Re: [Freeipa-users] Are replica gpg files reusable?

2014-04-25 Thread Justin Brown
This type of behavior is generally beyond what Puppet should do because it involves two systems retrieving information directly from one another and the puppet master can't reasonably serve as the repository of that information. Using a separate tool will likely work better. There's at least two wa

[Freeipa-users] Partial Domain Authority

2014-04-08 Thread Justin Brown
I'm sure that I'm doing this very wrong, but I'm wondering if anyone can offer any solutions. I currently have a relatively small domain that's used internally. Let's say fandingo.org. This domain covers various class C networks on 192.168.0.0/16. Currently, there's an Active Directory server that

Re: [Freeipa-users] Server Ports

2014-04-03 Thread Justin Brown
en just in the documentation. Thanks, Justin On Thu, Apr 3, 2014 at 2:25 AM, Petr Spacek wrote: > On 3.4.2014 07:55, Justin Brown wrote: >> >> I'm having some trouble determining which ports my servers need open >> to communicate and what ports client servers and use

[Freeipa-users] Server Ports

2014-04-02 Thread Justin Brown
I'm having some trouble determining which ports my servers need open to communicate and what ports client servers and users will need. The last documentation that I was able to find was included in Fedora 15 (http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/installing-ipa.html). I o

[Freeipa-users] Exporting a PEM Certificate for OpenStack Keystone

2013-07-21 Thread Justin Brown
Hi, I'm having some trouble understanding certificates in general and service certificates in FreeIPA. Keystone if the authentication layer for OpenStack, and I'm trying to get it setup to integrate with the certificates in my FreeIPA domain. By default, Keystone setups up a self-signed CA based

Re: [Freeipa-users] FreeIPA 3.1.5 User Guide published!

2013-06-25 Thread Justin Brown
I'm also a big fan of the documentation and reference it frequently. I know that documentation is not release notes, but it would be nice to have some relation between the two. Two ideas: * If the docs are released at the same time as the software, the release notes should include links to the rel

Re: [Freeipa-users] Anyone tried to authenticate Jenkins user through freeIPA?

2013-06-24 Thread Justin Brown
William, I am no FreeIPA expert, but I did find some instructions for configuring LDAP with Zimbra for FreeIPA. http://www.freeipa.org/page/Zimbra_Collaboration_Server_7.2_Authentication_and_GAL_lookups_against_FreeIPA Have you tried something similar? Regards, Justin On Mon, Jun 24, 2013 at 5

[Freeipa-users] Connect to FreeIPA's LDAP Directory

2013-05-27 Thread Justin Brown
I'm working on a small project that needs access to user information (primarily email addresses and phone numbers) from a LDAP directory. I'm successfully using FreeIPA for general authentication and DNS in my lab and would like to have this application use FreeIPA as well. I need to be able to bi