Re: [Freeipa-users] FreeIPA DMZ topology

2015-10-07 Thread Aly Khimji
gt; > > *From:* freeipa-users-boun...@redhat.com [mailto: > freeipa-users-boun...@redhat.com] *On Behalf Of *Aly Khimji > *Sent:* Wednesday, October 07, 2015 1:12 PM > *To:* freeipa-users@redhat.com > *Subject:* [Freeipa-users] FreeIPA DMZ topology > > > > Hey guys, > >

[Freeipa-users] dns_lookup_kdc question

2015-09-23 Thread Aly Khimji
Hey guys, Quick question. Just running through a poc and ran into a question. I have a simple AD DC (win2k8r2 box) with a trust setup to our IPA server. Trust and all is setup properly and I can see users on the client/ipa server and on the ipa server I can ssh into it with the AD user. I am

Re: [Freeipa-users] dns_lookup_kdc question

2015-09-23 Thread Aly Khimji
Excellent, Thank you for the quick response. I will look further into your suggestions Aly On Wed, Sep 23, 2015 at 3:50 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Wed, 23 Sep 2015, Aly Khimji wrote: > >> Hey guys, >> >> Quick question. Just

Re: Goodbye IBM, Hello Google

2015-03-24 Thread Aly Khimji
Congratulation! All the best to you and your future roles :) On Tue, Mar 24, 2015 at 4:00 PM, Wietse Venema wie...@porcupine.org wrote: After 18 years, including the best of my career, I decided that it was time to move on. I'll be working on security at Google NY. Please, there is no

Re: Anti spam filtering tools

2015-03-05 Thread Aly Khimji
Hey, I know it can be quite cumbersome but are you using a flat file for managing amavisd and policies or are using mysql backend? I have found putting all the policies, domains, managment, blacklists etc.. into mysql to be a much better way to manage it. Then you can use a tool like phpmyadmin

Re: SNMP traps and unknown log file

2015-01-26 Thread Aly Khimji
Hey, Can you show the contents of your snmptt.conf file? From my experience I have found that anything the snmptt can't understand (eg doesn't have a definition for it will log as unknown). For that reason I have a catch all in my config as the very bottom of that config file. (see below)

snmptrapd TCP vs UDP for hostname

2015-01-26 Thread Aly Khimji
Hey All, Wondering if you can shed some light on an odd issue I am having. When sending UDP traps I am able to receive and translate the host name of the sender which I can translate and process in our Nagios setup without any issues. However when using a tcp sent trap, which is exactly the

Re: Thank you, Wietse

2014-10-12 Thread aly . khimji
I just wanted to second that as well. Thx Sent from my BlackBerry device on the Rogers Wireless Network -Original Message- From: Venkat mvenkat...@gmail.com Sender: owner-postfix-us...@postfix.org Date: Sat, 11 Oct 2014 21:08:14 Cc: Postfix userspostfix-users@postfix.org Subject: Re:

Re: [CentOS] SAMBA as AD DC

2014-09-06 Thread Aly Khimji
Yes Samba4 is capable of working as a AD domain controller and more. See link. https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO Aly On Sep 6, 2014 4:16 PM, Sergio Belkin seb...@gmail.com wrote: Hi folks, Is able SAMBA on CentOS 7 to work as Active Directory Domain Controller? If it's

Re: [CentOS] SAMBA as AD DC

2014-09-06 Thread Aly Khimji
2014-09-06 18:01 GMT-03:00 Aly Khimji aly.khi...@gmail.com: Yes Samba4 is capable of working as a AD domain controller and more. See link. https://wiki.samba.org/index.php/Samba_AD_DC_HOWTO Aly On Sep 6, 2014 4:16 PM, Sergio Belkin seb...@gmail.com wrote: Hi folks, Is able SAMBA

Re: [CentOS] [CentOS-announce] CentOS Project joins forces with Red Hat

2014-01-07 Thread aly . khimji
That is amazing news, I hope this proves to be a great relationship. Congratulations, looking forward to the future. Aly Sent from my BlackBerry device on the Rogers Wireless Network -Original Message- From: Karanbir Singh kbsi...@centos.org Sender: centos-announce-boun...@centos.org

Re: [CentOS-virt] Announcing a new HA KVM tutorial!

2014-01-06 Thread Aly Khimji
Thank you very much for this, looks like a good read. Will provide feedback :) Aly On Mon, Jan 6, 2014 at 11:11 AM, Digimer li...@alteeve.ca wrote: Almost exactly two years ago, I released the first tutorial for building an HA platform for KVM VMs. In that time, I have learned a lot,

Re: [CentOS] Thank You To The CentOS Team

2013-12-01 Thread Aly Khimji
Agreed. Thank you all very much for your efforts. Aly On Dec 1, 2013 10:06 PM, B.J. McClure keepert...@bellsouth.net wrote: On 12/01/2013 09:56 PM, Mark LaPierre wrote: Hey all you dedicated folks out there who support the CentOS project. Thank you all for your dedicated effort and the

Re: [Freeipa-devel] [Freeipa-users] FreeIPA AD Trust improvements, Fedora 19 Test Day, July 25th

2013-07-22 Thread Aly Khimji
Wow.. These sound like some amazing additions and enhancements, great work! keep up the good job guys! Aly On Jul 19, 2013 5:57 PM, Dmitri Pal d...@redhat.com wrote: Hello, The FreeIPA team is happy to welcome you to a Fedora Test Day that is being held on Thursday, July 25th. We would

Re: [Freeipa-users] FreeIPA trusts with 2003 R2

2013-06-19 Thread Aly Khimji
So as others have mentioned windows obviously isn't my area of focus here either, however we have this working with 2003r2, but I do notice odd behaviour with id returning odd results sometimes depending on what system I am logged in from or initial logins failing the first time and working the

Re: [Freeipa-users] FreeIPA trusts with 2003 R2

2013-06-19 Thread Aly Khimji
, Alexander Bokovoy aboko...@redhat.comwrote: On Wed, 19 Jun 2013, Dmitri Pal wrote: On 06/19/2013 12:35 PM, Alexander Bokovoy wrote: On Wed, 19 Jun 2013, Aly Khimji wrote: So as others have mentioned windows obviously isn't my area of focus here either, however we have this working

Re: [Freeipa-users] FreeIPA trusts with 2003 R2

2013-06-19 Thread Aly Khimji
wrote: On 06/19/2013 06:47 PM, Alexander Bokovoy wrote: On Wed, 19 Jun 2013, Dmitri Pal wrote: On 06/19/2013 12:35 PM, Alexander Bokovoy wrote: On Wed, 19 Jun 2013, Aly Khimji wrote: So as others have mentioned windows obviously isn't my area of focus here either, however we have

Re: [Freeipa-users] IPA different ID results on different nodes

2013-06-04 Thread Aly Khimji
): *Failed to store group 0 members*. (Tue Jun 4 09:36:23 2013) [sssd[be[nix.corpnonprd..com]]] [acctinfo_callback] (0x0100): Request processed. Returned 0,0,Success Aly On Tue, Jun 4, 2013 at 3:56 AM, Sumit Bose sb...@redhat.com wrote: On Mon, Jun 03, 2013 at 09:22:21PM -0400, Aly Khimji

[Freeipa-users] Logging Failed User logins for Trust Users

2013-06-03 Thread Aly Khimji
Quick questions guys, can you advise if there is a particular place(s) successful and failed users authentication is logged? I know from local users I can go through the 389 access logs, but for trust based users can you advise where I would look? I know i see a proper ticket issued in krb5kdc

[Freeipa-users] IPA different ID results on different nodes

2013-06-03 Thread Aly Khimji
Hey guys, Just wanted to say thank you for all your support with everything and answering all my questions. Just wanted to show you something, maybe you can shed some light.. Below is my self running the ID command on 2 different nodes (1) the IDM server and the other the IDM client. I get two

Re: [Freeipa-users] Issue IPA: AD Users and IPA Users when using SSS/LDAP with SUDO

2013-05-03 Thread Aly Khimji
Hey Pavel/guys Any luck recreating the problem? Thx for the help Aly Thanks Pavel, Very much appreciated Aly On Tue, Apr 30, 2013 at 1:41 PM, Pavel Brezina pbrez...@redhat.com wrote: - Original Message - From: Pavel Březina pbrez...@redhat.com To: Aly Khimji aly.khi

[Freeipa-users] Issue IPA: AD Users and IPA Users when using SSS/LDAP with SUDO

2013-04-24 Thread Aly Khimji
Hey All, Hoping you can help out I have provided all details below. I have broken up diagnostics into sudo-ldap for AD/IPA users and sudo-sss for for AD/IPA users. Quick background. Have a 2003 Domain, with an IPA Trust Established and working. AD users and well as local IPA users are able to

Re: [Samba] Group access control under LDAP.

2011-09-21 Thread aly . khimji
Take a look at pam. You can use pam modules to restrict access based of groups, even those supplied via ldap, local, etc I am not near a PC but ill get you the syntax soon. Aly --Original Message-- From: Daniel Lopes de Carvalho Sender: samba-boun...@lists.samba.org To: Daniel

Re: [Samba] Group access control under LDAP.

2011-09-21 Thread aly . khimji
Hmm, I've have never tried that but I'm sure its possible. Are you using Samba and OpenLDAP? Aly --Original Message-- From: Daniel Lopes de Carvalho Sender: samba-boun...@lists.samba.org To: Daniel Carvalho Subject: [Samba] Group access control under LDAP. Sent: Sep 20, 2011 2:51 PM Hi.

Re: [Samba] Group access control under LDAP.

2011-09-21 Thread Aly Khimji
I have never done this before myself, but I am wondering is there is a group policy that can prevent/allow logon on to that machine for members in a certain group? This way you would just add/remove users to this group to allow/prevent access? Aly On Wed, Sep 21, 2011 at 10:01 AM, Daniel Lopes

Re: [Samba] Group access control under LDAP.

2011-09-21 Thread Aly Khimji
I am not sure if you are using XP, Vista, 7, etc.. http://mintywhite.com/windows-7/7maintenance/prevent-users-logging-domain-workstations/ But I found this link to prevent access based of groups + group policy Hope it points you in the right direction Aly On Wed, Sep 21, 2011 at 10:01 AM,

Re: How to integrate Postfix with MySql ?

2011-07-17 Thread aly . khimji
Hiam, Google Postix+Mysql integration, postfix+mysql+virtual domains, etc... There are many howto's available on the topic. Also the check out the documentation on the Postfix website. This topic has been heavily documented by a lot of people doing many different integration using Postfix and

Re: Large ISP which use Postfix

2011-07-14 Thread aly . khimji
I am almost 100% sure from bounce backs and certain errors I have seen in the past that RIM (here in Canada) the folks that run the Blackberry network, use postfix. AK Sent from my BlackBerry device on the Rogers Wireless Network

Re: constant relay access denied on VPS

2011-07-13 Thread aly . khimji
Sent from my BlackBerry device on the Rogers Wireless Network

Re: constant relay access denied on VPS

2011-07-13 Thread aly . khimji
This might seem obvious, but do you have your actual domain in mydestination in your main.cf file? AK Sent from my BlackBerry device on the Rogers Wireless Network

Re: constant relay access denied on VPS

2011-07-13 Thread aly . khimji
Jeffrey, Does the user dukey actually exist in your recipient table? As you are using a VPS with plesk it looks like the mailboxes are probably made from the control panel in plesk virtual_mailbox_maps = hash:/var/spool/postfix/plesk/vmailbox Check in your control panel. btw this means now

Re: [CentOS] [CentOS-announce] Release for CentOS-6.0 i386 and x86_64

2011-07-11 Thread aly . khimji
Just wanted to extend a personal thanks to the CentOS team for their hard work and dedication on this release and on the CentOS distro itself. Thanks for this release and everything else you all have provided and continue to provide, despite all the distractions and what not. Much appreciated

Re: [CentOS] Centos 6 Server has no GUI

2011-07-11 Thread aly . khimji
This might seem obvious but have you checked to see if you have X or any GUI desktops installed? AK Sent from my BlackBerry device on the Rogers Wireless Network ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: [CentOS] Log monitoring

2011-07-06 Thread aly . khimji
Same here, I just recently started using/testing rsyslogd (to mysql [native mysql support is great])+LogAnalyzer web front end for a central log host. So far its been working quite well. Worth checking out Aly Sent from my BlackBerry device on the Rogers Wireless Network

Re: [CentOS] Rsyslog5 and CentOS

2011-07-06 Thread aly . khimji
Not sure exactly what you need but I came across this when setting up rsyslog to work with mysql and was having SELinux protecting services. This is what I used you can see if it helps resolve your issue. Again I don't know if this will work for you but u can try it in a test environment and

Re: [CentOS] Rsyslog5 and CentOS

2011-07-06 Thread aly . khimji
Agreed, I was doing this in a test environment, and did review the rules created. Hopefully that part was assumed ;) but if not I agree it is wise to review the policy file it creates before they get snapped it. Aly Sent from my BlackBerry device on the Rogers Wireless Network

Re: [Samba] Fwd: getent group fails - fixed

2011-06-23 Thread aly . khimji
Nice find! good work Aly Sent from my BlackBerry device on the Rogers Wireless Network -Original Message- From: Dermot paik...@googlemail.com Sender: samba-boun...@lists.samba.org Date: Thu, 23 Jun 2011 13:00:55 To: samba@lists.samba.org Subject: [Samba] Fwd: getent group fails - fixed

Re: about postfix reload

2011-06-21 Thread aly . khimji
Usually a reload is sufficient. Aly --Original Message-- From: Li, Jilong (MU-Student) Sender: owner-postfix-us...@postfix.org To: postfix-users@postfix.org Subject: about postfix reload Sent: Jun 21, 2011 12:48 PM Hello, After changing the file main.cf, do I need to run postfix

Re: [CentOS] a hardware question

2011-05-17 Thread aly . khimji
Indeed I agree, we are a full IBM shop and after working with there gear for a very long time, I also suggest the same, this will ensure you get everything you need and all the correct parts to get you back asap. Its just a safe bet with IBM. Aly --Original Message-- From: John R

Re: amavis / emails in queue?

2011-04-13 Thread aly . khimji
You might want to up the verbose log level in the amavisd.conf, and check your maillog to see if amavisd its having (example: connecting to sql if u have it back ended that way). I know the regular log level sometimes isn't enough. Might be a good place to start. HTH Aly Sent from my

Re: [CentOS] Monitoring power consumption

2011-04-13 Thread aly . khimji
Peter, I have never done it directly of a servers PSU, however I am sure it can be done via SNMP or on a lower level via a management interface(iLO, B/RSA, etc..). However I have done it from a good APC PDU that had SNMP monitoring for all kinds of power aspects. Hope that helps. Aly

Re: [CentOS] Monitoring power consumption

2011-04-13 Thread aly . khimji
Peter, The ones I used were from APC and are under the product line of Metered Rack PDU, u can find them on the apc website. Here are a few product numbers from that line(APC7800,801,802) they all have web, snmp (u can graph with MRTG, or whatever), Telnet access, etc.. they start at about

Re: [CentOS] A round of applause!

2011-04-10 Thread aly . khimji
Yes, well put, I second that! Thanks to all dev's. As I said earlier on the release date, all your efforts are greatly appreciated Aly --Original Message-- From: Chuck Munro Sender: centos-boun...@centos.org To: CentOS Mailing List ReplyTo: CentOS mailing list Subject: [CentOS] A round

Re: [Samba] rebuilt XP machine cannot see Samba server

2011-04-08 Thread aly . khimji
What happens when on the XP machine you do a start- run- \\sambaIP\ What error do u get? Aly Sent from my BlackBerry device on the Rogers Wireless Network -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba

Re: [Samba] rebuilt XP machine cannot see Samba server

2011-04-08 Thread aly . khimji
Good work! That's why I was suggesting the IP in my reply ;) Aly --Original Message-- From: rodneytoady Sender: samba-boun...@lists.samba.org To: samba@lists.samba.org Subject: Re: [Samba] rebuilt XP machine cannot see Samba server Sent: Apr 8, 2011 9:03 PM OK. Solution found. For

Re: [CentOS] [CentOS-announce] Release for CentOS-5.6 i386 and x86_64

2011-04-08 Thread aly . khimji
Amazing!! Great work!! Thank you Aly Sent from my BlackBerry device on the Rogers Wireless Network ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos

Re: Reject the other user

2011-04-06 Thread aly . khimji
Do a quick google on postfix virtual domains and virtual users + mysql. Tons of great how to's and guides. Its quite simple once you see how it can be done in a guide or two and understand the concept. Check on howtoforge.com they have excellent guides for virtual users/domains using mysql +

Re: [CentOS] sshd: Authentication Failures: 137 Time(s)

2011-04-04 Thread aly . khimji
Hey you should check out fail2ban as well. Excellent little app that analysis the log for the corresponding demon using a regex (u can create custom ones too) and performs an action you choose including iptables, hosts.deny, etc.. You can easily adjust setting like 3 failed connections max per

[Samba] Samba4 AD/LDAP question

2011-04-03 Thread Aly Khimji
Hi guys, First time poster so I do apologize if this question has been asked before. In a test set up we are trying to use samba4 to authenticate a small network with Linux, Win, and OSX clients. I have successfully deployed samba4 in domain controller mode, can attach windows machines to it,

Re: [Samba] Samba4 AD/LDAP question

2011-04-03 Thread Aly Khimji
, Jonn jo...@taylortelephone.comwrote: On 04/03/2011 07:24 PM, Aly Khimji wrote: Hi guys, First time poster so I do apologize if this question has been asked before. In a test set up we are trying to use samba4 to authenticate a small network with Linux, Win, and OSX clients. I have

Re: [CentOS] Download the repo DAG of CentOS 5.5

2011-04-03 Thread aly . khimji
I believe there is a rpm available from the DAG site, that will install the .repo file and setup everything you need to access the repo Ak --Original Message-- From: Fidel Dominguez-Valero Sender: centos-boun...@centos.org To: centos@centos.org ReplyTo: CentOS mailing list Subject:

Re: [CentOS] dns question

2011-03-22 Thread aly . khimji
What do you mean by refresh rate of the dns server? Like TTL length of records? Or..? Aly --Original Message-- From: ann kok Sender: centos-boun...@centos.org To: centos@centos.org ReplyTo: CentOS mailing list Subject: [CentOS] dns question Sent: Mar 22, 2011 9:13 AM Hi all How can I

Re: [CentOS] Dvd iso?

2011-03-19 Thread aly . khimji
There is a dvd iso, just go through a few mirrors. Not all of them have it. Not sure if that's what u meant, but if so it does exist. Aly --Original Message-- From: mattias Sender: centos-boun...@centos.org To: centos@centos.org ReplyTo: CentOS mailing list Subject: [CentOS] Dvd iso?

Re: [CentOS] Dvd iso?

2011-03-19 Thread aly . khimji
They are installer only, if I recall correctly Aly --Original Message-- From: mattias Sender: centos-boun...@centos.org To: 'CentOS mailing list' ReplyTo: CentOS mailing list Subject: Re: [CentOS] Dvd iso? Sent: Mar 19, 2011 5:22 PM Yes I find it Are the dvd only installer or live cd

Re: [CentOS] Air Conditioning - ON!

2011-02-21 Thread aly . khimji
I too am with the fella's on this. Thanks for all your time and hard work. It is greatly appreciated, more then words can say. Aly --Original Message-- From: Corey A Johnson Sender: centos-boun...@centos.org To: CentOS mailing list ReplyTo: CentOS mailing list Subject: Re: [CentOS] Air

Re: [CentOS] funding

2011-02-21 Thread aly . khimji
I thinks is a great idea, Its our way of trying to contribute towards a common goal. Who knows it could be a great way to assist in any way we can. I think its a good thought, and I think we should point out, if you do help with hardware or whatever, then you still have no right to be bossy or

Re: [CentOS] System Log Error

2011-02-21 Thread aly . khimji
Are you using a wireless keyboard?? AK Sent on the TELUS Mobility network with BlackBerry -Original Message- From: sync jian...@gmail.com Sender: centos-boun...@centos.org Date: Tue, 22 Feb 2011 14:25:31 To: CentOS mailing listcentos@centos.org Reply-To: CentOS mailing list

Re: [CentOS] System Log Error

2011-02-21 Thread aly . khimji
Hmm, I usually get tons of that on my desktop linux machine that has a wireless keyboard, but if I use a ps2 keyboard I none of it. I also notice it with keyboards with ton's of extra functions (volume, audio functions, etc..). I believe its something with special key mappings. Do u have