Re: [Freeipa-users] Problems with failed upgrade: groups are not created

2015-05-16 Thread Will Sheldon
the default search query limit is 1000… It took a while to work that out, needless to say we all feel a little silly and a little wiser now :)   Will Sheldon On May 14, 2015 at 1:44:15 AM, Martin Basti (mba...@redhat.com) wrote: On 14/05/15 01:50, Will Sheldon wrote: Hello everyone :) We

[Freeipa-users] Problems with failed upgrade: groups are not created

2015-05-13 Thread Will Sheldon
tag=105 nentries=0 etime=0 csn=5553e3f800010004 === Which is consistent with the slapd log during the upgrade: [21/Apr/2015:19:18:43 +] NSACLPlugin - The ACL target cn=hr,cn=groups,cn=accounts,dc=foo,dc=com does not exist -- Kind regards, Will Sheldon -- Manage

Re: [Freeipa-users] IPA and geographically distributed masters

2015-04-01 Thread Will Sheldon
We have multiple distributed replicas running in the following locations: East coast AMER West coast AMER London EMEA and have had no issues with replication or performance. (max ping is about 120ms)   Will Sheldon On April 1, 2015 at 3:50:23 PM, Steven Jones (steven.jo...@vuw.ac.nz) wrote

Re: [Freeipa-users] Debian 7.0.8 and REHL IPA

2015-03-24 Thread Will Sheldon
There is a ppa for ubuntu: https://code.launchpad.net/~freeipa/+archive/ubuntu/ppa and packages in the deb archives: https://packages.qa.debian.org/f/freeipa.html I’ve had mixed results using them, there seem to be frequent regressions so having a canary machine / cluster is essential.  The

Re: [Freeipa-users] 3.0.0-42 Replication issue after Centos6.5-6.6 upgrade

2014-11-18 Thread Will Sheldon
No, not resolved yet I did test with GSSAPI (-Y) and like you it worked. :(   Will Sheldon On November 18, 2014 at 8:37:10 AM, dbisc...@hrz.uni-kassel.de (dbisc...@hrz.uni-kassel.de) wrote: Hi, On Fri, 7 Nov 2014, Dmitri Pal wrote: On 11/07/2014 01:24 AM, Will Sheldon wrote: On November 6

[Freeipa-users] 3.0.0-42 Replication issue after Centos6.5-6.6 upgrade

2014-11-06 Thread Will Sheldon
succeeded   last update ended: 2014-11-07 01:35:43+00:00 [root@server2 ~]#   Will Sheldon -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project

Re: [Freeipa-users] 3.0.0-42 Replication issue after Centos6.5-6.6 upgrade

2014-11-06 Thread Will Sheldon
On November 6, 2014 at 10:07:54 PM, Dmitri Pal (d...@redhat.com) wrote: On 11/07/2014 12:18 AM, Will Sheldon wrote: Hello all :) On the whole we are loving FreeIPA, Many thanks and much respect to all involved, we’ve had a great 12-18 months hassle free use out of it  - it is a fantastically

[Freeipa-users] DNS: Possible to set a CNAME for bare domain?

2014-10-04 Thread Will Sheldon
file?   Will Sheldon -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project

Re: [Freeipa-users] DNS: Possible to set a CNAME for bare domain?

2014-10-04 Thread Will Sheldon
at 10:20:43 AM, Michael Lasevich (mlasev...@gmail.com) wrote: You cannot have cname for a bare domain in IPA or in any DNS service, it violates DNS rfc's. On Oct 4, 2014 10:19 AM, Will Sheldon m...@willsheldon.com wrote: Hello everyone : ) Is it possible to configure a CNAME for a bare domain

Re: [Freeipa-users] Password expiration dates are different when being resetted by the (primary) admin and a different admin

2014-08-28 Thread Will Sheldon
1a) has come up before: https://www.redhat.com/archives/freeipa-users/2014-February/msg00313.html 1b) We handled this by setting the expire lifetime to a very large value (20 years) for members of a certain group. 2) I’m not sure. Kind regards, Will Sheldon +1.778-689-1244 On August 28

Re: [Freeipa-users] ipa-server-install + NATTED interface question

2014-03-31 Thread Will Sheldon
netmask 255.255.255.0 up then try the install again. Kind regards, Will Sheldon On Monday, March 31, 2014 at 11:59 AM, The Dude wrote: Hi all; avid user of both FreeIPA and IPA for a few years now. I have a unique situation that I hope someone can provide some insight, or help with. I

Re: [Freeipa-users] Win7 machine occasionally not able to lookup ipa hosts

2014-03-23 Thread Will Sheldon
What is the difference in the output of ipconfig /all” before and after the ipconfig /renew”? Kind regards, Will Sheldon On Sunday, March 23, 2014 at 1:21 AM, John Obaterspok wrote: Hello, A couple of times each day the win 7 machine is not able to lookup hosts on the ipa domain

Re: [Freeipa-users] About Windows client

2014-03-22 Thread Will Sheldon
of authentication and accounting interfaces including oAuth, SAML, OpenID and of course RADIUS. Kind regards, Will Sheldon +1.778-689-1244 On Saturday, March 22, 2014 at 2:17 PM, Dmitri Pal wrote: On 03/22/2014 01:18 PM, Arthur wrote: Dmitri Pal wrote: On 03/20/2014 11:15 PM, Arthur Faizullin

Re: [Freeipa-users] adding ubuntu client to red hat server

2014-02-21 Thread Will Sheldon
#revert change to the ipapython version back again #rm -f /usr/share/pyshared/ipapython/version.py mv /usr/share/pyshared/ipapython/version.py.bak /usr/share/pyshared/ipapython/version.py Kind regards, Will Sheldon +1.778-689-1244 On Friday, February 21, 2014 at 9:20 AM, Todd Maugh wrote

Re: [Freeipa-users] adding ubuntu client to red hat server

2014-02-21 Thread Will Sheldon
regards, Will Sheldon +1.778-689-1244 On Friday, February 21, 2014 at 9:42 AM, Todd Maugh wrote: thanks IM trying that but running in to an issue where it says im still installed I run the uninstall command and I get this root@se-idm-ubuntu-client-01:~# ipa-client-install --uninstall

Re: [Freeipa-users] adding ubuntu client to red hat server

2014-02-21 Thread Will Sheldon
. Slightly unrelated, but have a read of this ticket, it makes some good suggestions at the bottom: https://bugs.launchpad.net/bugs/1280215 Kind regards, Will Sheldon +1.778-689-1244 On Friday, February 21, 2014 at 9:55 AM, Todd Maugh wrote: OK I got it to go through with this but i don't

Re: [Freeipa-users] authentication against compat

2014-02-12 Thread Will Sheldon
Is SSSD working for IPA sudo now? I saw this From Jakub Horozek in this list a little while back: Unfortunately with 6.5 there is still no sudo ipa provider, there might be with one in 6.6. So in order to download the sudo rules you need to configure the LDAP sudo provider manually. Will. On

Re: [Freeipa-users] Upgrade form Centos to Fedora (3.0.0 - 3.3.3)

2014-02-05 Thread Will Sheldon
On 2/5/2014, 1:35 AM, Rob Crittenden wrote: Will Sheldon wrote: Hello IPA users :) We have implemented IPA using the packaged version in centos 6.5 (which is 3.0.0-37.el6), but have been playing with the more recent version in Fedora 19 (3.3.3-2.fc19) and are quite keen

[Freeipa-users] Upgrade form Centos to Fedora (3.0.0 - 3.3.3)

2014-02-04 Thread Will Sheldon
bet? Any pointers would be hugely appreciated.. -- Kind regards, Will Sheldon ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

2014-01-06 Thread Will Sheldon
I’m not too concerned on the default as long as the user is warned (or even maybe asked) at install time. Kind regards, Will Sheldon +1.778-689-1244 On Monday, January 6, 2014 at 1:57 PM, Sigbjorn Lie wrote: On 03/01/14 20:33, Stephen Ingram wrote: On Fri, Jan 3, 2014 at 10:29 AM

Re: [Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

2014-01-03 Thread Will Sheldon
/2014 02:23 AM, Will Sheldon wrote: This is cause for concern. Is there a hardening / best practices for production guide anywhere, did I miss a section of the documentation? What else do I need to secure? I understand that there is a tradeoff between security and compatibility, but maybe

Re: [Freeipa-users] ipa-client-install 2.58 client incompatible with 2.49 server

2014-01-02 Thread Will Sheldon
Thanks guys. For now I've just reverted the reported version while the install script runs. It seems to work OK. On Thu, Jan 2, 2014 at 9:06 AM, Martin Kosek mko...@redhat.com wrote: On 12/28/2013 06:50 PM, Rob Crittenden wrote: Will Sheldon wrote: Hello :) I'm trying to setup

Re: [Freeipa-users] FreeIPA Security issue : Anonymous user can fetch user details from IPA without authenticating

2014-01-02 Thread Will Sheldon
. ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users -- Kind regards, Will Sheldon +1.(778)-689-4144 ___ Freeipa-users mailing list Freeipa-users@redhat.com https

[Freeipa-users] ipa-client-install 2.58 client incompatible with 2.49 server

2013-12-27 Thread Will Sheldon
on the server somewhere? Would anyone be interested in helping with development of a yum and apt repo on the server to make all this easier? -- Kind regards, Will Sheldon ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman