Re: [Freeipa-users] [sssd[pam]] [pam_reply] (0x0200): pam_reply called with result [6]: Permission denied.

2017-01-08 Thread TomK
On 1/8/2017 12:22 AM, TomK wrote: Hey All, Wanted to tap your experience a bit. Do you recall under which conditions this error can be triggered under? (Sun Jan 8 00:15:17 2017) [sssd[pam]] [pam_dp_process_reply] (0x0200): received: [6 (Permission denied)][mds.xyz] (Sun Jan 8 00:15:17 2017

[Freeipa-users] [sssd[pam]] [pam_reply] (0x0200): pam_reply called with result [6]: Permission denied.

2017-01-07 Thread TomK
Hey All, Wanted to tap your experience a bit. Do you recall under which conditions this error can be triggered under? (Sun Jan 8 00:15:17 2017) [sssd[pam]] [pam_dp_process_reply] (0x0200): received: [6 (Permission denied)][mds.xyz] (Sun Jan 8 00:15:17 2017) [sssd[pam]] [pam_reply] (0x0200)

Re: [Freeipa-users] FreeIPA + /etc/named.conf

2017-01-06 Thread TomK
On 1/5/2017 2:17 PM, Martin Basti wrote: On 05.01.2017 20:03, TomK wrote: Hey All, QQ. Should the DNS forwarders be updated in /etc/named.conf? Until I manually change /etc/named.conf, can't ping the windows AD cluster: mds.xyz. Nor can I get dig to resolve the SRV records (dig SRV

[Freeipa-users] FreeIPA + /etc/named.conf

2017-01-05 Thread TomK
Hey All, QQ. Should the DNS forwarders be updated in /etc/named.conf? Until I manually change /etc/named.conf, can't ping the windows AD cluster: mds.xyz. Nor can I get dig to resolve the SRV records (dig SRV _ldap._tcp.mds.xyz). sssd-ipa-1.14.0-43.el7_3.4.x86_64 ipa-client-4.4.0-14.el7.c

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-08 Thread TomK
On 12/6/2016 3:37 PM, Alexander Bokovoy wrote: On ti, 06 joulu 2016, TomK wrote: On 12/5/2016 2:02 AM, Alexander Bokovoy wrote: On su, 04 joulu 2016, TomK wrote: Could not get much from logs and decided to start fresh. When I run this: ipa trust-add --type=ad mds.xyz --admin Administrator

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-07 Thread TomK
On 12/6/2016 11:32 PM, TomK wrote: On 12/6/2016 3:37 PM, Alexander Bokovoy wrote: On ti, 06 joulu 2016, TomK wrote: On 12/5/2016 2:02 AM, Alexander Bokovoy wrote: On su, 04 joulu 2016, TomK wrote: Could not get much from logs and decided to start fresh. When I run this: ipa trust-add

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-05 Thread TomK
On 12/5/2016 2:02 AM, Alexander Bokovoy wrote: On su, 04 joulu 2016, TomK wrote: Could not get much from logs and decided to start fresh. When I run this: ipa trust-add --type=ad mds.xyz --admin Administrator --password Trust works fine and id t...@mds.xyz returns a valid result. However

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-04 Thread TomK
On 12/3/2016 12:57 PM, TomK wrote: On 12/3/2016 12:33 AM, TomK wrote: On 12/2/2016 8:43 AM, Sumit Bose wrote: On Fri, Dec 02, 2016 at 08:30:28AM -0500, TomK wrote: Hey All, I've successfully mapped the nixadmins to the external group nixadmins_external. However no users in that group

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-03 Thread TomK
On 12/3/2016 12:33 AM, TomK wrote: On 12/2/2016 8:43 AM, Sumit Bose wrote: On Fri, Dec 02, 2016 at 08:30:28AM -0500, TomK wrote: Hey All, I've successfully mapped the nixadmins to the external group nixadmins_external. However no users in that group make it over to Free IPA that I ca

Re: [Freeipa-users] Mapping users from AD to IPA KDC

2016-12-02 Thread TomK
On 12/2/2016 8:43 AM, Sumit Bose wrote: On Fri, Dec 02, 2016 at 08:30:28AM -0500, TomK wrote: Hey All, I've successfully mapped the nixadmins to the external group nixadmins_external. However no users in that group make it over to Free IPA that I can see. ipa group-add-m

[Freeipa-users] Mapping users from AD to IPA KDC

2016-12-02 Thread TomK
Hey All, I've successfully mapped the nixadmins to the external group nixadmins_external. However no users in that group make it over to Free IPA that I can see. ipa group-add-member nixadmins_external --external "nixadmins" Windows AD users, 3 of them, are in the windows AD group nixadmins

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-25 Thread TomK
On 11/25/2016 9:09 AM, Petr Spacek wrote: On 25.11.2016 14:48, TomK wrote: On 11/25/2016 4:00 AM, Petr Spacek wrote: On 25.11.2016 05:57, TomK wrote: On 11/24/2016 4:49 AM, Petr Spacek wrote: On 24.11.2016 06:08, TomK wrote: On 11/23/2016 3:28 AM, Martin Basti wrote: On 23.11.2016 03:48

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-25 Thread TomK
On 11/25/2016 4:00 AM, Petr Spacek wrote: On 25.11.2016 05:57, TomK wrote: On 11/24/2016 4:49 AM, Petr Spacek wrote: On 24.11.2016 06:08, TomK wrote: On 11/23/2016 3:28 AM, Martin Basti wrote: On 23.11.2016 03:48, TomK wrote: On 11/22/2016 10:22 AM, Martin Basti wrote: On 22.11.2016 13

Re: [Freeipa-users] anyone else getting porn spam pretending to be replies to freeipa-users threads?

2016-11-24 Thread TomK
On 11/16/2016 11:23 AM, Sean Hogan wrote: Yes... just got 2 of them from same address.. kimi rachel Sean Hogan Inactive hide details for Tony Brian Albers ---11/15/2016 11:54:35 PM---Hehe, just you wait Lachlan ;) /tonyTony Brian Albers ---11/15/2016 11:54:35 PM---Hehe, just you wait

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-24 Thread TomK
On 11/24/2016 4:49 AM, Petr Spacek wrote: On 24.11.2016 06:08, TomK wrote: On 11/23/2016 3:28 AM, Martin Basti wrote: On 23.11.2016 03:48, TomK wrote: On 11/22/2016 10:22 AM, Martin Basti wrote: On 22.11.2016 13:57, TomK wrote: On 11/22/2016 2:59 AM, Martin Basti wrote: Hey, On

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-23 Thread TomK
On 11/23/2016 3:28 AM, Martin Basti wrote: On 23.11.2016 03:48, TomK wrote: On 11/22/2016 10:22 AM, Martin Basti wrote: On 22.11.2016 13:57, TomK wrote: On 11/22/2016 2:59 AM, Martin Basti wrote: Hey, On 22.11.2016 06:33, TomK wrote: Hey Guy's, I'm forwarding a domain d

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-22 Thread TomK
On 11/22/2016 10:22 AM, Martin Basti wrote: On 22.11.2016 13:57, TomK wrote: On 11/22/2016 2:59 AM, Martin Basti wrote: Hey, On 22.11.2016 06:33, TomK wrote: Hey Guy's, I'm forwarding a domain dom.abc.xyz from a Windows Server 2012 over to my dual Free IPA server. The Free I

Re: [Freeipa-users] Ping forwarded domain name.

2016-11-22 Thread TomK
On 11/22/2016 2:59 AM, Martin Basti wrote: Hey, On 22.11.2016 06:33, TomK wrote: Hey Guy's, I'm forwarding a domain dom.abc.xyz from a Windows Server 2012 over to my dual Free IPA server. The Free IPA servers are authoritative for this subdomain. The Windows Server 2012 DNS is r

[Freeipa-users] Ping forwarded domain name.

2016-11-21 Thread TomK
Hey Guy's, I'm forwarding a domain dom.abc.xyz from a Windows Server 2012 over to my dual Free IPA server. The Free IPA servers are authoritative for this subdomain. The Windows Server 2012 DNS is resolves on abc.xyz and forwards dom.abc.xyz. I cannot ping dom.abc.xyz. Everything else, in

Re: [Freeipa-users] HBAC

2015-10-01 Thread TomK
On 10/1/2015 12:04 PM, Simo Sorce wrote: On 30/09/15 21:22, TomK wrote: On 9/30/2015 8:12 AM, Martin Kosek wrote: On 09/30/2015 07:50 AM, Alexander Bokovoy wrote: On Tue, 29 Sep 2015, TomK wrote: Hey Guy's, (Sending this again as I didn't have this email included in the fre

Re: [Freeipa-users] HBAC

2015-09-30 Thread TomK
On 9/30/2015 8:12 AM, Martin Kosek wrote: On 09/30/2015 07:50 AM, Alexander Bokovoy wrote: On Tue, 29 Sep 2015, TomK wrote: Hey Guy's, (Sending this again as I didn't have this email included in the freeipa-users mailing list so not sure if the other message will get posted.) Bef

[Freeipa-users] HBAC

2015-09-29 Thread TomK
deas folks have. I've a situation as follows. I have the following setup in WS 2012 AD DC: TomK (user) TomK Groups: unixg windowsg unixg has the 'host' attribute defined 'lab01,lab02,lab03,lab04' windowsg has the 'host' attribute