Re: [Freeipa-users] renewing cert and migrating free-ipa 3.1

2017-04-18 Thread Umarzuki Mochlis
below are from httpd error log [Thu Feb 18 16:28:06.351007 2016] [:error] [pid 310] ipa: INFO: ad...@domain.com.my: user_find(u'yusma', sizelimit=0, pkey_only=True): SUCCESS [Thu Feb 18 16:28:06.400453 2016] [:error] [pid 311] ipa: INFO: ad...@domain.com.my: batch: user_show(u'nisa', all=True): SU

Re: [Freeipa-users] renewing cert and migrating free-ipa 3.1

2017-04-18 Thread Umarzuki Mochlis
please ignore that domain because I did not mask it properly -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] renewing cert and migrating free-ipa 3.1

2017-04-18 Thread Umarzuki Mochlis
request, will retry: 4301 (RPC failed at server. Certificate operation cannot be completed: Unable to communicate with CMS (Internal Server Error)). stuck: yes key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB&#

Re: [Freeipa-users] renewing cert and migrating free-ipa 3.1

2017-03-03 Thread Umarzuki Mochlis
;t connect to host). 2017-03-03 13:20 GMT+08:00 Umarzuki Mochlis : > After httpd failed to start even with "NSSEnforceValidCerts off" in > /etc/httpd/conf.d/nss.conf > It used to work for a while since we use this only for zimbra but > today it won't start anymore. > &g

[Freeipa-users] renewing cert and migrating free-ipa 3.1

2017-03-02 Thread Umarzuki Mochlis
After httpd failed to start even with "NSSEnforceValidCerts off" in /etc/httpd/conf.d/nss.conf It used to work for a while since we use this only for zimbra but today it won't start anymore. We are not using commercial certs, so which steps should I follow to renew certs? It seems CA has expired

Re: [Freeipa-users] Configuring httpd error when selinux is permissive

2016-11-08 Thread Umarzuki Mochlis
2016-11-08 16:33 GMT+08:00 郑磊 : > Hello everyone, > I have been setting up freeipa(its version is 4.3.1) on Ubuntu. Selinux is > enable, and its mode is permissive. I met a problem at configuring the httpd > process, but the process won't be interrupted. The configuration information > is as follow

Re: [Freeipa-users] freeipa sudden stop

2015-06-30 Thread Umarzuki Mochlis
2015-07-01 3:51 GMT+08:00 Lukas Slebodnik : > End of life for Fedora 18 was 2014-01-14. > See https://fedoraproject.org/wiki/End_of_life > > Could you try to upgrade to recent release (fedora 21)? > If you did not want to upgrade very often then it would > be better to use distribution with longe

Re: [Freeipa-users] freeipa sudden stop

2015-06-29 Thread Umarzuki Mochlis
2015-06-30 13:34 GMT+08:00 David Kupka : .. > > Hello! > The issue seems quite annoying. Could you please provide more info? > Do you have one freeipa master or more replicas? > If not do you experience this issue only on one of them? > > According to the logs it looks like starting of pki-tomcatd

Re: [Freeipa-users] Failed to start Identity, Policy, Audit

2015-03-01 Thread Umarzuki Mochlis
stopped. How do I suppose to bring up replica when master itself could not be started? 2015-03-01 21:56 GMT+08:00 Umarzuki Mochlis : > After rebooting freeipa server, I cannot log in to its web interface > and when I try to start it, it failed > -- Manage your subscription for the Freeipa

[Freeipa-users] Failed to start Identity, Policy, Audit

2015-03-01 Thread Umarzuki Mochlis
After rebooting freeipa server, I cannot log in to its web interface and when I try to start it, it failed More info: [root@ipa ~]# systemctl start ipa.service Job for ipa.service failed. See 'systemctl status ipa.service' and 'journalctl -n' for details. [root@ipa ~]# systemctl status ipa.servi

Re: [Freeipa-users] ipa-replica-install command failed

2013-02-26 Thread Umarzuki Mochlis
389-ds-base logs on the > replica and see if there is any bug? The log should be in > /var/log/dirsrv/slapd-YOUR-IPA-INSTANCE/errors. > > Martin -- Regards, Umarzuki Mochlis http://debmal.my ___ Freeipa-users mailing list Freeipa-users@re

Re: [Freeipa-users] creating group via CLI

2013-02-08 Thread Umarzuki Mochlis
2013/2/8 John Dennis : > On 02/07/2013 08:42 PM, Umarzuki Mochlis wrote: >> >> Hi, >> >> Is it possible to create groups and add users to that group via CLI? >> So far, I could not find any sample command on doing that. > > > The ipa CLI has help > >

[Freeipa-users] creating group via CLI

2013-02-07 Thread Umarzuki Mochlis
Hi, Is it possible to create groups and add users to that group via CLI? So far, I could not find any sample command on doing that. I'm using FreeIPA 3.1.0-2 on fc18 -- Regards, Umarzuki Mochlis http://debmal.my ___ Freeipa-users mailing

[Freeipa-users] SSO page FreeIPAv3

2013-01-16 Thread Umarzuki Mochlis
via webmail.domain.com, user B on OSS also can log in from webmail.domain.com is there any way that I could achieve this with freeipa 3.0? -- Regards, Umarzuki Mochlis http://debmal.my ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat

Re: [Freeipa-users] how do i apply patch?

2013-01-14 Thread Umarzuki Mochlis
2013/1/12 John Dennis : > 1) Download the source rpm matching the version you have installed, add the > patch, rebuild the rpm locally, install the locally built rpm. how do i 'add the patch' to source rpm? any documentation that i can follow to do this? -- Regards, Umarz

Re: [Freeipa-users] how do i apply patch?

2013-01-11 Thread Umarzuki Mochlis
ain only the official build + chosen patches. > > Martin Hi, what I want to do is simply patch free ipa with that patch from ipa-server 2.2.0 on my centos 6 any method that would retain current configuration? -- Regards, Umarzuki Mochlis http://debmal.my _

[Freeipa-users] how do i apply patch?

2013-01-09 Thread Umarzuki Mochlis
i'm interested on patch https://fedorahosted.org/freeipa/changeset/1eab43d29244f6e0b8d6f3146317624715d84af7/ so i can have user to be able to reset own password do i manually edit each listed files or is there any specific step(s) needed? -- Regards, Umarzuki Mochlis http://debm