Re: [Freeipa-users] named-pkcs11 doesn't start after bind update

2016-08-17 Thread Arthur Fayzullin
any news? I've tried to make selinux permissive and write new policy, that didn't help. require { type ipa_var_lib_t; type named_t; class dir read; class file { write open lock read getattr }; } #= named_t == allow named_t ipa_var_lib_t:dir

Re: [Freeipa-users] question about automount config

2016-06-07 Thread Arthur Fayzullin
ght. Also, does your > autofs setup work without kerberos ? As a first step it to work with > non-kerberised nfs. > > On Mon, May 23, 2016 at 11:06 AM, Arthur Fayzullin <art...@deus.pro > <mailto:art...@deus.pro>> wrote: > > Good day, colleagues! >

Re: [Freeipa-users] question about automount config

2016-05-30 Thread Arthur Fayzullin
does your > autofs setup work without kerberos ? As a first step it to work with > non-kerberised nfs. > > On Mon, May 23, 2016 at 11:06 AM, Arthur Fayzullin <art...@deus.pro > <mailto:art...@deus.pro>> wrote: > > Good day, colleagues! > I am confused about

[Freeipa-users] question about automount config

2016-05-23 Thread Arthur Fayzullin
Good day, colleagues! I am confused about how automount work and howto configure it. I have tried to configure it according to https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html document (paragraph 9.1.1

Re: [Freeipa-users] FreeRadius and FreeIPA

2016-01-18 Thread Arthur Fayzullin
Thank for such good explanation! that has pointed my search. I have succeed in integration freeradius with freeipa by help of William Brown and his blog. Thanks to Him :-) Links to related articles in his blog: first part: https://firstyear.id.au/entry/22 second part:

[Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Arthur Fayzullin
Good day, Colleagues! And Happy New Year! I have tried to install test stend with ipa v4.2 and 2 master-master servers. files /etc/hosts on both servers contain: 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 ::1 localhost localhost.localdomain localhost6

Re: [Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Arthur Fayzullin
Bingo!!! that it is!!! dm password contains % - symbol! I am not sure but with previous versions that have not caused any problem. Thanks a lot! 11.01.2016 16:48, Martin Kosek пишет: > On 01/11/2016 12:01 PM, Arthur Fayzullin wrote: >> Good day, Colleagues! >> >> And Ha

Re: [Freeipa-users] FreeRadius and FreeIPA

2015-12-12 Thread Arthur Fayzullin
I think these are the good points to start: https://www.eduroam.us/node/90 http://wiki.freeradius.org/modules/Rlm_krb5 I You'll be succeeded how-to will be awesome ;-) 09.12.2015 19:52, Randy Morgan пишет: > Hello, > > We are setting up our wireless to authenticate against FreeRadius and >

[Freeipa-users] some documentation issues

2015-05-11 Thread Arthur Fayzullin
Have a nice day! I think that I have found somethings that are mispresent and unpresent in documentation. I have tried to configure debian jessie as a freeipa client. This has been done in 2 ways: * reference instalation: I have installed freeipa-client package from sid and configured host by

Re: [Freeipa-users] some documentation issues

2015-05-11 Thread Arthur Fayzullin
В Пн, 11/05/2015 в 11:35 -0400, Dmitri Pal пишет: AFAIR some time ago we stopped fetching host cert by default. There was no use of it so we decided not issue a cert that has not practical use. -- Thank you, Dmitri Pal Director of Engineering for IdM portfolio Red Hat, Inc. Yes, I

Re: [Freeipa-users] Fedora Core IPTables or FirewallID?

2014-08-27 Thread Arthur Fayzullin
I've got something like this: $ sudo firewall-cmd --permanent --list-all [sudo] password for afayzullin: public (default) interfaces: sources: services: dhcpv6-client dns http https kerberos kpasswd ldap ldaps ntp ssh ports: 7389/tcp masquerade: no forward-ports: icmp-blocks: rich

Re: [Freeipa-users] Install FreeIPA 4 on ubuntu

2014-08-22 Thread Arthur Fayzullin
Can confirm that does work :) 21.08.2014 12:40, Lukas Slebodnik пишет: On (20/08/14 20:27), Chris Whittle wrote: Is there instructions anywhere? My FreeIPA 3 on CentOS died so I'm starting over You can try FreeIPA 3.3. on CentOS 7 bash-4.2# yum info ipa-server Loaded plugins:

[Freeipa-users] IPA-server and conrainers

2014-06-10 Thread Arthur Fayzullin
HI! Alexandr, I've seen Your presentation at RedHat forum. Very good presentation! :) I've got a question about FreeIPA from that presentation. Of course question is not only for You. So, the question: Are there any plans for integration freeipa-server with containers? * working freeipa as a

Re: [Freeipa-users] IPA-server and conrainers

2014-06-10 Thread Arthur Fayzullin
Running IPA as a bunch of containers can reduce size of each one. Of course then total size will be much greater. 10.06.2014 18:10, Jan Pazdziora пишет: On Tue, Jun 10, 2014 at 05:27:40PM +0600, Arthur Fayzullin wrote: HI! Alexandr, I've seen Your presentation at RedHat forum. Very good

Re: [Freeipa-users] DDNS with DHCPD and IPA

2014-04-09 Thread Arthur Fayzullin
If this http://www.freeipa.org/page/Howto/ISC_DHCPd_and_Dynamic_DNS_update is it, then it is quite not easy to understand what is it about. here, in mail-list it was much more understandable. 10.04.2014 00:20, Dmitri Pal ?: On 04/09/2014 11:58 AM, Andy Tomlin wrote: Ok, I added a howto page

Re: [Freeipa-users] Getting Samba to authenticate against FreeIPA

2013-03-23 Thread Arthur Fayzullin
24.03.2013 04:27, Martin пишет: Hello, apologize if this is a faq. We're trying to set up a file server that authenticate all users against a FreeIPA-server. The systems are up to date CentOS 6 machines and everything works just swell for logins and NFS4-mounts. However, we're completely stuck

[Freeipa-users] libsssd_sudo as dependency to ipa-client

2013-03-21 Thread Arthur Fayzullin
HI! I have configured sssd_sudo integration on EL6.4 and it works nice! But then I've checked this: [afaizullin@domen00 ~]$ sudo package-cleanup --leaves [sudo] password for afaizullin: Loaded plugins: fastestmirror libertas-usb8388-firmware-5.110.22.p23-3.1.el6.noarch