I'd have to say no. It doesn't look truncated to me. At least there are no obvious signs. But then again I don't know everything that is suppose to be there. I know that the

Re: [Freeipa-users] Disable Anonymous LDAP another way...

2014-09-23 Thread Tommy McNeely
DISREGARD! Sorry all, do not actually try my query, it makes authentication not work at least on CentOS6. Here is the doc I actually read the first time: http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/disabling-anon-binds.html (google search led me here) ... which says to turn

Re: [Freeipa-users] Squid negotiate auth and trust relationship

2014-09-23 Thread Dmitri Pal
On 09/23/2014 11:54 AM, Loris Santamaria wrote: Hi, I'm setting up a squid proxy in a environment with a trust relationship between IPA and AD. The machine where squid is running belongs to the IPA domain, users may belong to AD or to IPA and in each one of the domains there are groups that

[Freeipa-users] problem with log in ipa

2014-09-23 Thread alireza baghery
hi i have configured ipa (ipa on centos 6.5) and configure rsyslog for send log to syslog server (juniper strm) in strm get error unknown generic log event (log's ipa clients ) but with another server linux not problem -- Manage your subscription for the Freeipa-users mailing list: