Re: [Freeipa-users] FreeIPA Consistency Checker

2016-02-09 Thread Petr Spacek
On 8.2.2016 20:38, Peter Pakos wrote: > Just a quick heads-up, > > The newest version of the ipa_check_consistency script comes with > Nagios/Opsview plug-in functionality and some further improvements. > > Feel free to take it for a spin! > > https://github.com/peterpakos/ipa_check_consistency

Re: [Freeipa-users] IPA 4.2: pki-tomcatd in terrible shape

2016-02-09 Thread Rob Crittenden
Timothy Geier wrote: The debug log has a lot of instances of: Could not connect to LDAP server host xxx. port 636 Error netscape.ldap.LDAPException: IO Error creating JSS SSL Socket (-1) Internal Database Error encountered: Could not connect to LDAP server host xxx. port 636 Error nets

[Freeipa-users] Active Directory Trust = filter users

2016-02-09 Thread Winfried de Heiden
Hi all, Using an Active Directory Trust with IPA all works fine but there's an disadvantage: it might brong in lots and lots of groups I am not interested in since it mainly hit Windows and/or Office stuff. Now, is it possible to filter AD-grou

Re: [Freeipa-users] PKINIT support in FreeIPA 4.2.0

2016-02-09 Thread Nik Lam
On Mon, Feb 8, 2016 at 11:53 PM, Sumit Bose wrote: > On Thu, Feb 04, 2016 at 07:25:29PM +1100, Nik Lam wrote: > > On Wed, Feb 3, 2016 at 8:08 PM, Sumit Bose wrote: > > > > > On Wed, Feb 03, 2016 at 10:29:49AM +1100, Nik Lam wrote: > > > > Hello, > > > > > > > > I installed ipa-server on Centos 7

Re: [Freeipa-users] PKINIT support in FreeIPA 4.2.0

2016-02-09 Thread Sumit Bose
On Wed, Feb 10, 2016 at 02:08:55AM +1100, Nik Lam wrote: > On Mon, Feb 8, 2016 at 11:53 PM, Sumit Bose wrote: > > > On Thu, Feb 04, 2016 at 07:25:29PM +1100, Nik Lam wrote: > > > On Wed, Feb 3, 2016 at 8:08 PM, Sumit Bose wrote: > > > > > > > On Wed, Feb 03, 2016 at 10:29:49AM +1100, Nik Lam wro

[Freeipa-users] sudo runs despite being denied by HBAC rules

2016-02-09 Thread Ian Collier
Can anyone help me to understand these logs... is there maybe a bug here? The basic situation is that there is no HBAC rule that would allow sudo. When people try it, sss accepts their password but then denies them access to the sudo command. But despite this, our logs still contain some entries

Re: [Freeipa-users] IPA 4.2: pki-tomcatd in terrible shape

2016-02-09 Thread Timothy Geier
> On Feb 9, 2016, at 2:58 AM, Rob Crittenden wrote: > > Timothy Geier wrote: >> >> >> The debug log has a lot of instances of: >> >> Could not connect to LDAP server host xxx. port 636 Error >> netscape.ldap.LDAPException: IO Error creating JSS SSL Socket (-1) >> Internal Database Error e

[Freeipa-users] Migrating NIS host to freeIPA host with smart card

2016-02-09 Thread Michael Rainey (Contractor)
Greetings, I have a question about migrating a system from NIS to freeIPA. In my efforts of setting up a host on freeIPA I would normally use a fresh install to setup the system. I'm now at a point where I'm moving existing systems from an NIS domain to a freeIPA domain. Is it recommended

Re: [Freeipa-users] PKINIT support in FreeIPA 4.2.0

2016-02-09 Thread Nik Lam
On Wed, Feb 10, 2016 at 3:04 AM, Sumit Bose wrote: > On Wed, Feb 10, 2016 at 02:08:55AM +1100, Nik Lam wrote: > > On Mon, Feb 8, 2016 at 11:53 PM, Sumit Bose wrote: > > > > > On Thu, Feb 04, 2016 at 07:25:29PM +1100, Nik Lam wrote: > > > > On Wed, Feb 3, 2016 at 8:08 PM, Sumit Bose wrote: > > >

[Freeipa-users] Where should I create my Linux and Mac users in a AD IPA trust?

2016-02-09 Thread Supratik Goswami
I am currently running IPA server 4.2 in RHEL 7.2 and I have created a two-way trust between my Windows AD and IPA server. I have a heterogeneous environment where I have Windows, Linux and Mac clients. The Windows users are present in AD and they can access the resources under IPA through the tr