Re: [SSSD] auth.log error message: _sasl_plugin_load failed

2013-11-14 Thread Qing Chang
: <20131114094145.gd3...@hendrix.brq.redhat.com> Content-Type: text/plain; charset=us-ascii On Wed, Nov 13, 2013 at 04:19:03PM -0500, Qing Chang wrote: >there was a thread on Aug 8, 2013 that was about this error, my situation is >a little different. This happens on Ubuntu 12.04 IPA cl

[SSSD] auth.log error message: _sasl_plugin_load failed on sasl_canonuser_init for plugin: ldapdb

2013-11-13 Thread Qing Chang
directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable backend system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. This package provides t

[SSSD] automatic renewal of TGT for IPA users

2013-10-18 Thread Qing Chang
In sssd InternalsDocs, there is a statement: "SSSD can automatically renew the TGT at a configurable interval". Can someone give me a pointer as how I can configure sssd to do it? I am using krenew for the same effect, thought a native way would be much better... Many thanks, Qing

Re: [SSSD] ssh does not remove credential cache at logout

2013-10-16 Thread Qing Chang
Appreciate your explanations and suggestions. I was wondering about having krenew process killed automatically when user logs out if the ccache is cleared. Regards, Qing On 12/10/2013 11:06 PM, Simo Sorce wrote: On Fri, 2013-10-11 at 12:07 -0400, Qing Chang wrote: IPA clients (RHEL, CentOS

[SSSD] ssh does not remove credential cache at logout

2013-10-11 Thread Qing Chang
pam_deny.so authrequiredpam_permit.so authoptionalpam_cap.so = Is this a pam configuration issue or a pam_sss issue? Thanks, Qing -- -- Qing Chang Senior Systems Administrator M6-624 Research Computing

Re: [SSSD] Group name lost randomly

2013-04-24 Thread Qing Chang
On 23/04/2013 4:42 AM, Jakub Hrozek wrote: On Mon, Apr 22, 2013 at 09:59:53AM -0400, Qing Chang wrote: just for the record. This is considered solved. When migrated from OpenLDAP to IPA, inactive user accounts were left out, but some of the accounts were still in place as secondary group

Re: [SSSD] Group name lost randomly

2013-04-22 Thread Qing Chang
sssd seems to be able to get the name on some IPA clients not others, as mentioned in my first post... Thanks, Qing On 19/04/2013 1:33 PM, Qing Chang wrote: it is 1.9.2-82.4.el6_4. Host is RHEL 6.4 (2.6.32-358.2.1.el6.x86_64) /var/log/sssd/sssd_nss.log has multiple entries: [sssd[nss]] [nss_cmd_get

Re: [SSSD] Group name lost randomly

2013-04-19 Thread Qing Chang
recursive look of all GIDs? "getent group" (with enumerate turned on) returns single entries for the GIDs that are involved so far (42, 421 etc,.) Thanks, Qing On 19/04/2013 1:07 PM, Jakub Hrozek wrote: On Fri, Apr 19, 2013 at 01:02:00PM -0400, Qing Chang wrote: at the same time on dif

[SSSD] Group name lost randomly

2013-04-19 Thread Qing Chang
id not come back. A reboot would fix the problem, but it could creep back some time later. Any idea why this is happening? Best Regards, Qing -- ------ Qing Chang Senior Systems Administrator M6-624 Research Computing Sunnybrook Health Sciences Centre 2075 Bayview Ave. Toronto, Ontario

[SSSD] How to obtain a renewable ticket from IPA when login to an IPA client?

2013-02-28 Thread Qing Chang
work with IPA client because it seems IPA client can not obtain a renewable ticket by default at login. Can this be changed? Thanks, Qing -- -- Qing Chang Senior Systems Administrator M6-624 Research Computing Sunnybrook Health Sciences Centre 2075 Bayview Ave. Toronto, Ontario, M4N

Re: [SSSD] IPA client randomly lose memory of users

2012-12-07 Thread Qing Chang
On 2012/12/6 13:54, Jakub Hrozek wrote: On Thu, Dec 06, 2012 at 01:49:14PM -0500, Qing Chang wrote: On 06/12/2012 12:12 PM, Jakub Hrozek wrote: On Thu, Dec 06, 2012 at 11:37:41AM -0500, Qing Chang wrote: On 05/12/2012 2:58 PM, Dmitri Pal wrote: On 12/05/2012 02:00 PM, Qing Chang wrote: On

Re: [SSSD] IPA client randomly lose memory of users

2012-12-06 Thread Qing Chang
On 06/12/2012 12:12 PM, Jakub Hrozek wrote: On Thu, Dec 06, 2012 at 11:37:41AM -0500, Qing Chang wrote: On 05/12/2012 2:58 PM, Dmitri Pal wrote: On 12/05/2012 02:00 PM, Qing Chang wrote: On 05/12/2012 12:59 PM, Simo Sorce wrote: On Wed, 2012-12-05 at 11:31 -0500, Qing Chang wrote: I see

Re: [SSSD] IPA client randomly lose memory of users

2012-12-06 Thread Qing Chang
On 05/12/2012 2:58 PM, Dmitri Pal wrote: On 12/05/2012 02:00 PM, Qing Chang wrote: On 05/12/2012 12:59 PM, Simo Sorce wrote: On Wed, 2012-12-05 at 11:31 -0500, Qing Chang wrote: I see this: First failed "getent passwd shassan" triggers: (Wed Dec 5 10:45:05 2012)

Re: [SSSD] IPA client randomly lose memory of users

2012-12-05 Thread Qing Chang
On 05/12/2012 12:59 PM, Simo Sorce wrote: On Wed, 2012-12-05 at 11:31 -0500, Qing Chang wrote: I see this: First failed "getent passwd shassan" triggers: (Wed Dec 5 10:45:05 2012) [sssd[nss]] [nss_cmd_getpwnam_dp_callback] (0x0040): Unable to get information from Data Provider Er

Re: [SSSD] IPA client randomly lose memory of users

2012-12-04 Thread Qing Chang
On 04/12/2012 2:50 PM, Jakub Hrozek wrote: On Tue, Dec 04, 2012 at 02:38:34PM -0500, Simo Sorce wrote: On Tue, 2012-12-04 at 14:31 -0500, Qing Chang wrote: On 04/12/2012 2:19 PM, Simo Sorce wrote: On Tue, 2012-12-04 at 13:11 -0500, Dmitri Pal wrote: A "service sssd restart"

Re: [SSSD] IPA client randomly lose memory of users

2012-12-04 Thread Qing Chang
On 04/12/2012 2:19 PM, Simo Sorce wrote: On Tue, 2012-12-04 at 13:11 -0500, Dmitri Pal wrote: A "service sssd restart" "fix" the problem... I am thinking of running a cron job of above every 10 minutes to work around the problem while it is being troubleshoot. Is it a bad idea? Well every 1

Re: [SSSD] IPA client randomly lose memory of users

2012-12-04 Thread Qing Chang
On 03/12/2012 4:24 PM, Simo Sorce wrote: On Mon, 2012-12-03 at 15:42 -0500, Qing Chang wrote: On 03/12/2012 10:12 AM, Dmitri Pal wrote: On 12/02/2012 11:37 AM, Jakub Hrozek wrote: On Sat, Dec 01, 2012 at 10:01:55PM -0500, Qing Chang wrote: On 30/11/2012 7:30 PM, Dmitri Pal wrote: On 11/30

Re: [SSSD] IPA client randomly lose memory of users

2012-12-03 Thread Qing Chang
On 03/12/2012 10:12 AM, Dmitri Pal wrote: On 12/02/2012 11:37 AM, Jakub Hrozek wrote: On Sat, Dec 01, 2012 at 10:01:55PM -0500, Qing Chang wrote: On 30/11/2012 7:30 PM, Dmitri Pal wrote: On 11/30/2012 05:21 PM, Qing Chang wrote: my dovecot IMAP server would randomly lose memory of users, as

Re: [SSSD] IPA client randomly lose memory of users

2012-12-01 Thread Qing Chang
On 30/11/2012 7:30 PM, Dmitri Pal wrote: On 11/30/2012 05:21 PM, Qing Chang wrote: my dovecot IMAP server would randomly lose memory of users, as an example: Samba/NFS server knows this user: [root@smb2 shassan]# getent passwd bqiang bqiang:*:47105:471:Beiping Qiang:/home2/bqiang:/bin/tcsh

Re: [SSSD] IPA client randomly lose memory of users

2012-12-01 Thread Qing Chang
On 30/11/2012 5:39 PM, Simo Sorce wrote: On Fri, 2012-11-30 at 17:21 -0500, Qing Chang wrote: my dovecot IMAP server would randomly lose memory of users, as an example: Samba/NFS server knows this user: [root@smb2 shassan]# getent passwd bqiang bqiang:*:47105:471:Beiping Qiang:/home2/bqiang

[SSSD] IPA client randomly lose memory of users

2012-11-30 Thread Qing Chang
Your help is much appreciated. Thanks, Qing -- -- Qing Chang Senior Systems Administrator M6-624 Research Computing Sunnybrook Health Sciences Centre 2075 Bayview Ave. Toronto, Ontario, M4N 3M5 (416) 480-6100 x3263 qch...@