[Freeipa-users] A security bug in SSSD 1.10 and later (CVE-2015-5292)

2015-10-15 Thread Jakub Hrozek
=== A security bug in SSSD 1.10 and later == = = Subject: A memory leak was found in SSSD's PAC processing plugin = = CVE ID#: CVE-2015-5292 = = Summary: When SSSD's PAC responder is configured and a user login = triggers parsing

[Freeipa-users] IPA Domain vs. AD

2015-10-15 Thread Ben Francis
Hello IPA Warriors, Firstly, some love: I installed ipa-server from the Oracle Linux repos and it worked right out of the box. Woot! Getting that many packages to play nice together is a huge accomplishment. However, I uninstalled it because I feared it would cause problems with our current Activ

[Freeipa-users] IPA with external CA signed certs

2015-10-15 Thread James Masson
Hi list, I successfully have IPA working with CA certs signed by an upstream Dogtag. Now I'm trying to use a CA cert signed by a different type of CA - Vault. Setup fails, using the same 2 step IPA setup process as used with upstream Dogtag. I've also tried the external-ca-type option. Like

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Zoske, Fabian
I think this is related to diferent names on different systems. RHEL and CentOS are using crond Ubuntu and similar are using cron From: Karl Forner [karl.for...@gmail.com] Sent: Thursday, October 15, 2015 16:24 To: Zoske, Fabian Cc: freeipa-users@redhat.c

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Karl Forner
ok, makes sense. And ubuntu users are quite rare... On Thu, Oct 15, 2015 at 4:26 PM, Zoske, Fabian wrote: > I think this is related to diferent names on different systems. > > RHEL and CentOS are using crond > Ubuntu and similar are using cron > > > From:

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Karl Forner
Yes it works !!! Maybe this should be documented somewhere ? Thanks. On Thu, Oct 15, 2015 at 4:20 PM, Zoske, Fabian wrote: > Hi, > > we just had the same problem. > > You need to add a new service "cron" and assign this to the user/group. > > Best regards, > Fabian > > -Ursprüngliche Nachrich

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Karl Forner
%ipa hbactest User name: qbuser Target host: asgard Service: crond Access granted: True On Thu, Oct 15, 2015 at 3:53 PM, Karl Forner wrote: > Hi, > > cron jobs do no work using a freeIPA user account. > > the cron job: > */1 * * * * echo coucou > > in /var/log/syslog: > Oct 1

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Zoske, Fabian
Hi, we just had the same problem. You need to add a new service "cron" and assign this to the user/group. Best regards, Fabian -Ursprüngliche Nachricht- Von: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] Im Auftrag von Karl Forner Gesendet: Donnerstag, 15.

Re: [Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Jakub Hrozek
On Thu, Oct 15, 2015 at 03:53:07PM +0200, Karl Forner wrote: > Hi, > > cron jobs do no work using a freeIPA user account. > > the cron job: > */1 * * * * echo coucou > > in /var/log/syslog: > Oct 15 15:48:02 asgard CRON[9779]: Permission denied > > in /var/log/auth.log: > Oct 15 15:48:02 asgard

[Freeipa-users] freeIPA user can not use cron

2015-10-15 Thread Karl Forner
Hi, cron jobs do no work using a freeIPA user account. the cron job: */1 * * * * echo coucou in /var/log/syslog: Oct 15 15:48:02 asgard CRON[9779]: Permission denied in /var/log/auth.log: Oct 15 15:48:02 asgard CRON[9779]: pam_sss(cron:account): Access denied for user qbuser: 6 (Permission deni

Re: [Freeipa-users] How to config automembership for IP or subnet

2015-10-15 Thread Martin Kosek
On 10/14/2015 05:51 PM, zhiyong xue wrote: > Thanks Martin. > > This is the document link: > https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/automember.html > It says : Dividing hosts based on their IP address or subnet. Ah, I see. This is rather old and deprecated guide (see ht

Re: [Freeipa-users] shared ip space for iDM and AD

2015-10-15 Thread Petr Spacek
On 14.10.2015 20:11, Craig White wrote: > -Original Message- > From: freeipa-users-boun...@redhat.com > [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Petr Spacek > Sent: Tuesday, October 13, 2015 11:57 PM > To: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] shared ip spac