[Freeipa-devel] SSH Public Key - Centralized Solution

2014-12-22 Thread Prashant Bapat
Hi, We are planning to roll out FreeIPA for our AWS infrastructure to be the central authentication service. Initially we plan to use the SSH publi keys, user and group management by FreeIPA. We are looking at rolling out the SSS on clients a little later. Two questions. 1. We need to be able to

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2014-12-23 Thread Prashant Bapat
please give me some pointers on how this can be done ? Thanks again. --Prashant On 23 December 2014 at 19:45, Adam Young wrote: > > On 12/22/2014 08:40 PM, Prashant Bapat wrote: > > Hi, > > We are planning to roll out FreeIPA for our AWS infrastructure to be the > central a

[Freeipa-devel] Modifying ID Range

2014-12-23 Thread Prashant Bapat
Hi, What I'm trying to do is to modify the Range FreeIPA uses. I removed the random Range Id created during install, added a new range that I wanted. But problem is when I try to add a new user or a group now its still using the old range that was created during installation. I tried restarting t

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2014-12-29 Thread Prashant Bapat
ment FreeIPA in our org right now. Thanks in advance. --Prashant On 23 December 2014 at 21:39, Prashant Bapat wrote: > Adam, > > Thanks much for the reply. I will take a look at the code. > > For the expiration part, do you think it would be a good idea to modify > the LDAP

Re: [Freeipa-devel] SSH Public Key - Centralized Solution

2015-01-05 Thread Prashant Bapat
Ping! Any pointers for doing this would be appreciated. On 30 December 2014 at 06:27, Prashant Bapat wrote: > Hi Again, > > For enforcing SSH key rotation every N days, I'm thinking the following. > Please let me know if this makes sense. > > 1. Limit the number of keys