[Freeipa-users] How to clean out(reset) FreeIPA,

2017-01-25 Thread Tony Brian Albers
Hi guys, Is there a way to expunge everything except admin account from IPA? We have a supercomputer test installation here that needs it, and a reset is preferable over a complete reinstall. TIA Tony -- Best regards, Tony Albers Systems administrator, IT-development Royal Danish Library, Vi

Re: [Freeipa-users] anyone else getting porn spam pretending to be replies to freeipa-users threads?

2016-11-15 Thread Tony Brian Albers
Hehe, just you wait Lachlan ;) /tony On 11/16/2016 01:56 AM, Lachlan Musicman wrote: > Gah, just happened to me. Wasn't porn, but was someone called Kimi and > the only content was "Heeey Lachlan, how's it going?" > > L. > > -- > The most dangerous phrase in the language is, "We've always don

[Freeipa-users] krb5 and nfsv4 not working right

2016-11-15 Thread Tony Brian Albers
Hi guys, I've followed every guide I can find on this subject. What I'm trying to is to get our home directories which are shared via NFS from the FreeIPA server mounted via autofs on the clients. The client is kact-man-001 and the FreeIPA server is kact-adm-001 /etc/exports: I've done the i

Re: [Freeipa-users] can't get sudo to work.

2016-08-24 Thread Tony Brian Albers
And indeed the compat tree was disabled. Guess I forgot to reenable it after copying the db to a testing environment. Thanks guys, sudo is working fine now. /tony On Tue, 2016-08-23 at 10:13 -0400, Rob Crittenden wrote: > Pavel Březina wrote: > > On 08/23/2016 01:55 PM, Tony Brian Alb

Re: [Freeipa-users] can't get sudo to work.

2016-08-23 Thread Tony Brian Albers
d or bad?) Any advice is appreciated. /tony On Tue, 2016-08-23 at 09:17 +0200, Jakub Hrozek wrote: > On Tue, Aug 23, 2016 at 07:11:44AM +, Tony Brian Albers wrote: > > Thanks Simon, > > > > Is this a known issue? We're on Centos 7.2 and yes, the sssd version is &g

Re: [Freeipa-users] can't get sudo to work.

2016-08-23 Thread Tony Brian Albers
om: freeipa-users-boun...@redhat.com > [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Tony Brian Albers > Sent: Tuesday, 23 August 2016 4:24 PM > To: freeipa-users@redhat.com > Subject: [Freeipa-users] can't get sudo to work. > > Hi guys, > > I've been tr

[Freeipa-users] can't get sudo to work.

2016-08-22 Thread Tony Brian Albers
Hi guys, I've been trying to get sudo to work for our day-to-day admin who have their own usergroup in IPA called subadmin. For some reason I can't really get sudo to work, I suspect I am missing something simple, but I can't really figure out what it is. This is my config: # ipa sudorule-find

Re: [Freeipa-users] sudo Cmnd_Alias ?

2016-08-09 Thread Tony Brian Albers
On Tue, 2016-08-09 at 10:16 +0200, Jakub Hrozek wrote: > On Tue, Aug 09, 2016 at 07:12:30AM +0000, Tony Brian Albers wrote: > > Hi guys, > > > > I'm working on getting ambari from IBM BigInsights working using sudo in > > FreeIPA, and I've come across t

[Freeipa-users] sudo Cmnd_Alias ?

2016-08-09 Thread Tony Brian Albers
Hi guys, I'm working on getting ambari from IBM BigInsights working using sudo in FreeIPA, and I've come across the following(there are a few of these): Cmnd_Alias BIGSQL_SERVICE_AGNT= /var/lib/ambari-agent/cache/stacks/BigInsights/*/services/BIGSQL/package/scripts/* Does anyone know ho

Re: [Freeipa-users] copying through intermediate host. SOLVED

2016-07-08 Thread Tony Brian Albers
Ok, so I managed to get this fixed, It turned out that I ssh port-forwarded in the wrong direction. So the solution is as follows: [workstation1]# ssh -L 9000:localhost:389 root@server1 [server1]# [workstation1]# ssh -R 9100:localhost:9000 root@server2 [server2]# echo password | ipa migrate-ds

Re: [Freeipa-users] copying through intermediate host.

2016-07-08 Thread Tony Brian Albers
ver2net cn: Administrator objectClass: posixAccount objectClass: ipaOverrideTarget So, I can connect to server2 on server1's port 9100 but I can't get ipa migrate-ds to use it. And I did a kinit admin on server1 first ;) Any suggestione are appreciated. /tony On Fri, 2016-07-08 at 08:

[Freeipa-users] copying through intermediate host.

2016-07-08 Thread Tony Brian Albers
Hi Guys, I'm trying to copy relevant users and groups from one IPA server(server1) to another(server2). This is they can't talk to one another, they can't even establish connections to something outside their own networks. SSH into the servers from where I am(workstation1) works fine for both of t

[Freeipa-users] Apache Knox and FreeIPA

2016-06-02 Thread Tony Brian Albers
Hi guys, Do any of you have this setup working? And if so, how did you do it? Thanks, Tony -- Best regards, Tony Albers Systems administrator, IT-development State and University Library, Victor Albecks Vej 1, 8000 Aarhus C, Denmark. Tel: +45 8946 2316 -- Manage your subscription for the

[Freeipa-users] Sudo ALL rule

2016-05-31 Thread Tony Brian Albers
Hi guys, I'm implementing FreeIPA to auhenticate users on a small HPC cluster here. For a few of these I need a sudo rule that in essence does the same as the standard ALL(ALL) rule. How do I implement that in FreeIPA? I've found some links/guides on the net, but they don't seem appropriate for o