Re: [Freeipa-users] Traceback starting pki-cad - ca.subsystem.certreq missing?

2016-02-29 Thread Fraser Tweedale
On Mon, Feb 22, 2016 at 06:42:04PM +0100, Natxo Asenjo wrote: > On Sat, Feb 20, 2016 at 5:58 PM, Ian Pilcher wrote: > > > I am running IPA 3.0.0 on CentOS 6 (32-bit x86), and I am getting a > > traceback every time pki-cad starts: > > > > Traceback (most recent call last): > > File "/usr/sbin/p

Re: [Freeipa-users] OTP not working since upgrade

2016-02-29 Thread Simo Sorce
On Mon, 2016-02-29 at 16:49 +, Alessandro De Maria wrote: > Of course, > > could you point me to the logs you would be interested in? Probably the kdc logs, I am not sure we directly log from ipa-otpd, but you could take a look at the journal/syslog too ? Simo. > Regards > Alessandro > > O

Re: [Freeipa-users] version compatibility between server and client

2016-02-29 Thread Rakesh Rajasekharan
the only reason for me to avoid ipa-client-install was few of our machines are Amazon Linux and I was having a tough time setting up ipa over there as the yum does not get the repo even with epel enabled. Otherwise, I was able to get this working on all of the other systems , which are centos 6.3

Re: [Freeipa-users] OTP not working since upgrade

2016-02-29 Thread Alessandro De Maria
Of course, could you point me to the logs you would be interested in? Regards Alessandro On 29 February 2016 at 05:44, Simo Sorce wrote: > On Mon, 2016-02-29 at 00:11 +, Alessandro De Maria wrote: > > Solved. > > This turned out to be the ipa-otp process stuck on one of the 2 servers. > >

Re: [Freeipa-users] Preserved users not replicated to new master (FreeIPA 4.2.0)

2016-02-29 Thread thierry bordaz
Hi Justin, I was trying to reproduce this but I think I am missing some steps. Do you mind reviewing my testcase to check what is missing ? The test case is : install master M, prepare replica (+copy of gpg), install replica (new master) R. On R: * Authenticate as 'admin'

Re: [Freeipa-users] version compatibility between server and client

2016-02-29 Thread Martin Kosek
On 02/26/2016 05:23 PM, Rakesh Rajasekharan wrote: > Hi!, > > I had successfully set up ipa in our qa environment, but since we are > running cenots 6, i just got 3.0.25 version of IPA. > > I wanted to try out the latest 4.x version, for server by using a centos 7 > OS. But have few questions reg

Re: [Freeipa-users] DNSSEC KSK rollover

2016-02-29 Thread Peter Fern
On 02/29/2016 21:22, Petr Spacek wrote: > On 28.2.2016 14:51, Peter Fern wrote: >> Hi all, >> A new KSK has been auto-generated, and it's transitioned through >> 'published' and is now sitting in the 'ready' state, but does not appear >> as a DNSKEY record on the zone. I can see that ods-enforcerd

Re: [Freeipa-users] DNSSEC KSK rollover

2016-02-29 Thread Petr Spacek
On 28.2.2016 14:51, Peter Fern wrote: > Hi all, > A new KSK has been auto-generated, and it's transitioned through > 'published' and is now sitting in the 'ready' state, but does not appear > as a DNSKEY record on the zone. I can see that ods-enforcerd has picked > up the state change correctly an

Re: [Freeipa-users] Unable to get new certificates after upgrade

2016-02-29 Thread Martin Babinsky
On 02/27/2016 09:36 PM, Alessandro De Maria wrote: Hello list, I was running freeipa 4.1 on Centos 7.1. I wanted to upgrade to freeipa 4.2.x to make use of user certificates. Upgrade (through yum upgrade) went ok and I am now on version: Name: ipa-server Version : 4.2.0 Release