Re: [Freeipa-users] Sudo Rules Help

2015-11-12 Thread Branden Coates
Thank you for the welcome! So in the process of pulling the output of the log files with the most recent attempts on cent6 I sorted out the issues with cent6, though cent5 is still problematic. I added debug_level = 6 to sudo and the domain in the sssd.conf. Originally I only had this for

Re: [Freeipa-users] ipa-getkeytab missing permissions after migration

2015-11-12 Thread Martin Kosek
On 11/12/2015 03:58 PM, Simo Sorce wrote: On 11/11/15 15:22, Martin Kosek wrote: On 11/10/2015 02:59 PM, Dominik Korittki wrote: Hello folks, I created a replica IPA host with version 4.1.0-18.el7.centos.4, while the initial master is a FreeIPA 3.3.3. Everything seems to work fine with the

Re: [Freeipa-users] 3/4 replica failure - unknown reasons why

2015-11-12 Thread thierry bordaz
On 11/11/2015 04:20 PM, Andrew Krause wrote: Yesterday I came in to 3 of my 4 freeipa replicas in an unusable state and replication was not connecting any of the hosts to each other. My first/primary host was still servicing authentication requests, but the others were in varying states of

Re: [Freeipa-users] Sudo Rules Help

2015-11-12 Thread Pavel Březina
On 11/11/2015 03:24 PM, Branden Coates wrote: I have a few issues with sudo rules(FreeIPA 4.1.4-4 on Fedora 22) that I would greatly appreciate some help with. The core of the issue is that sudo rules fail to work when using ldap instead of ipa when you assign user groups and host groups to the

Re: [Freeipa-users] 4.2 Packages for RHEL/CentOS 7.1

2015-11-12 Thread Alexander Bokovoy
On Wed, 11 Nov 2015, Christopher Young wrote: Do we know what the status of getting these packages prepped and into the mainstream repos (like EPEL, I suppose)? I'm just curious as I try and keep my repos minimal on servers (for obvious reasons), but I would really like to begin testing/using

Re: [Freeipa-users] Unable to communicate with CMS (Service Unavailable)

2015-11-12 Thread Martin Kosek
On 11/12/2015 04:51 PM, Terry John wrote: I got a core dump of certmonger failing user abrt but it's huge. Is there any particular part that would be useful. CCing Nalin and David for the core dump. More below. On 11/12/2015 02:17 PM, Terry John wrote: I had a working freeipa setup on a

Re: [Freeipa-users] problems with NFS service principal

2015-11-12 Thread jcnt
On Mon, 9 Nov 2015 08:53:34 +0100, Petr Spacek wrote: > > What do you mean, exactly, by 'stand alone NFS server'? > > Is it another server which did not executed ipa-client-install? Correct, another server, which didn't execute ipa-client-install. I created host principal and nfs principal

[Freeipa-users] Suggestions requested for disabling an account by date

2015-11-12 Thread Roderick Johnstone
Hi I'd like to find a way to disable an account on a date that we can set in the account information. ie like the Account Availability option in Solaris Management Console or the /etc/shadow "account expiration date" concept on Linux. I couldn't obviously see in the docs or on the list how

Re: [Freeipa-users] IPA with external CA signed certs

2015-11-12 Thread James Masson
On 30/10/15 13:52, Rob Crittenden wrote: James Masson wrote: On 26/10/15 16:11, Martin Kosek wrote: On 10/26/2015 04:05 PM, James Masson wrote: On 19/10/15 21:06, Rob Crittenden wrote: James Masson wrote: Hi list, I successfully have IPA working with CA certs signed by an upstream

Re: [Freeipa-users] Suggestions requested for disabling an account by date

2015-11-12 Thread Mateusz Małek
Hi, W dniu 12.11.2015 o 13:35, Roderick Johnstone pisze: I'd like to find a way to disable an account on a date that we can set in the account information. ie like the Account Availability option in Solaris Management Console or the /etc/shadow "account expiration date" concept on Linux. I

Re: [Freeipa-users] REST/JSON API: Howto add a user that is not expired

2015-11-12 Thread Petr Vobornik
On 11/11/2015 04:13 PM, Alexander Bokovoy wrote: On Wed, 11 Nov 2015, Oliver Dörr wrote: Hi, i've tried user_mod instead because of https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/pwd-expiration.html and got Error-code:2100 Error-name:ACIError Error-msg:

Re: [Freeipa-users] 389DS segfaults after upgrade FC 21 -> 22

2015-11-12 Thread Prashant Bapat
Is there a way for you to try F23. Its the latest anyway if thats the reason you're upgrading. I recently did this couple of times in a test setup (aws and virtualbox). I have 4.1.4 (F21) in production. Was trying upgrade from F21->F22 and F22->F23 this would give me freeipa 4.2.3.​ Things went

Re: [Freeipa-users] problems with NFS service principal

2015-11-12 Thread Petr Spacek
On 13.11.2015 00:13, j...@use.startmail.com wrote: > > > On Mon, 9 Nov 2015 08:53:34 +0100, Petr Spacek wrote: >> >> What do you mean, exactly, by 'stand alone NFS server'? >> >> Is it another server which did not executed ipa-client-install? > > Correct, another server, which didn't execute

[Freeipa-users] Unable to communicate with CMS (Service Unavailable)

2015-11-12 Thread Terry John
I had a working freeipa setup on a CentOS release 6.7 machine. All was well until I did a yum update. Now I have multiple issue apparently based around the CMS (Service Unavailable) issue. My current version of ipa-server is 3.0.0-47 Certmonger crashes with a segmentation fault at boot time

Re: [Freeipa-users] Suggestions requested for disabling an account by date

2015-11-12 Thread Roderick Johnstone
On 12/11/15 13:01, Mateusz Małek wrote: Hi, W dniu 12.11.2015 o 13:35, Roderick Johnstone pisze: I'd like to find a way to disable an account on a date that we can set in the account information. ie like the Account Availability option in Solaris Management Console or the /etc/shadow "account

Re: [Freeipa-users] Unable to communicate with CMS (Service Unavailable)

2015-11-12 Thread Martin Kosek
On 11/12/2015 02:17 PM, Terry John wrote: > I had a working freeipa setup on a CentOS release 6.7 machine. All was well > until I did a yum update. Now I have multiple issue apparently based around > the CMS (Service Unavailable) issue. > > My current version of ipa-server is 3.0.0-47 > >

Re: [Freeipa-users] ipa-getkeytab missing permissions after migration

2015-11-12 Thread Simo Sorce
On 11/11/15 15:22, Martin Kosek wrote: On 11/10/2015 02:59 PM, Dominik Korittki wrote: Hello folks, I created a replica IPA host with version 4.1.0-18.el7.centos.4, while the initial master is a FreeIPA 3.3.3. Everything seems to work fine with the new host except for one thing: We have a

Re: [Freeipa-users] IPA with external CA signed certs

2015-11-12 Thread Rob Crittenden
James Masson wrote: On 30/10/15 13:52, Rob Crittenden wrote: James Masson wrote: On 26/10/15 16:11, Martin Kosek wrote: On 10/26/2015 04:05 PM, James Masson wrote: On 19/10/15 21:06, Rob Crittenden wrote: James Masson wrote: Hi list, I successfully have IPA working with CA certs

Re: [Freeipa-users] IPA with external CA signed certs

2015-11-12 Thread James Masson
On 12/11/15 15:21, Rob Crittenden wrote: James Masson wrote: On 30/10/15 13:52, Rob Crittenden wrote: James Masson wrote: On 26/10/15 16:11, Martin Kosek wrote: On 10/26/2015 04:05 PM, James Masson wrote: On 19/10/15 21:06, Rob Crittenden wrote: James Masson wrote: Hi list, I

Re: [Freeipa-users] Unable to communicate with CMS (Service Unavailable)

2015-11-12 Thread Terry John
I got a core dump of certmonger failing user abrt but it's huge. Is there any particular part that would be useful. On 11/12/2015 02:17 PM, Terry John wrote: >> I had a working freeipa setup on a CentOS release 6.7 machine. All was well >> until I did a yum update. Now I have multiple issue

Re: [Freeipa-users] IPA with external CA signed certs

2015-11-12 Thread Rob Crittenden
James Masson wrote: On 12/11/15 15:21, Rob Crittenden wrote: James Masson wrote: On 30/10/15 13:52, Rob Crittenden wrote: James Masson wrote: On 26/10/15 16:11, Martin Kosek wrote: On 10/26/2015 04:05 PM, James Masson wrote: On 19/10/15 21:06, Rob Crittenden wrote: James Masson

Re: [Freeipa-users] krb5kdc will not start (kerberos authentication error)

2015-11-12 Thread Simo Sorce
On 10/11/15 11:54, Gronde, Christopher (Contractor) wrote: # ldapsearch -x -D 'cn=Directory Manager' -W -b cn=mapping,cn=sasl,cn=config Enter LDAP Password: # extended LDIF # # LDAPv3 # base