Re: [Freeipa-users] Kerberos authentication from a third party app - Shibboleth

2016-03-01 Thread Alexander Bokovoy
On Tue, 01 Mar 2016, Prashant Bapat wrote: Hi, I'm trying to use Shibboleth IdP with FreeIPA and Kerberos Authentication. I'm aware of Ipsilon, just that Shibboleth is more suited for my use case. I've installed ipa-client on a server and connected it to ipa. Shibboleth is installed on this ser

Re: [Freeipa-users] Cross Forest Transitive AD Trust

2016-03-01 Thread Alexander Bokovoy
On Wed, 02 Mar 2016, PARTH MONGA wrote: Thanks Alexander for the prompt reply. Appreciated. Now i am wondering how likewise is able to do this stuff under the hood for me. I have similar setup with likewise and same one way incoming trust relationships towards my primary domain (dom1) from anot

Re: [Freeipa-users] Cross Forest Transitive AD Trust

2016-03-01 Thread PARTH MONGA
Thanks Alexander for the prompt reply. Appreciated. Now i am wondering how likewise is able to do this stuff under the hood for me. I have similar setup with likewise and same one way incoming trust relationships towards my primary domain (dom1) from another external domain (dom2). And i am able

[Freeipa-users] Kerberos authentication from a third party app - Shibboleth

2016-03-01 Thread Prashant Bapat
Hi, I'm trying to use Shibboleth IdP with FreeIPA and Kerberos Authentication. I'm aware of Ipsilon, just that Shibboleth is more suited for my use case. I've installed ipa-client on a server and connected it to ipa. Shibboleth is installed on this server and I'm able to get the Kerberos authenti

Re: [Freeipa-users] Cross Forest Transitive AD Trust

2016-03-01 Thread Alexander Bokovoy
On Wed, 02 Mar 2016, PARTH MONGA wrote: Hi List Members, I have a situation I am having a hard time getting a clean answer on. I have a IDM/IPA domain setup and I have a trust setup with my Windows domain. That part is working perfectly. I have a one way forest transitive trust (outgoing) with

[Freeipa-users] Cross Forest Transitive AD Trust

2016-03-01 Thread PARTH MONGA
Hi List Members, I have a situation I am having a hard time getting a clean answer on. I have a IDM/IPA domain setup and I have a trust setup with my Windows domain. That part is working perfectly. I have a one way forest transitive trust (outgoing) with a second windows domain. I want users in

Re: [Freeipa-users] DNSSEC KSK rollover

2016-03-01 Thread Petr Spacek
On 29.2.2016 11:54, Peter Fern wrote: > On 02/29/2016 21:22, Petr Spacek wrote: >> On 28.2.2016 14:51, Peter Fern wrote: >>> Hi all, >>> A new KSK has been auto-generated, and it's transitioned through >>> 'published' and is now sitting in the 'ready' state, but does not appear >>> as a DNSKEY reco

Re: [Freeipa-users] version compatibility between server and client

2016-03-01 Thread Martin Kosek
On 02/29/2016 07:03 PM, Rakesh Rajasekharan wrote: > the only reason for me to avoid ipa-client-install was few of our machines > are Amazon Linux and I was having a tough time setting up ipa over there as > the yum does not get the repo even with epel enabled. Ah, right. This was already discusse

Re: [Freeipa-users] Traceback starting pki-cad - ca.subsystem.certreq missing?

2016-03-01 Thread German Parente
Hi Fraser, thanks for the workaround. As I have a customer who hit this bug, I have created BZ 1313207 to trace this issue in the case. Regards, German. - Original Message - > From: "Fraser Tweedale" > To: "Ian Pilcher" , "Natxo Asenjo" > > Cc: freeipa-users@redhat.com > Sent: Tuesd