[Freeipa-users] WARNING: Existing users or groups do not have a SID identifier assigned

2017-02-23 Thread Gady Notrica
Hello, When setting up a trust between IPA and AD I am having the Warning below. Question: Is this going to affect the users in Active Directory if IPA sync back with AD? # ipa-adtrust-install WARNING: 200 existing users or groups do not have a SID identifier assigned. Installer can run a

[Freeipa-users] WARNING: Existing users or groups do not have a SID identifier assigned

2017-02-23 Thread Gady Notrica
Hello, When setting up a trust between IPA and AD I am having the Warning below. Question: Is this going to affect the users in Active Directory if IPA sync back with AD? Any help? # ipa-adtrust-install WARNING: 200 existing users or groups do not have a SID identifier assigned. Installer

[Freeipa-users] httpd broken

2017-01-14 Thread Gady Notrica
Hey guys, After updating my IPA and http packages, httpd and samba are not starting. Something weird happening to the python code. Any idea? httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; disabled; vendor preset: disabled) Drop-In:

[Freeipa-users] ipa-replica-install command failed

2016-12-20 Thread Gady Notrica
Hello, Need some help installing replica - FREEIPA on Centos 7. My networking is run, DNS is up on the master IPA all ports are opened. But I can't isolate the problem. Any help? -- Error: The ipa-replica-install command failed, exception: SystemExit: Connection check failed! Please fix

Re: [Freeipa-users] Ldap error in ModifyPassword - 50: Insufficient access

2016-04-30 Thread Gady Notrica
Any help guys? Gady From: Gady Notrica Sent: April 29, 2016 1:37 PM To: 'freeipa-users@redhat.com' Subject: Ldap error in ModifyPassword - 50: Insufficient access Hey guys, After my previous issue, my password do not sync anymore with IPA. No password changed for the sync user. Any ideas

[Freeipa-users] Ldap error in ModifyPassword - 50: Insufficient access

2016-04-29 Thread Gady Notrica
Hey guys, After my previous issue, my password do not sync anymore with IPA. No password changed for the sync user. Any ideas? Thank you, 04/29/16 13:32:56: Ldap error in ModifyPassword 50: Insufficient access 04/29/16 13:32:56: Modify password failed for remote entry:

Re: [Freeipa-users] krb5kdc service not starting

2016-04-27 Thread Gady Notrica
All good!!! Gady -Original Message- From: Alexander Bokovoy [mailto:aboko...@redhat.com] Sent: April 27, 2016 1:19 PM To: Gady Notrica Cc: Ludwig Krispenz; freeipa-users@redhat.com Subject: Re: [Freeipa-users] krb5kdc service not starting On Wed, 27 Apr 2016, Gady Notrica wrote: >He

Re: [Freeipa-users] krb5kdc service not starting

2016-04-27 Thread Gady Notrica
r/2016:10:26:17 -0400] dse - Please edit the file to correct the reported problems and then restart the server. [root@cd-p-ipa1 log]# Gady From: Ludwig Krispenz [mailto:lkris...@redhat.com] Sent: April 27, 2016 10:06 AM To: Gady Notrica Cc: Rob Crittenden; freeipa-users@redhat.com Subject: Re: [Free

Re: [Freeipa-users] krb5kdc service not starting

2016-04-27 Thread Gady Notrica
OREDT$,cn=users,cn=accounts,dc=ipa,dc=candeal,dc=ca" missing attribute "sn" required by object class "person" [cid:image003.jpg@01D1A069.EF91B910] I don’t know if that helps. Gady From: Ludwig Krispenz [mailto:lkris...@redhat.com] Sent: April 27, 2016 3:18 AM To: G

Re: [Freeipa-users] krb5kdc service not starting

2016-04-26 Thread Gady Notrica
uest: 2 Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 26, 2016 2:44 PM To: Gady Notrica; Ludwig Krispenz; freeipa-users@redhat.com Subject: Re: [Freeipa-users] krb5kdc service not starting Gady Notrica wrote: > Hey world, > > An

Re: [Freeipa-users] krb5kdc service not starting

2016-04-26 Thread Gady Notrica
Hey world, Any ideas? Gady -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Gady Notrica Sent: April 26, 2016 10:10 AM To: Ludwig Krispenz; freeipa-users@redhat.com Subject: Re: [Freeipa-users] krb5kdc service

Re: [Freeipa-users] krb5kdc service not starting

2016-04-26 Thread Gady Notrica
No, no changes. Lost connectivity with my VMs during the night (networking issues in datacenter) Reboot the server and oups, no IPA is coming up... The replica (secondary server) is fine though. Gady Notrica -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa

Re: [Freeipa-users] krb5kdc service not starting

2016-04-26 Thread Gady Notrica
redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Martin Babinsky Sent: April 26, 2016 9:17 AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] krb5kdc service not starting On 04/26/2016 03:13 PM, Gady Notrica wrote: > Hello world, > > > > I am having issues this morning

[Freeipa-users] krb5kdc service not starting

2016-04-26 Thread Gady Notrica
;; WHEN: Tue Apr 26 09:02:43 EDT 2016 ;; MSG SIZE rcvd: 282 Gady Notrica | IT Systems Analyst | 416.814.7800 Ext. 7921 | Cell. 416.818.4797 | gnotr...@candeal.com<mailto:gnotr...@candeal.com> CanDeal | 152 King St. E, 4th Floor, Toronto ON M5A 1J4 | www.candeal.com<http://www.cande

[Freeipa-users] RoundRobin - Cname - 2 servers with same services

2016-04-22 Thread Gady Notrica
Hello World, I am trying to enable roundrobin on freeipa. I have 2 servers providing same service (http). I am trying to give it a friendly name so that when user what to access it, they can land on any one of the 2 servers. But IPA dns doesn't want to let me create CName that has the same

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
, 2016 4:16 PM To: Gady Notrica Cc: Rob Crittenden; Martin Basti; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa-client-install errors On (20/04/16 20:10), Gady Notrica wrote: >[root@cd-s-prd-db1 krb5.include.d]# ls -l > >-rw-r--r--. 1 root root 224 Apr

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
.x86_64 #1 SMP Thu Mar 31 16:04:38 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux It's Centos 7. Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 20, 2016 4:04 PM To: Gady Notrica; Martin Basti; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
Original file attached - no changes to the file Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 20, 2016 3:52 PM To: Gady Notrica; Martin Basti; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa-client-install errors Gady Notrica wrote

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
] # .example.com = EXAMPLE.COM # example.com = EXAMPLE.COM [root@prddb1]# Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 20, 2016 3:14 PM To: Gady Notrica; Martin Basti; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa-client-install errors Gady

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
certificates in /etc/ipa/nssdb: Command ''/usr/bin/certutil' '-d' '/etc/ipa/nssdb' '-L'' returned non-zero exit status 255 Disabling client Kerberos and LDAP configurations Gady Notrica -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
initialization failed [root@cprddb1 /]# Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 20, 2016 1:59 PM To: Martin Basti; Gady Notrica; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa-client-install errors Martin Basti wrote: > > > On 20.04.2

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
Thank you Martin, I have tried many different ways. I can't seem to be able to remove anything in the file. Gady From: Martin Basti [mailto:mba...@redhat.com] Sent: April 20, 2016 12:50 PM To: Gady Notrica; freeipa-users@redhat.com Subject: Re: [Freeipa-users] ipa-client-install errors

Re: [Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
On 04/20/2016 06:00 PM, Gady Notrica wrote: > Hello World, > > I am having these errors trying to install ipa-client-install. Every > other machine is fine and they IPA servers are functioning perfectly > > Error trying to clean keytab: /usr/sbin/ipa-rmkeytab returned 1 > >

[Freeipa-users] ipa-client-install errors

2016-04-20 Thread Gady Notrica
Hello World, I am having these errors trying to install ipa-client-install. Every other machine is fine and they IPA servers are functioning perfectly Error trying to clean keytab: /usr/sbin/ipa-rmkeytab returned 1 Kerberos authentication failed: kinit: Improper format of Kerberos

Re: [Freeipa-users] NEEDED_PREAUTH: Additional pre-authentication required - User can't access any centos server

2016-04-18 Thread Gady Notrica
Hi Rob, Thanks for the reply. I did reset the user password multiple times to a simple password, still having same issue. Gady -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: April 18, 2016 2:25 PM To: Gady Notrica; freeipa-users@redhat.com Subject: Re

[Freeipa-users] NEEDED_PREAUTH: Additional pre-authentication required - User can't access any centos server

2016-04-18 Thread Gady Notrica
domain@ipa.domain.com, Decrypt integrity check failed Gady Notrica | IT Systems Analyst | 416.814.7800 Ext. 7921 | Cell. 416.818.4797 | gnotr...@candeal.com<mailto:gnotr...@candeal.com> CanDeal | 152 King St. E, 4th Floor, Toronto ON M5A 1J4 | www.candeal.com<http://www.candeal.ca/> | Follo

[Freeipa-users] IPA-Server installation

2016-01-13 Thread Gady Notrica
ecuredata.com/centos/7.2.1511/updates/x86_64/repodata/b0789cdf06109ebe3313dab51585247700dd285b7eb0bc83f9d80a90cf2360f6-primary.sqlite.bz2: [Errno 14] HTTP Error 404 - Not Found Gady Notrica | IT Systems Analyst | 416.814.7800 Ext. 7921 | Cell. 416.818.4797 | gnotr...@candeal.com<mailto:gnotr.