Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-05 Thread nasir nasir
gt;>>the CA that issued your Apache cert.>>>>>> How can we proceed further?  Nidal. --- On Thu, 1/5/12, Rob Crittenden wrote: From: Rob Crittenden Subject: Re: [Freeipa-users] Expired SSL certificate issue with IPA To: "nasir nasir" Cc: freeipa-users@redhat.co

Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-05 Thread nasir nasir
d/alias/pwdfile.txt'        certificate: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB'        CA: IPA        issuer: CN=Certificate Authority,O=HUGAYET.COM        subject: CN=openipa.hugayet.com,O=HUGAYET.COM        expi

Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-05 Thread nasir nasir
pd/conf.d/nss.conf? Please advice. Nidal. --- On Thu, 1/5/12, Rob Crittenden wrote: From: Rob Crittenden Subject: Re: [Freeipa-users] Expired SSL certificate issue with IPA To: "nasir nasir" Cc: freeipa-users@redhat.com, fasilk...@gmail.com Date: Thursday, January 5, 2012, 7:38 AM na

Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-04 Thread nasir nasir
IPA To: "nasir nasir" Cc: "Rich Megginson" , freeipa-users@redhat.com, fasilk...@gmail.com Date: Wednesday, January 4, 2012, 11:52 AM nasir nasir wrote: > Thanks for all the replies. > > Rob, > Please find the output of your guidelines. Here is the culprit: ca-er

Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-04 Thread nasir nasir
    key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token='NSS Certificate DB',pinfile='/etc/httpd/alias/pwdfile.txt'        certificate: type=NSSDB,location='/etc/httpd/alias',nickname='Server-Cert',token=

Re: [Freeipa-users] Expired SSL certificate issue with IPA

2012-01-03 Thread nasir nasir
--- On Tue, 1/3/12, Rich Megginson wrote: From: Rich Megginson Subject: Re: [Freeipa-users] Expired SSL certificate issue with IPA To: "nasir nasir" Cc: freeipa-users@redhat.com, fasilk...@gmail.com Date: Tuesday, January 3, 2012, 7:41 AM On 01/03/2012 12:52

[Freeipa-users] Expired SSL certificate issue with IPA

2012-01-02 Thread nasir nasir
Hi, I am facing a serious issue with my production IPA server. When I try to access IPA web interface using Firefox, it hangs and doesn't allow me to get in. It seems to be due to expired SSL certificate as seen in the apache log file, [Tue Jan 03 10:34:08 2012] [error] Certificate not verifi

Re: [Freeipa-users] Could not update ICEauthority file /home/brad/.ICEauthority FreeIPA

2011-08-14 Thread nasir nasir
While I don't know much about the issue you mentioned, you can add the mkhomedir switch to the necessary pam files later also. If you don't know the exact files and switches, compare it with an identical machine where you have mkhomedir switch enabled at the time of IPA client installation. I th

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-08-01 Thread nasir nasir
. > > > > If it helps, I can provide shell access to the > system. > > > > cu romal > > > > > > > > > > Am 26.07.11 19:26, schrieb nasir nasir: > >> > >> Hi all, > >> > >> After applying the patches and rest

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-26 Thread nasir nasir
Tkac wrote: > From: Adam Tkac > Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment > To: "nasir nasir" > Cc: freeipa-users@redhat.com, "Robert M. Albrecht" > Date: Tuesday, July 26, 2011, 7:58 AM > On 07/26/2011 04:51 PM, nasir nasir > wr

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-26 Thread nasir nasir
Linux desktop deployment > To: "nasir nasir" > Cc: freeipa-users@redhat.com, "Robert M. Albrecht" > Date: Tuesday, July 26, 2011, 7:13 AM > On 07/26/2011 03:56 PM, nasir nasir > wrote: > > Hi, > > > >>> In my case things are getting worse afte

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-26 Thread nasir nasir
Hi, > > > > In my case things are getting worse after the > configuration change. Earlier the issue used to pops up once > in a day or so. But now it is recurring in  every hour > or so.  So I have reverted that parameter. > > > May I ask you if you send reload (rndc reload or kill -HUP) > or stop

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-26 Thread nasir nasir
Hi, > > Hi, > > I already included it, it's running for 15 minutes now. It > never > survived longer than a minute before. > > Keep fingers crossed :-) In my case things are getting worse after the configuration change. Earlier the issue used to pops up once in a day or so. But now it is r

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-26 Thread nasir nasir
. Thanks again and best regards, Nidal --- On Tue, 7/26/11, Adam Tkac wrote: > From: Adam Tkac > Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment > To: "nasir nasir" > Cc: freeipa-users@redhat.com > Date: Tuesday, July 26, 2011, 1:14 AM > Note this

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-25 Thread nasir nasir
esktop deployment > To: "nasir nasir" > Cc: freeipa-users@redhat.com > Date: Monday, July 25, 2011, 7:22 AM > nasir nasir wrote: > > Hi Rob, > > > > Thanks indeed for the quick reply! Please see the > attached backtrace > > files. I have generated i

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-07-25 Thread nasir nasir
for Linux desktop deployment To: "nasir nasir" Cc: freeipa-users@redhat.com Date: Monday, July 25, 2011, 6:16 AM nasir nasir wrote: > Hi, > > Further to the ongoing deployment of Linux clients and servers using > FreeIPA, I was able to successfully get all the requirements

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-18 Thread nasir nasir
mented out, does the /home/nasir directory get created on the local disk?

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-17 Thread nasir nasir
ctory get created on the local disk? On 05/16/2011 09:19 PM, nasir nasir wrote: Thanks again! No! it allows auto mount that pre created home folder ONLY  to the NFS se

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
nasir directory, either via odd job, or just test it as root. What I am guessing is happening here is that ssh is not triggereing the odd job creation of the home directory.  Either that, or this particular IPA client was run without the switch to create the home-d

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
t, or this particular IPA client was run without the switch to create the home-dir.  If Automount is commented out, does the /home/nasir directory get created on the local disk? On 05/16/2011 09:19 PM, nasir n

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
Thanks again! No! it allows auto mount that pre created home folder ONLY  to the NFS server. For e.g if I have /xtra/home/nasir alread created, then it automatically mounts  while login to NFS server ( ssh -l nasir NFS_SERVER ). But when I try to login as the same user to some other machine ( ss

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
Sorry, I forgot to answer the below question in my last mail. I can manually mount my main partition for home folder(i.e /xtra/home ) But I can't mount real home folders under that because they don't exist. If I manually create one home folder( e.g /xtra/home/abc ) under than, then I can mount i

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
Thanks for the reply! Please see the following output from and IPA client machine. [root@rhel ~]# showmount -e hugayat.cohort.orgExport list for hugayat.cohort.org:/xtra/home *[root@rhel ~]# The result is same across all the machines. Thanks and regards,Nidal automount. Does manually mounting

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-16 Thread nasir nasir
reeipa-users] FreeIPA for Linux desktop deployment To: freeipa-users@redhat.com Date: Monday, May 16, 2011, 1:23 AM On 05/15/2011 06:49 AM, nasir nasir wrote: > Thanks again! > > NO, it was not set. I added it manually now (*automount:  ldap *) and > now a different error pops up in /v

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-13 Thread nasir nasir
I was trying to see whether I could mount the NFS share manually. Thats why I tested the first step. I have two machines configured now. One IPA server and the other one as IPA client(with --mkhomedir switch) configured as an NFS server too. Here the /xtra partition with a home subfolder is the

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-13 Thread nasir nasir
--/etc/auto.home:*       -rw,sec=krb5,soft,rsize=8192,wsize=8192 nfsserver.cohort.org:/xtra/home/& Is this OK ? Please help. Thanks and regards,Nidal --- On Fri, 5/13/11, Adam Young wrote: From: Adam Young Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment To: "nasir

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-13 Thread nasir nasir
Adam, Thanks indeed! I tried your suggestions.    -- I can mkdir  -- When I try to chown, I get the following error chown: changing ownership of `nasir': Operation not permitted Could you please explain me what do you mean by 'You probably need rwx permissions in /etc/export' ? This is my /etc/exp

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-12 Thread nasir nasir
Thanks for the reply! Selinux is disabled! Actually disabling selinux is "mandatory post-installation" step for me :-) Thanks and regards,Nasir --- On Thu, 5/12/11, Steven Jones wrote: From: Steven Jones Subject: RE: [Freeipa-users] FreeIPA for Linux desktop deployment To: &q

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-12 Thread nasir nasir
n for /etc/oddjobd.conf file to go further. Please help. Thanks and regards,Nidal --- On Thu, 5/12/11, Rob Crittenden wrote: > From: Rob Crittenden > Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment > To: "nasir nasir" > Cc: "Adam Young" , freeipa

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-12 Thread nasir nasir
Adam, I tried to follow your recommendations with RHEL 6.1 beta on server and client machine. Centralized login and such things work. I have NFS service too working. But automount is not working.  For the time being I configured my server as NFS server and created a folder /export as a share for

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-09 Thread nasir nasir
ubject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment To: "nasir nasir" Cc: freeipa-users@redhat.com Date: Monday, May 9, 2011, 6:17 AM On 05/08/2011 11:57 PM, nasir nasir wrote:

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-08 Thread nasir nasir
). Still, its the same. Any idea ? Thanks and regards,Nidal --- On Sun, 5/8/11, Adam Young wrote: From: Adam Young Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment To: "nasir nasir" Cc: freeipa-users@redhat.com Date: Sunday, May 8, 2011, 4:39 PM

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-08 Thread nasir nasir
some guide lines or docs for the same ? Thanks and Regards,Nidal --- On Mon, 5/2/11, Adam Young wrote: From: Adam Young Subject: Re: [Freeipa-users] FreeIPA for Linux desktop deployment To: "nasir nasir" Cc: freeipa-users@redhat.com Date: Monday, May 2, 2011, 8:03 AM

Re: [Freeipa-users] FreeIPA for Linux desktop deployment

2011-05-01 Thread nasir nasir
Thanks for all the replies and great suggestions! I do appreciate it a lot. Apologies for being a bit confusing about the cetralized /home foder in my previous mail. What I want is that all the users should have their /home folder stored in the storage. This entire partition (or LUN) can be attac

[Freeipa-users] FreeIPA for Linux desktop deployment

2011-04-29 Thread nasir nasir
Hi All, First of all, many thanks indeed to the developers and community for making some great strides in the open source IPA world ! I am planning for a Linux deployment with the following requirements.    -- About 50 Linux clients running Kubuntu (can change this to ubuntu if necessary)   -- Ce