[Freeipa-devel] Re: IPA's NTP service

2018-02-26 Thread Florence Blanc-Renaud via FreeIPA-devel
Hi, * During client installation, the installer calls "/usr/bin/timeout ntpd -qgc " in order to synchronize the clock with either a/ one of the servers specified in --ntp-server b/ a NTP server found in the DNS (_ntp._udp in the domain) or c/ the master This command does not configure the NTP

[Freeipa-devel] Re: IPA's NTP service

2018-02-22 Thread Rob Crittenden via FreeIPA-devel
Tibor Dudlák via FreeIPA-devel wrote: > Hello FreeIPA-devel listfellow beings! > > I would like to continue the discussion started in [1], and find > itssolution. > > While using the Single-Sign-on authentication provided via anMIT > Kerberos KDC  there must not be any significant clock skew betw

[Freeipa-devel] Re: IPA's NTP service

2018-02-06 Thread Tibor Dudlák via FreeIPA-devel
Hi! To be more clear about what i do want to achieve, there is bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1456863 I want to replace ntp configuration with script provided by Miroslav Lichvar. And if any administrator would like to have another time synchronization service up and r

[Freeipa-devel] Re: IPA's NTP service

2018-01-30 Thread Levin Stanislav via FreeIPA-devel
Hello. I have several suggestions: 1) make an optional requires of server/client packages to ntpd, because last could conflict with another NTP server/client (based to platform); 2) make an abstract NTP module to easy change basic operations (like read/write configuration, time sync); 3) based

[Freeipa-devel] Re: IPA's NTP service

2018-01-29 Thread Tibor Dudlák via FreeIPA-devel
On Mon, Jan 29, 2018 at 3:09 PM, Simo Sorce wrote: > On Mon, 2018-01-29 at 14:54 +0100, Tibor Dudlák wrote: > > [...] > > > > > > So given the above we initially decided to make IPA servers also > ntp > > > > > servers and configure client to use IPA server as time sources. > > > > Not configurin

[Freeipa-devel] Re: IPA's NTP service

2018-01-29 Thread Simo Sorce via FreeIPA-devel
On Mon, 2018-01-29 at 14:54 +0100, Tibor Dudlák wrote: [...] > > > > So given the above we initially decided to make IPA servers also ntp > > > > servers and configure client to use IPA server as time sources. > > Not configuring NTP service but still requiting it might be way to give > freedom

[Freeipa-devel] Re: IPA's NTP service

2018-01-29 Thread Tibor Dudlák via FreeIPA-devel
On Thu, Jan 25, 2018 at 2:02 PM, Rob Crittenden via FreeIPA-devel < freeipa-devel@lists.fedorahosted.org> wrote: > Levin Stanislav via FreeIPA-devel wrote: > > Hello All. > > > > > > There are several good NTP servers/clients. And different Linux > > distributions > > > > use them (not only ntpd o

[Freeipa-devel] Re: IPA's NTP service

2018-01-25 Thread Rob Crittenden via FreeIPA-devel
Levin Stanislav via FreeIPA-devel wrote: > Hello All. > > > There are several good NTP servers/clients. And different Linux > distributions > > use them (not only ntpd or chronyd). But FreeIPA chose ntpd strictly. It > is a > > bottleneck for a platform porting. Perhaps, FreeIPA should allow to

[Freeipa-devel] Re: IPA's NTP service

2018-01-24 Thread Levin Stanislav via FreeIPA-devel
Hello All. There are several good NTP servers/clients. And different Linux distributions use them (not only ntpd or chronyd). But FreeIPA chose ntpd strictly. It is a bottleneck for a platform porting. Perhaps, FreeIPA should allow to select administrator which one to use and should support it

[Freeipa-devel] Re: IPA's NTP service

2018-01-24 Thread Simo Sorce via FreeIPA-devel
On Wed, 2018-01-24 at 16:25 +0100, Tibor Dudlák via FreeIPA-devel wrote: > Hello FreeIPA-devel list fellow beings! > > I would like to continue the discussion started in [1], and find its > solution. > > While using the Single-Sign-on authentication provided via an MIT Kerberos > KDC there must