Re: [Freeipa-users] Userpassword randomly not working anymore.

2015-07-07 Thread Matt .
Hi Martin, No problem I thought you guys needed a vacation but you are working on 4.2, wow sounds great! I can provide that but it will take some time as I cannot see when it happens so need to check. I might can post it tomorrow! Good luck there with the release! Cheers, Matt 2015-07-07 13:

Re: [Freeipa-users] FreeIPA mail object to use in 3rd party tool

2015-07-07 Thread Christopher Lamb
Hi Markus I can now replicate FreeIPA groups / group membership to Jira Local Directory /var/log/dirsrv/slapd-*/access showed me the queries Jira is performing to get the groups. Comparing this to the FreeIPA structure using Apache Directory Studio gave the answer. Under Group Schema Settings,

Re: [Freeipa-users] Trace / Debug LDAP queries from 3rd Party Tools against FreeIPA Server

2015-07-07 Thread Christopher Lamb
Rich, Martin Thanks, I saw the query Jira was performing to retrieve the groups in /var/log/dirsrv/slapd-*/access, and have been able to correctly configure Jira accordingly Chris From: Rich Megginson To: freeipa-users@redhat.com Date: 07.07.2015 18:15 Subject:Re: [Freeipa-u

Re: [Freeipa-users] Trace / Debug LDAP queries from 3rd Party Tools against FreeIPA Server

2015-07-07 Thread Rich Megginson
On 07/07/2015 10:09 AM, Martin Basti wrote: On 07/07/15 17:39, Christopher Lamb wrote: Hi All Is there any way on the FreeIPA side to log / debug / trace the LDAP queries made by 3rd Party Tools against a FreeIPA Server? In another thread we are trying to solve some problems with integration

Re: [Freeipa-users] Trace / Debug LDAP queries from 3rd Party Tools against FreeIPA Server

2015-07-07 Thread Martin Basti
On 07/07/15 17:39, Christopher Lamb wrote: Hi All Is there any way on the FreeIPA side to log / debug / trace the LDAP queries made by 3rd Party Tools against a FreeIPA Server? In another thread we are trying to solve some problems with integration of JIRA to FreeIPA. I think if I can see the e

[Freeipa-users] Trace / Debug LDAP queries from 3rd Party Tools against FreeIPA Server

2015-07-07 Thread Christopher Lamb
Hi All Is there any way on the FreeIPA side to log / debug / trace the LDAP queries made by 3rd Party Tools against a FreeIPA Server? In another thread we are trying to solve some problems with integration of JIRA to FreeIPA. I think if I can see the exact LDAP queries JIRA is making against Fre

Re: [Freeipa-users] error after change cert

2015-07-07 Thread Rob Crittenden
barry...@gmail.com wrote: Where is it ? Could u advise ? My old cert is godady And.new cert is combro Please keep responses on the list. $ ldapsearch -LLL -x -D 'cn=directory manager' -W -b cn=RSA,cn=encryption,cn=config nsSSLPersonalitySSL If the result doesn't match the nickname of your n

Re: [Freeipa-users] IPA replica without CA, how to become CA

2015-07-07 Thread Matt .
Hi Rob, OK, I had difficulties with that and try it. What I actually did is: Turned off IPA1 (to act it like a dead one) and removed it from ipa2. Now when I install a new replica with ipa2 as it's master/source I get complains there is no CA. So my ipa2 needs to become ca in some way. I need

Re: [Freeipa-users] IPA Replication Questions

2015-07-07 Thread John Stein
Thanks for the reply. Maybe this should be added to the documentation? John On Tue, Jul 7, 2015 at 11:02 AM Łukasz Jaworski wrote: > Yes. > ipa-replica-manage connect s2 s3 > > and for CA replication: > ipa-csreplica-manage connect s2 s3 > > Best regards, > Ender > > Wiadomość napisana przez J

Re: [Freeipa-users] Using NTP SRV records

2015-07-07 Thread John Stein
Thank you (both of you) John On Tue, Jul 7, 2015 at 2:42 PM Baird, Josh wrote: > You need to specify '--no-ntp' on 'ipa-client-install' > > > > Josh > > > > *From:* freeipa-users-boun...@redhat.com [mailto: > freeipa-users-boun...@redhat.com] *On Behalf Of *John Stein > *Sent:* Tuesday, July 0

Re: [Freeipa-users] Using NTP SRV records

2015-07-07 Thread Jan Pazdziora
On Tue, Jul 07, 2015 at 11:37:39AM +, John Stein wrote: > Hi, > > I have an IPA server installed with --no-ntp, and created SRV records > _ntp._udp_.linux.john.com > pointing to my actual NTP servers. However, when I run ipa-client-install > it is configured with the IPA server as an NTP serve

Re: [Freeipa-users] Using NTP SRV records

2015-07-07 Thread Baird, Josh
You need to specify '--no-ntp' on 'ipa-client-install' Josh From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of John Stein Sent: Tuesday, July 07, 2015 7:38 AM To: freeipa-users@redhat.com Subject: [Freeipa-users] Using NTP SRV records Hi, I have an IP

Re: [Freeipa-users] Userpassword randomly not working anymore.

2015-07-07 Thread Martin Kosek
On 07/05/2015 01:08 AM, Matt . wrote: > Hi Guys, > > I created a bug where no response is on yet for a week, so I thought > to ask the mailinglist if someone has seen this behaviour. Hi Matt, Sorry for the delay in the answer in Bugzilla, most of the team is now very busy with FreeIPA 4.2 finali

[Freeipa-users] Using NTP SRV records

2015-07-07 Thread John Stein
Hi, I have an IPA server installed with --no-ntp, and created SRV records _ntp._udp_.linux.john.com pointing to my actual NTP servers. However, when I run ipa-client-install it is configured with the IPA server as an NTP server. Am I missing something? Thanks, John -- Manage your subscription f

Re: [Freeipa-users] What is the recommended way to create an Administrator account through the web ui?

2015-07-07 Thread Martin Kosek
On 07/03/2015 05:45 PM, nat...@nathanpeters.com wrote: > I have been trying to create accounts in FreeIPA that have the same level > of permission as the built-in administrator account. Basically, I want to > do the equivalent of what you can do in Active Directory by adding someone > to the Domai

Re: [Freeipa-users] IPA Replication Questions

2015-07-07 Thread Łukasz Jaworski
Yes. ipa-replica-manage connect s2 s3 and for CA replication: ipa-csreplica-manage connect s2 s3 Best regards, Ender Wiadomość napisana przez John Stein w dniu 7 lip 2015, o godz. 07:56: > Hi, > > Looking at the documentation, I've found no examples of creating replication > agreement with

Re: [Freeipa-users] strange password error..

2015-07-07 Thread Sumit Bose
On Mon, Jul 06, 2015 at 02:25:56PM -0700, Janelle wrote: > On 7/6/15 10:44 AM, Simo Sorce wrote: > >On Mon, 2015-07-06 at 10:11 -0700, Janelle wrote: > >>Hello all, > >> > >>Is there any known bug that would cause: > >> > >>Password change failed. Server message: Current password's minimum life > >