Re: [Freeipa-users] AD trust deployment without IPA authority over reverse lookup zone

2015-08-01 Thread John Stein
Hi, Thanks for the reply. Any Idea when will the GSSAPI-updating bug fix get to RHEL 7? Thanks again, John On Mon, Jul 27, 2015 at 5:30 PM Alexander Bokovoy wrote: > On Mon, 27 Jul 2015, John Stein wrote: > >Hi, > > > >I consider deploying IPA in my organizati

[Freeipa-users] AD trust deployment without IPA authority over reverse lookup zone

2015-07-27 Thread John Stein
Hi, I consider deploying IPA in my organization.The environment is disconnected from the internet.I have some concerns I'm not sure how to resolve. The environment consists mostly of windows servers (thousands) and workstations (ten thousand) managed by AD (CORP.COM). There is also a small linux

Re: [Freeipa-users] reverse lookup dns records in trust setup

2015-07-18 Thread John Stein
Hi, Does that mean deleting the NS record on AD and creating an A record instead? Thanks, John On Wed, Jul 15, 2015, 18:28 Petr Spacek wrote: > On 14.7.2015 15:19, John Stein wrote: > > Hi, > > > > What I meant was that the IPA server is managing two zones: > > &

Re: [Freeipa-users] reverse lookup dns records in trust setup

2015-07-14 Thread John Stein
com >>linux (Same as parent folder) NS ipa1.linux.john.com Anything more that's unclear? Thank you very much! John On Tue, Jul 14, 2015, 15:52 Petr Spacek wrote: > On 14.7.2015 14:49, John Stein wrote: > > I ran the above commands exactly as I told you on the IPA server. I also

Re: [Freeipa-users] reverse lookup dns records in trust setup

2015-07-14 Thread John Stein
I ran the above commands exactly as I told you on the IPA server. I also set the IPA server as a global forwarder in the AD. On Wed, Jul 8, 2015, 12:50 Petr Spacek wrote: > On 5.7.2015 08:38, John Stein wrote: > > Hi, > > > > I ran these commands in the IdM server >

Re: [Freeipa-users] IPA Replication Questions

2015-07-07 Thread John Stein
> Wiadomość napisana przez John Stein w dniu 7 lip > 2015, o godz. 07:56: > > > Hi, > > > > Looking at the documentation, I've found no examples of creating > replication agreement with only one server. > > > > What I assume needs to be done is this:

Re: [Freeipa-users] Using NTP SRV records

2015-07-07 Thread John Stein
Thank you (both of you) John On Tue, Jul 7, 2015 at 2:42 PM Baird, Josh wrote: > You need to specify '--no-ntp' on 'ipa-client-install' > > > > Josh > > > > *From:* freeipa-users-boun...@redhat.com [mailto: > freeipa-users-boun...@redhat.com]

[Freeipa-users] Using NTP SRV records

2015-07-07 Thread John Stein
Hi, I have an IPA server installed with --no-ntp, and created SRV records _ntp._udp_.linux.john.com pointing to my actual NTP servers. However, when I run ipa-client-install it is configured with the IPA server as an NTP server. Am I missing something? Thanks, John -- Manage your subscription f

[Freeipa-users] IPA Replication Questions

2015-07-06 Thread John Stein
Hi, Looking at the documentation, I've found no examples of creating replication agreement with only one server. What I assume needs to be done is this: For each replica, run ipa-replica-prepare and follow the documentation. This creates replication agreements between two nodes. >From there, I sh

Re: [Freeipa-users] reverse lookup dns records in trust setup

2015-07-04 Thread John Stein
client is not. Maybe there's another thing I need to configure in the AD in order to enable forwarding that I'm missing? Thank you very much, John On Mon, Jun 29, 2015 at 4:52 PM Petr Spacek wrote: > On 29.6.2015 13:57, John Stein wrote: > > Hi, > > > > I have an

[Freeipa-users] reverse lookup dns records in trust setup

2015-06-29 Thread John Stein
Hi, I have an AD and IdM server. AD domain - john.com IdM domain - linux.john.com each spans multiple netwrok segments, with some segments having both linux and windows machines. the IdM is configured to forward DNS requests to AD (forward first), and the AD is configured to forward requests in

Re: [Freeipa-users] Installing FreeIPA 3.1 -> 3.3 On RHEL

2014-02-18 Thread John Stein
solved for RHEL 6.x.? 3) What is the newest version that i can run on RHEL 6.x without losing my mind? 4) Will it be easier to Install IPA 3.3 on RHEL 7 (beta)? Thanks again, John On Feb 17, 2014 10:12 PM, "Alexander Bokovoy" wrote: > On Mon, 17 Feb 2014, John Stein wrote: > &g

[Freeipa-users] Installing FreeIPA 3.1 -> 3.3 On RHEL

2014-02-17 Thread John Stein
Hi all. The newest IPA version that exists in the RHN repository is 3.0.0-37. I would like to install IPA version greater then 3.0 on RHEL 6.x. How would you recommend installing newer versions? Using Fedora repository, EPEL or just download the tarball and build it? thank you very much, John