Re: [Freeipa-users] freeIPA function basics from user's perspective

2015-03-10 Thread Dmitri Pal
On 03/10/2015 02:39 PM, Robert Erzen wrote: Hi all, I'm new to freeIPA and I'm researching how freeIPA bassically work. How does this looks like from the perspective of the end user. Can you please confirm or correct my knowledge about freeIPA functioning. Let assume we have a mixed environme

Re: [Freeipa-users] Trying to migrate, can't set hashed passwords

2015-03-10 Thread Ben Slusky
On Mon, Mar 9, 2015 at 2:45 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Ben Slusky wrote: > >> Greetings FreeIPA users, >> >> I'm setting up FreeIPA service in our production environment to replace >> several different authentication methods for various systems. I'm trying >> to >> migrat

Re: [Freeipa-users] freeIPA SSL authentication

2015-03-10 Thread Dmitri Pal
On 03/10/2015 01:19 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 03/10/2015 10:22 AM, Rob Crittenden wrote: K SHK wrote: hi, My hortonworks hadoop cluster is keberized with FreeIPA and works splendid :) I want to clarify if SSL authentication with out a login/password will work against Fre

[Freeipa-users] freeIPA function basics from user's perspective

2015-03-10 Thread Robert Erzen
Hi all, I'm new to freeIPA and I'm researching how freeIPA bassically work. How does this looks like from the perspective of the end user. Can you please confirm or correct my knowledge about freeIPA functioning. Let assume we have a mixed environment of five freeIPA servers which are gatheredint

Re: [Freeipa-users] Need to replace cert for ipa servers

2015-03-10 Thread sipazzo
I was told the GoDaddy certs were just imported using certutil -a but in looking at the certs the original certs were actually replaced. This is only in /etc/dirsrv/slapd-REALM-COM: Certificate Nickname                                         Trust Attributes                                  

Re: [Freeipa-users] freeIPA SSL authentication

2015-03-10 Thread Rob Crittenden
Dmitri Pal wrote: > On 03/10/2015 10:22 AM, Rob Crittenden wrote: >> K SHK wrote: >>> hi, >>> >>> My hortonworks hadoop cluster is keberized with FreeIPA and works >>> splendid :) >>> >>> I want to clarify if SSL authentication with out a login/password will >>> work against FreeIPA... >>> >>> ie.

Re: [Freeipa-users] Web UI Authentication errors - revisited

2015-03-10 Thread Dan Mossor
On Fri, Mar 6, 2015 at 1:53 PM, Martin Kosek wrote: > On 03/06/2015 05:59 PM, Dan Mossor wrote: > >> >> IT WORKS! WOOT! >> >> In the steps of researching a small issue on another hypervisor, I >> discovered >> that my underlying network, while operational, was not properly >> configured. The >> I

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Traiano Welcome wrote: Hi Alexander On Tue, Mar 10, 2015 at 12:08 PM, Alexander Bokovoy wrote: On Tue, 10 Mar 2015, Traiano Welcome wrote: However, I'm still not able to authenticate via the ssh->sssd path (I cn get kerberos tickets for ad users via cli though), so I th

Re: [Freeipa-users] freeIPA SSL authentication

2015-03-10 Thread Dmitri Pal
On 03/10/2015 10:22 AM, Rob Crittenden wrote: K SHK wrote: hi, My hortonworks hadoop cluster is keberized with FreeIPA and works splendid :) I want to clarify if SSL authentication with out a login/password will work against FreeIPA... ie. client connects to apache webserver over SSL, and set

Re: [Freeipa-users] Migration from RHEL6 (3.0.0-42) to CentOS7 (3.3.3-28.0.1)

2015-03-10 Thread Benjamin Reed
On 3/10/15 10:06 AM, Alexander Bokovoy wrote: > We have http://www.freeipa.org/page/Documentation#User_Guides and going > through user guide would be our recommended action. There is a whole > chapter 6 in RHEL7 docs for upgrades and migration. Ah, I see it now. I had no idea from the name that "

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
Hi Alexander On Tue, Mar 10, 2015 at 12:08 PM, Alexander Bokovoy wrote: > On Tue, 10 Mar 2015, Traiano Welcome wrote: >> >> However, I'm still not able to authenticate via the ssh->sssd path (I >> cn get kerberos tickets for ad users via cli though), so I think that >> incorrect dc discovery is

Re: [Freeipa-users] freeIPA SSL authentication

2015-03-10 Thread Rob Crittenden
K SHK wrote: > hi, > > My hortonworks hadoop cluster is keberized with FreeIPA and works > splendid :) > > I want to clarify if SSL authentication with out a login/password will > work against FreeIPA... > > ie. client connects to apache webserver over SSL, and sets in username via > > http://h

Re: [Freeipa-users] how can i configure solaris10 as freeIPA 4.1.2 client

2015-03-10 Thread Rob Crittenden
Dmitri Pal wrote: > On 03/08/2015 05:25 PM, Jakub Hrozek wrote: >> On Sun, Mar 08, 2015 at 04:51:08PM -0400, Rob Crittenden wrote: >>> The IPA team has moved away from trying to provide direct support >>> /documentation for non-Linux platforms since we don't have the in-house >>> expertise. The doc

Re: [Freeipa-users] Migration from RHEL6 (3.0.0-42) to CentOS7 (3.3.3-28.0.1)

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Benjamin Reed wrote: On 3/10/15 9:31 AM, Alexander Bokovoy wrote: Are you following these instructions? https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/migrating-ipa-proc.html Aha! No. T

Re: [Freeipa-users] Migration from RHEL6 (3.0.0-42) to CentOS7 (3.3.3-28.0.1)

2015-03-10 Thread Benjamin Reed
On 3/10/15 9:31 AM, Alexander Bokovoy wrote: > Are you following these instructions? > https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/migrating-ipa-proc.html Aha! No. There are so many false positives in google

Re: [Freeipa-users] Errors while adding DNS Zone

2015-03-10 Thread Matt Wells
@Martin Basti that was it. Thanks so much for the assistance. @Petr Spacek also thanks for the reply also. I failed to provide some rather important information that you mentioned. Thanks all for your the help. On Tue, Mar 10, 2015 at 1:35 AM, Petr Spacek wrote: > Hello! > > First of all, what

Re: [Freeipa-users] Migration from RHEL6 (3.0.0-42) to CentOS7 (3.3.3-28.0.1)

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Benjamin Reed wrote: I'm attempting to migrate FreeIPA from an RHEL6 server to a CentOS7 server. When I run ipa-replica-install to set up the CentOS7 server, I get the following error: ipa : CRITICAL The master CA directory server does not have necessary schema. Pl

[Freeipa-users] Migration from RHEL6 (3.0.0-42) to CentOS7 (3.3.3-28.0.1)

2015-03-10 Thread Benjamin Reed
I'm attempting to migrate FreeIPA from an RHEL6 server to a CentOS7 server. When I run ipa-replica-install to set up the CentOS7 server, I get the following error: > ipa : CRITICAL The master CA directory server does not have > necessary schema. Please copy the following script to all CA

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Guertin, David S. wrote: You should be able to 'see' them via getent passwd but they should not be allowed to login when HBAC_ALLOW_ALL is disabled. Ah, OK, thanks, that's what is happening. I can see them with getent passwd and id, and I can su to them, but I can't log in

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Guertin, David S.
> You should be able to 'see' them via getent passwd but they should not be > allowed to login when HBAC_ALLOW_ALL is disabled. Ah, OK, thanks, that's what is happening. I can see them with getent passwd and id, and I can su to them, but I can't log in as them. On the other hand, I also can't lo

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Jakub Hrozek
On Tue, Mar 10, 2015 at 11:14:21AM +, Guertin, David S. wrote: > > > Seems the initial/default setup for IPA server is to put in an 'allow_all' > > rule. Thus you can actively manage HBAC but out of the box, it is > > essentially > > turned off by that rule. > > > > Yes. The default was the o

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Guertin, David S. wrote: > Seems the initial/default setup for IPA server is to put in an 'allow_all' rule. Thus you can actively manage HBAC but out of the box, it is essentially turned off by that rule. Yes. The default was the opposite very long time ago, you had to expli

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Petr Spacek
On 10.3.2015 12:14, Guertin, David S. wrote: >>> Seems the initial/default setup for IPA server is to put in an 'allow_all' >> rule. Thus you can actively manage HBAC but out of the box, it is essentially >> turned off by that rule. >> >> Yes. The default was the opposite very long time ago, you ha

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Guertin, David S.
> > Seems the initial/default setup for IPA server is to put in an 'allow_all' > rule. Thus you can actively manage HBAC but out of the box, it is essentially > turned off by that rule. > > Yes. The default was the opposite very long time ago, you had to explicitly > enable access to the box. But

Re: [Freeipa-users] Can't add AD user group to IPA group

2015-03-10 Thread Guertin, David S.
>>I have already: >>- created an IPA group called ad_users. >>- created an IPA group called ad_users_external. > Did you create this group with --external? Doh! Nope, somehow I missed that. I've done that and that part is working now. But the other part of the question remains, i.e. I'm still se

[Freeipa-users] freeIPA SSL authentication

2015-03-10 Thread K SHK
hi, My hortonworks hadoop cluster is keberized with FreeIPA and works splendid :) I want to clarify if SSL authentication with out a login/password will work against FreeIPA... ie. client connects to apache webserver over SSL, and sets in username via http://httpd.apache.org/docs/2.2/mod/mod_ss

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Jakub Hrozek
On Tue, Mar 10, 2015 at 09:47:18AM +0100, Sumit Bose wrote: > On Mon, Mar 09, 2015 at 08:27:05PM -0400, Dmitri Pal wrote: > > On 03/09/2015 03:40 PM, Jakub Hrozek wrote: > > >On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: > > >>On 03/09/2015 02:29 PM, Traiano Welcome wrote: > > >>>Hi A

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Alexander Bokovoy
On Tue, 10 Mar 2015, Traiano Welcome wrote: However, I'm still not able to authenticate via the ssh->sssd path (I cn get kerberos tickets for ad users via cli though), so I think that incorrect dc discovery is not really the issue here. Instead, it seem the ldap query against the discovered AD do

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
On Mon, Mar 9, 2015 at 9:49 PM, Alexander Bokovoy wrote: > On Mon, 09 Mar 2015, Traiano Welcome wrote: >> >> Hi Alexander >> >> Thanks for the response: >> >> On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy >> wrote: >>> >>> On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List >>>

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Sumit Bose
On Mon, Mar 09, 2015 at 08:27:05PM -0400, Dmitri Pal wrote: > On 03/09/2015 03:40 PM, Jakub Hrozek wrote: > >On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: > >>On 03/09/2015 02:29 PM, Traiano Welcome wrote: > >>>Hi Alexander > >>> > >>> Thanks for the response: > >>> > >>>On Mon, Mar

Re: [Freeipa-users] Errors while adding DNS Zone

2015-03-10 Thread Petr Spacek
Hello! First of all, what version of FreeIPA do you use? FreeIPA 4.1.what? On 9.3.2015 19:18, Matt Wells wrote: > I'm getting some errors on a DNS Zone that I'm attempting to create. > My systems reside within a sub-domain of example.com. > (xyz.example.com) > Of course example.com is the interne

Re: [Freeipa-users] Errors while adding DNS Zone

2015-03-10 Thread Martin Basti
On 09/03/15 19:18, Matt Wells wrote: I'm getting some errors on a DNS Zone that I'm attempting to create. My systems reside within a sub-domain of example.com. (xyz.example.com) Of course example.com is the internet address, but I want to host the internal example.com so we're able to point to in