Re: [Freeipa-users] IPA Backup in AWS - best practices?

2014-10-31 Thread Dmitri Pal
On 10/31/2014 05:42 PM, Michael Lasevich wrote: What is the current best practice for backing up IPA servers? Especially in AWS? Given AWS strengths and weaknesses, I would love to be able to move all of IPA data/state onto a separate drive and just snapshot it on regular basis - but it seems th

[Freeipa-users] IPA Backup in AWS - best practices?

2014-10-31 Thread Michael Lasevich
What is the current best practice for backing up IPA servers? Especially in AWS? Given AWS strengths and weaknesses, I would love to be able to move all of IPA data/state onto a separate drive and just snapshot it on regular basis - but it seems that IPA data is all over the place, so it is hard t

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-31 Thread Michael Lasevich
Thank you!!! That was exactly it. * Removed the "nsEncryptionConfig" entry from 99user.ldif * Re-run the "ipa-ldap-update --upgrade" * Then "ipa-dns-install" and things are looking much better - both servers are now back up and running. What is the lesson here (besides "have good backups")? Shou

Re: [Freeipa-users] Extra attributes for sync agreement AD to FreeIPA

2014-10-31 Thread Dmitri Pal
On 10/31/2014 11:49 AM, Rob Crittenden wrote: Edouard Guigné wrote: Hello Rob, Thank you for your answer. Do you mean it should already work ? Or I have to do this on the FreeIPA server : |rm /etc/dirsrv/slapd-INSTNAME/schema/10rfc2307.ldif cp /usr/share/dirsrv/data/10rfc2307bis.ldif /etc/dirs

Re: [Freeipa-users] DNS forwarders in 4.1.0

2014-10-31 Thread Dmitri Pal
On 10/31/2014 10:42 AM, Petr Spacek wrote: On 31.10.2014 04:38, Rolf Nufable wrote: Hello , I've been trying to install freeipa server v 4.1.0 on my fedora 20 machine and I can't complete the installation because of hte DNS forwarders What exactly is the problem/symptom? Are you receiving a

Re: [Freeipa-users] Replication fails after CentOS 6.5 -> 6.6 Upgrade - sasl_io_recv failed to decode packet for connection xxxx

2014-10-31 Thread Craig White
Craig White System Administrator O 623-201-8179   M 602-377-9752 SkyTouch Technology 4225 E. Windrose Dr. Phoenix, AZ 85032 -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Michael Mercier Sent: Friday, October

Re: [Freeipa-users] Extra attributes for sync agreement AD to FreeIPA

2014-10-31 Thread Rob Crittenden
Edouard Guigné wrote: > Hello Rob, > > Thank you for your answer. > Do you mean it should already work ? > Or I have to do this on the FreeIPA server : > > |rm /etc/dirsrv/slapd-INSTNAME/schema/10rfc2307.ldif > cp /usr/share/dirsrv/data/10rfc2307bis.ldif /etc/dirsrv/slapd-INSTNAME/schema Sor

Re: [Freeipa-users] strange error from EL 7 install?

2014-10-31 Thread Christoph Maser
On Mon, Oct 13, 2014 at 10:08:55PM -0700, Janelle wrote: > Actually, I did find a fix and forgot to post. > > I was able to mirror the COPR repo, and after reviewing it, found that > simply removing the pki-base...fc21 directory, and regenning the repo data > with createrepo, fixed the problem. It

[Freeipa-users] Replication fails after CentOS 6.5 -> 6.6 Upgrade - sasl_io_recv failed to decode packet for connection xxxx

2014-10-31 Thread Michael Mercier
Hello, I just did a 'yum update' from CentOS 6.5 -> 6.6 on my freeipa system (master and 2 replicas) and I seen to have run into the following bug, https://bugzilla.redhat.com/show_bug.cgi?id=953653 On Master: [root@srv-1 slapd-CN-LOCAL]# rpm -qa|grep ipa ipa-client-3.0.0-42.el6.centos.x86_64 l

Re: [Freeipa-users] Extra attributes for sync agreement AD to FreeIPA

2014-10-31 Thread Rob Crittenden
Edouard Guigné wrote: > Hello freeipa Users, > > I am working on a sync agreement between AD server -> FreeIPA server > (fedora 20) > > I follow the documentation, my sync works beetwen AD -> FreeIPA with > "ipa-replica-manage connect --winsync ..." > > However, I would like to extract attribute

[Freeipa-users] Extra attributes for sync agreement AD to FreeIPA

2014-10-31 Thread Edouard Guigné
Hello freeipa Users, I am working on a sync agreement between AD server -> FreeIPA server (fedora 20) I follow the documentation, my sync works beetwen AD -> FreeIPA with "ipa-replica-manage connect --winsync ..." However, I would like to extract attributes from my AD like : - uidNumber - g

Re: [Freeipa-users] DNS forwarders in 4.1.0

2014-10-31 Thread Petr Spacek
On 31.10.2014 04:38, Rolf Nufable wrote: Hello , I've been trying to install freeipa server v 4.1.0 on my fedora 20 machine and I can't complete the installation because of hte DNS forwarders What exactly is the problem/symptom? Are you receiving an error? Or something else? We need to see

[Freeipa-users] DNS forwarders in 4.1.0

2014-10-31 Thread Rolf Nufable
Hello , I've been trying to install freeipa server v 4.1.0 on my fedora 20 machine and I can't complete the installation because of hte DNS forwarders my machine's IP is 192.168.254.7 and I'm using the same IP for DNS forwarders, this is what I did when I was installing 4.0.3 and 3.3.5 and it

Re: [Freeipa-users] [SOLVED] IPA DNS response issue

2014-10-31 Thread Petr Spacek
On 19.3.2014 15:12, David wrote: On Wed, Mar 19, 2014 at 01:57:24PM +0100, Petr Spacek wrote: On 18.3.2014 15:26, David wrote: We have an installation of FreeIPA (through CentOS 6.5) that's exhibiting some odd behavior with respect to serving DNS. Periodically (interval at random) named runnin

Re: [Freeipa-users] Centos IPA Client fails after upgrade to 6.6

2014-10-31 Thread Jakub Hrozek
> On 31 Oct 2014, at 02:23, David Taylor wrote: > > I just recently updated one of our test servers from CentOS 6.5 to CentOS > 6.6, after which I noticed that IPA logons were no longer available. From > what I can see the upgrade includes quite a few changes with regard to sssd. > > -

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-31 Thread Ludwig Krispenz
On 10/30/2014 07:36 PM, Martin Basti wrote: On 30/10/14 19:18, Michael Lasevich wrote: Makes sense. What is the solution here? I have the latest 389-ds installed but still getting "allowWeakCipher" error - how to I get around that? -M Sorry I don't know, I CCied Ludwig, he is DS guru. I