Re: [Freeipa-users] Error when adding new users via UI:

2016-07-05 Thread Traiano Welcome
Finally got around to fixing this: On Tue, May 24, 2016 at 5:15 PM, Martin Kosek <mko...@redhat.com> wrote: > On 05/24/2016 04:07 PM, Rob Crittenden wrote: >> Traiano Welcome wrote: >>> Hi >>> >>> I have IPA server 4,2 running on centos 7 &g

[Freeipa-users] Error when adding new users via UI:

2016-05-24 Thread Traiano Welcome
Hi I have IPA server 4,2 running on centos 7 (ipa-server-4.2.0-15.el7.centos.3.x86_64). This morning, after many months of stable operation, I tried to add a user and got this error via the web interface: --- Operations error: Allocation of a new value for range cn=posix ids,cn=distributed

Re: [Freeipa-users] FreeIPA Clients behind unreliable network links at remote sites

2015-12-07 Thread Traiano Welcome
Hi Jakub On Mon, Dec 7, 2015 at 12:00 PM, Jakub Hrozek <jhro...@redhat.com> wrote: > On Sun, Dec 06, 2015 at 09:58:58PM +0300, Traiano Welcome wrote: >> Hi List >> >> >> Current Scenario: >> = >> >> I have a number of stores on r

[Freeipa-users] FreeIPA Clients behind unreliable network links at remote sites

2015-12-06 Thread Traiano Welcome
Hi List Current Scenario: = I have a number of stores on really unreliable network connections: It's quite possible for the links to have been down for 3 - 4 days at a time. In a given store is a single Linux "Back Office" server running Directory 389 which holds credentials for a

[Freeipa-users] Cleanly Removing a Stubborn IPA Replica Server

2015-09-17 Thread Traiano Welcome
Hi All I'm trying to delete replication agreements between a 'master' ipa server and a replica, but it seems the directory server has gotten into a state where the replication agreements can't be removed (or some other stale meta-data is still hanging around). (CentOS Linux release 7.1.1503,

[Freeipa-users] FreeIPA On SuSE (SLES 11, 12, and up)

2015-05-26 Thread Traiano Welcome
Hi All Has anyone successfully configured IPA v4.xx on SLES (specifically 11.x)? Thanks in advance, Traiano -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] .LDAPUpdate: ERROR Add failure missing required attribute objectclass

2015-04-12 Thread Traiano Welcome
Hi Dmitri Thanks for the response. On Mon, Apr 13, 2015 at 5:14 AM, Dmitri Pal d...@redhat.com wrote: On 04/11/2015 03:51 PM, Traiano Welcome wrote: Hi I got this error while installing an IPA replica of my primary master IDM server: .LDAPUpdate: ERRORAdd failure missing required

[Freeipa-users] .LDAPUpdate: ERROR Add failure missing required attribute objectclass

2015-04-11 Thread Traiano Welcome
Hi I got this error while installing an IPA replica of my primary master IDM server: .LDAPUpdate: ERRORAdd failure missing required attribute objectclass Replica add command: ipa-replica-install --setup-ca --setup-dns --no-forwarders /var/lib/ipa/replica-info-siteX-idm-slve.lol.local.gpg

Re: [Freeipa-users] krb5kdc: Server error

2015-04-08 Thread Traiano Welcome
Hi Ben On Wed, Apr 8, 2015 at 12:39 PM, Ben .T.George bentech4...@gmail.com wrote: HI i am getting krb5kdc: Server error on ligs: krb5kdc: Server error - while fetching master key K/M for realm SUN.LOCAL and the ipactl status is taking long time. Web interface is not able to

[Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
Hi List I've just tried to restart my IPA services after recently adding a new replica (0 configuration changes on the IPA server otherwise!), but ipactl fails when starting up named: --- [root@lolpr-xyz-mstr slapd-XYZ-LOCAL]# ipactl start Starting Directory Service Starting krb5kdc Service

Re: [Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
, 2015 at 9:56 AM, Traiano Welcome trai...@gmail.com wrote: Hi List I've just tried to restart my IPA services after recently adding a new replica (0 configuration changes on the IPA server otherwise!), but ipactl fails when starting up named: --- [root@lolpr-xyz-mstr slapd-XYZ-LOCAL

Re: [Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
Hi Martin Thanks for the response. Check results inline: On Wed, Apr 1, 2015 at 10:37 AM, Martin Babinsky mbabi...@redhat.com wrote: On 04/01/2015 09:20 AM, Traiano Welcome wrote: Some information from the dirsrv error log (sanitized: XYZ = realm): [01/Apr/2015:11:01:49 +0300] - 389

Re: [Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
Hi Dmitri On Wed, Apr 1, 2015 at 3:06 PM, Dmitri Pal d...@redhat.com wrote: On 04/01/2015 07:52 AM, Traiano Welcome wrote: Hi Dmitri On Wed, Apr 1, 2015 at 2:23 PM, Dmitri Pal d...@redhat.com wrote: On 04/01/2015 04:14 AM, Traiano Welcome wrote: Hi Martin Thanks for the response

Re: [Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
On Wed, Apr 1, 2015 at 2:20 PM, Martin Babinsky mbabi...@redhat.com wrote: On 04/01/2015 10:14 AM, Traiano Welcome wrote: Hi Martin Thanks for the response. Check results inline: On Wed, Apr 1, 2015 at 10:37 AM, Martin Babinsky mbabi...@redhat.com wrote: On 04/01/2015 09:20 AM

Re: [Freeipa-users] ipactl start fails for no apparent reason

2015-04-01 Thread Traiano Welcome
Crittenden rcrit...@redhat.com wrote: Traiano Welcome wrote: Hi Dmitri This is a freshly generated DS log (sanitized: XYZ = realm): 389-Directory/1.3.1.6 B2014.160.2139 lolpr-xyz-mstr.xyz.local:636 (/etc/dirsrv/slapd-XYZ-LOCAL) [01/Apr/2015:15:19:01 +0300] - 389-Directory

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
Hi Alexander On Tue, Mar 10, 2015 at 12:08 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Tue, 10 Mar 2015, Traiano Welcome wrote: However, I'm still not able to authenticate via the ssh-sssd path (I cn get kerberos tickets for ad users via cli though), so I think that incorrect dc

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-10 Thread Traiano Welcome
On Mon, Mar 9, 2015 at 9:49 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi

[Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Traiano Welcome
Hi List I have AD trusts configured and working between an IPA server and a master primary domain controller (dc-1) in a forest in one data center. This allows me to connect with SSH to linux servers in the same data-center, authenticating with my AD credentials. I'm trying to test a scenario

Re: [Freeipa-users] IPA/Kerberos5 and Upper Case/Lower-case Hostnames

2015-01-18 Thread Traiano Welcome
Hi Dmitri On Tue, Dec 30, 2014 at 12:17 AM, Dmitri Pal d...@redhat.com wrote: On 12/24/2014 01:04 AM, Traiano Welcome wrote: Hi List I have a large number of legacy hosts with upper-case host names, that I'd like to configure as IPA clients. However ipa client refuses to accept upper case

[Freeipa-users] IPA/Kerberos5 and Upper Case/Lower-case Hostnames

2014-12-23 Thread Traiano Welcome
Hi List I have a large number of legacy hosts with upper-case host names, that I'd like to configure as IPA clients. However ipa client refuses to accept upper case hostnames during configuration time. I think this derives from the fact that the kerberos5 database stores host names in a case

[Freeipa-users] The ipa-replica-install command failed, exception: SystemExit: Invalid IP Address ... Cannot use IP network address

2014-11-07 Thread Traiano Welcome
Hi List I'm trying to configure a replica for a primary freeipa IdM server (both CentOS 7, AD trusts configured on primary), but ipa-replica-install fails with the following error: -- ipa-replica-install -d --setup-ca --setup-dns --no-forwarders

Re: [Freeipa-users] The ipa-replica-install command failed, exception: SystemExit: Invalid IP Address ... Cannot use IP network address

2014-11-07 Thread Traiano Welcome
Hi Petr On Fri, Nov 7, 2014 at 6:19 PM, Petr Spacek pspa...@redhat.com wrote: On 7.11.2014 14:08, Traiano Welcome wrote: Hi List I'm trying to configure a replica for a primary freeipa IdM server (both CentOS 7, AD trusts configured on primary), but ipa-replica-install fails

Re: [Freeipa-users] The ipa-replica-install command failed, exception: SystemExit: Invalid IP Address ... Cannot use IP network address

2014-11-07 Thread Traiano Welcome
On Fri, Nov 7, 2014 at 7:22 PM, Petr Spacek pspa...@redhat.com wrote: On 7.11.2014 17:20, Traiano Welcome wrote: Hi Petr On Fri, Nov 7, 2014 at 6:19 PM, Petr Spacek pspa...@redhat.com wrote: On 7.11.2014 14:08, Traiano Welcome wrote: Hi List I'm trying to configure a replica

Re: [Freeipa-users] FreeIPA 3.3 and Solaris 10 Client Integration:

2014-09-25 Thread Traiano Welcome
Hi Martin On Wed, Sep 24, 2014 at 2:18 PM, Martin Kosek mko...@redhat.com wrote: On 09/24/2014 01:06 PM, Traiano Welcome wrote: Hi List I'm currently running IPA 3.3 on Centos 7, and successfully authenticating Linux clients (Centos 6.5). I'd like to setup Solaris 10 as an IPA

Re: [Freeipa-users] FreeIPA ActiveDire​ctory Integratio​n: Managing AD Users in IPA

2014-09-20 Thread Traiano Welcome
(belated response) On Sun, Sep 14, 2014 at 12:10 AM, Dmitri Pal d...@redhat.com wrote: On 09/13/2014 04:03 PM, Traiano Welcome wrote: Hi List Currently I have a stable trust relationship going between IPA and Windows AD. I create users and manage passwords in AD, but want to manage

Re: [Freeipa-users] FreeIPA ActiveDirectory Integration, Fedora and Windows 2008 R2 AD: ipa: ERROR: an internal error has occurred

2014-09-13 Thread Traiano Welcome
for the assistance all!! Traiano On Sat, Sep 13, 2014 at 12:07 AM, Alexander Bokovoy aboko...@redhat.com wrote: On Fri, 12 Sep 2014, Traiano Welcome wrote: Hi List I'm following the guide at http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup#Assumptions , this time with Fedora

Re: [Freeipa-users] FreeIPA ActiveDirectory Integration, Fedora and Windows 2008 R2 AD: ipa: ERROR: an internal error has occurred

2014-09-13 Thread Traiano Welcome
On Sat, Sep 13, 2014 at 7:03 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Sat, 13 Sep 2014, Traiano Welcome wrote: Hi I've managed to get trusts working with CentOS 7 as an IdM server, Win2K8R2 AD DC and CentOS6.5 as a client, using the exact same series of steps

[Freeipa-users] FreeIPA ActiveDire​ctory Integratio​n: Managing AD Users in IPA

2014-09-13 Thread Traiano Welcome
Hi List Currently I have a stable trust relationship going between IPA and Windows AD. I create users and manage passwords in AD, but want to manage the rest in IPA, the rest being default shell, default home directory settings, RBAC, HBAC, Selinux etc .. What I'm expecting it to be able to log

Re: [Freeipa-users] FreeIPA Active directory Integration: ipa unknown command trustdomain-fetch

2014-09-12 Thread Traiano Welcome
Hi Alexander On Thu, Sep 11, 2014 at 8:16 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Thu, 11 Sep 2014, Traiano Welcome wrote: This one is not usable. You need to enable debugging on the server side. See http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup# Debugging_trust

[Freeipa-users] FreeIPA ActiveDirectory Integration, Fedora and Windows 2008 R2 AD: ipa: ERROR: an internal error has occurred

2014-09-12 Thread Traiano Welcome
Hi List I'm following the guide at http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup#Assumptions , this time with Fedora 20.1. Everything proceeds smoothly until I try to establish trust with the AD domain controller, at which point IPA crashes: --- [root@idm001 ~]# ipa trust-add

Re: [Freeipa-users] FreeIPA Active directory Integration: ipa unknown command trustdomain-fetch

2014-09-11 Thread Traiano Welcome
On Thu, Sep 11, 2014 at 6:06 PM, Traiano Welcome trai...@gmail.com wrote: Hi Alexander On Thu, Sep 11, 2014 at 4:38 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Thu, 11 Sep 2014, Traiano Welcome wrote: Hi List I'm currently working through the IPAv3 AD integration document

[Freeipa-users] Integrating FreeIPA with ActiveDirectory (Windows 2008 R2)

2014-09-10 Thread Traiano Welcome
Hi List I've been following the AD integration guide for IPAv3 here: http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup However, when I reach the Add trust with AD domain step I get the following error: --- [root@ipa ~]# ipa trust-add --type=ad mhatest.local --admin Administrator --password