[Freeipa-users] Version name changed?

2016-03-03 Thread Simpson Lachlan
Hi, I have just installed Spacewalk to manage my servers and I noticed that the FreeIPA wanted to update some packages. My FreeIPA server is Centos 7. I notices in Spacewalk that the ipa-server package (and various bits) wanted to update, and the relevant versions were: Installed packages:

Re: [Freeipa-users] user certificate ldap EXTERNAL authentication

2016-03-03 Thread Rob Crittenden
Natxo Asenjo wrote: > hi, > > I am testing certificate authentication to ipa ldap ( centos 7.2 ). > > I have generated a user certificate following the instructions on > https://blog-ftweedal.rhcloud.com/2015/08/user-certificates-and-custom-profiles-with-freeipa-4-2/ > > After that I modified my

[Freeipa-users] user certificate ldap EXTERNAL authentication

2016-03-03 Thread Natxo Asenjo
hi, I am testing certificate authentication to ipa ldap ( centos 7.2 ). I have generated a user certificate following the instructions on https://blog-ftweedal.rhcloud.com/2015/08/user-certificates-and-custom-profiles-with-freeipa-4-2/ After that I modified my $HOME/.ldaprc with these settings:

Re: [Freeipa-users] FreeIPA 4.2.0 / Replica / Join Issue

2016-03-03 Thread devin
Rob, Yeah i forgot to attach the file when I initially sent. I also attached the output from all the nodes. I guess what i realized is that my agreements are a little different than i originally thought. What is also strange is on a few hosts that initially did enroll from AWS, when I look at t

Re: [Freeipa-users] FreeIPA 4.2.0 / Replica / Join Issue

2016-03-03 Thread Rob Crittenden
de...@pabstatencio.com wrote: > > I am running the latest patched CentOS 7.2, with FreeIPA 4.2.0, and I > the Master node in the Data Center, then i created 3 replica's, one in > the DC for High Availability, and then 2 Replica's in the AWS Cloud. I'm > having major issues with the Replica's in th

Re: [Freeipa-users] I think I have an issue, but maybe not.....Is IPA Replica Clean-up Needed?

2016-03-03 Thread Rob Crittenden
Auerbach, Steven wrote: > We have IPA set up in active-active mode. The first node (ipa01) logs > errors regularly (every few minutes) that seem to be based upon an > attempt to communicate with a replica that no longer exists. > > > > Feb 25 14:38:04 ipa01 named[2161]: LDAP query timed out. T

[Freeipa-users] FreeIPA 4.2.0 / Replica / Join Issue

2016-03-03 Thread devin
I am running the latest patched CentOS 7.2, with FreeIPA 4.2.0, and I the Master node in the Data Center, then i created 3 replica's, one in the DC for High Availability, and then 2 Replica's in the AWS Cloud. I'm having major issues with the Replica's in the AWS Cloud. I am trying to have it so

[Freeipa-users] I think I have an issue, but maybe not.....Is IPA Replica Clean-up Needed?

2016-03-03 Thread Auerbach, Steven
We have IPA set up in active-active mode. The first node (ipa01) logs errors regularly (every few minutes) that seem to be based upon an attempt to communicate with a replica that no longer exists. Feb 25 14:38:04 ipa01 named[2161]: LDAP query timed out. Try to adjust "timeout" parameter Feb 2

Re: [Freeipa-users] ipa python client - group_remove_member

2016-03-03 Thread Rob Crittenden
bahan w wrote: > Hello everyone ! > > I send you this mail because I'm using the python libraries and I'm > encountering a blocking problem when trying to use the > api.Command['group_remove_member'] command. > > I don't really know what is the syntax of this command. > I know how to make work th

[Freeipa-users] ipa python client - group_remove_member

2016-03-03 Thread bahan w
Hello everyone ! I send you this mail because I'm using the python libraries and I'm encountering a blocking problem when trying to use the api.Command['group_remove_member'] command. I don't really know what is the syntax of this command. I know how to make work the api.Command['user_show'](user

Re: [Freeipa-users] Some high level questions (DNS & CA)

2016-03-03 Thread Martin Basti
Hello, comments inline On 03.03.2016 13:11, Geselle Stijn wrote: Hello, We have a large Windows environment and around 50 RHEL servers (which will grow to a few hundred in the future). Our goal is to be able to login with our AD credentials and have sudo centrally managed. To be able to ma

[Freeipa-users] Some high level questions (DNS & CA)

2016-03-03 Thread Geselle Stijn
Hello, We have a large Windows environment and around 50 RHEL servers (which will grow to a few hundred in the future). Our goal is to be able to login with our AD credentials and have sudo centrally managed. To be able to manage users and their access/permissions we are looking into IdM combin

Re: [Freeipa-users] Kerberos authentication from a third party app - Shibboleth

2016-03-03 Thread Prashant Bapat
I guess I was looking at this wrongly! Simo, you're right! Java and Kerberos wont work ! However password+OTP against LDAP server directly works! I can use that! Thanks for your help! On 3 March 2016 at 14:40, Prashant Bapat wrote: > Thanks. > > Let me figure out possible alternatives. > > On

Re: [Freeipa-users] Kerberos authentication from a third party app - Shibboleth

2016-03-03 Thread Prashant Bapat
Thanks. Let me figure out possible alternatives. On 3 March 2016 at 00:20, Simo Sorce wrote: > > > On Wed, 2016-03-02 at 16:25 +0530, Prashant Bapat wrote: > > Thanks. But my problem is not OTP per se but Kerberos thru Java. > > Specifically i'm getting below error. > > > > javax.security.auth.