[Freeipa-users] Re: Jira and Confluence user authentication with FreeIPA

2018-08-29 Thread Simo Sorce via FreeIPA-users
You can use something like KeyCloak or Ipsilon as an Idp to which you auth via kerberos, and then use their SAML or OIDC tokens to auth to Atlassian products. The net effect is Single Sign On, it works without issues. On Wed, 2018-08-29 at 10:22 -0500, Jacob Block via FreeIPA-users wrote: >

[Freeipa-users] Re: Switch CA from Internal (IPA) to AD

2018-08-29 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/28/2018 05:57 PM, Alexander Bokovoy via FreeIPA-users wrote: On ti, 28 elo 2018, Peter Tselios via FreeIPA-users wrote: Hello, I have a FreeIPA installation (4.5.4). There is a one-way trust with the ActiveDirectory server. We had setup 2 different CAs (one for the Linux domain and one

[Freeipa-users] Re: Jira and Confluence user authentication with FreeIPA

2018-08-29 Thread Jacob Block via FreeIPA-users
Thanks for sharing this. As a follow-up, is there currently a path for SSO with Jira + Confluence + Crucible and FreeIPA? It seems like there is a shortcoming of Atlassian products missing Kerberos support. On Tue, Aug 28, 2018 at 4:14 PM Jacob Jenner Rasmussen via FreeIPA-users <

[Freeipa-users] Re: HBAC rule for http service

2018-08-29 Thread Alexander Bokovoy via FreeIPA-users
On ke, 29 elo 2018, Jan Gardian via FreeIPA-users wrote: Hello Alexander, Thanks for help. I found that I have to name pam.d service with same name as HBAC service in IPA and it works. My mistake when reading documentation. Glad that you got it working. Yes, HBAC service name is the PAM

[Freeipa-users] Re: HBAC rule for http service

2018-08-29 Thread Jan Gardian via FreeIPA-users
Hello Alexander, Thanks for help. I found that I have to name pam.d service with same name as HBAC service in IPA and it works. My mistake when reading documentation. With kind regards, Jan Gardian On 08/28/2018 05:44 PM, Alexander Bokovoy wrote: On ti, 28 elo 2018, Jan Gardian via

[Freeipa-users] Re: Audit Log Replication

2018-08-29 Thread Alexander Bokovoy via FreeIPA-users
On ke, 29 elo 2018, Ludwig Krispenz via FreeIPA-users wrote: On 08/29/2018 08:56 AM, Alexander Bokovoy via FreeIPA-users wrote: On ke, 29 elo 2018, Quan Zhou via FreeIPA-users wrote: I have a similar question, should the audit logs be enabled on the master or replicas? If it's only enabled on

[Freeipa-users] Re: Audit Log Replication

2018-08-29 Thread Ludwig Krispenz via FreeIPA-users
On 08/29/2018 08:56 AM, Alexander Bokovoy via FreeIPA-users wrote: On ke, 29 elo 2018, Quan Zhou via FreeIPA-users wrote: I have a similar question, should the audit logs be enabled on the master or replicas? If it's only enabled on replicas would the date be consistent with the actual date

[Freeipa-users] Re: Audit Log Replication

2018-08-29 Thread Alexander Bokovoy via FreeIPA-users
On ke, 29 elo 2018, Quan Zhou via FreeIPA-users wrote: I have a similar question, should the audit logs be enabled on the master or replicas? If it's only enabled on replicas would the date be consistent with the actual date of change or just the "date" replication happens? Each IPA

[Freeipa-users] Re: Audit Log Replication

2018-08-29 Thread Quan Zhou via FreeIPA-users
I have a similar question, should the audit logs be enabled on the master or replicas? If it's only enabled on replicas would the date be consistent with the actual date of change or just the "date" replication happens? On Wed, Aug 29, 2018 at 7:05 AM Joshua Ruybal via FreeIPA-users <