[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-23 Thread Rob Crittenden via FreeIPA-users
Ralph Crongeyer via FreeIPA-users wrote: > Can this be manually removed? W currently can't login to the web portal > due to this issue. I don't understand how one master is affecting the web server of another. By design they are independent. Can you provide details on how login is failing? rob

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-23 Thread Mark Reynolds via FreeIPA-users
On 10/23/18 12:54 PM, Ralph Crongeyer via FreeIPA-users wrote: Can this be manually removed? W currently can't login to the web portal due to this issue. http://www.port389.org/docs/389ds/howto/howto-cleanruv.html#cleanallruv Or you can run:   cleanallruv.pl -h HTH, Mark On Fri, Oct 19,

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-23 Thread Ralph Crongeyer via FreeIPA-users
Can this be manually removed? W currently can't login to the web portal due to this issue. On Fri, Oct 19, 2018 at 8:42 AM Ralph Crongeyer wrote: > The goal is to remove the replica server from the master. No split brain. > I need to remove this as we can't login to the portal because of this.

[Freeipa-users] Re: sss_ssh_authorizedkeys returns empty list

2018-10-23 Thread Johannes Falke via FreeIPA-users
You're right, and that was using LDAP. When trying to get sss_ssh_authorizedkeys working on my FreeIPA host itself just now (which of course uses id_provider = ipa), I actually encountered this problem again, too. There it was related to the fact that sss_ssh_authorizedkeys queries the

[Freeipa-users] Re: Abstracted NTP server configuration

2018-10-23 Thread Andrey Bychkov via FreeIPA-users
Hello, I fixed design page. https://www.freeipa.org/page/V4/NTP_Servers_Configuration 19.10.2018 17:11, Rob Crittenden via FreeIPA-users пишет: Andrey Bychkov via FreeIPA-users wrote: /->>There is no description about what the abstraction layer should be. What basic functions are there for

[Freeipa-users] Re: sss_ssh_authorizedkeys returns empty list

2018-10-23 Thread Alexander Bokovoy via FreeIPA-users
On ti, 23 loka 2018, Johannes Falke via FreeIPA-users wrote: For posterity, I had the same issue and fixed it by explicitly setting ldap_user_ssh_public_key = ipaSshPubKey in the domain portion of sssd.conf. Otherwise I assume it looks for the attribute "sshPublicKey", since that's what

[Freeipa-users] Re: sss_ssh_authorizedkeys returns empty list

2018-10-23 Thread Johannes Falke via FreeIPA-users
For posterity, I had the same issue and fixed it by explicitly setting ldap_user_ssh_public_key = ipaSshPubKey in the domain portion of sssd.conf. Otherwise I assume it looks for the attribute "sshPublicKey", since that's what it's called in the sssd cache DB.

[Freeipa-users] Re: GSSAPI Error: Unspecified GSS

2018-10-23 Thread Rob Crittenden via FreeIPA-users
mohammad sereshki via FreeIPA-users wrote: > Hi > But it is near 2 months that exists and servers which refer to it > sometimes ger error and it does not work prperly You need to provide more information. The snippet you provided, as I've said, is a common thing to see and can normally be ignored

[Freeipa-users] Re: Only users that has 'su-l' service *enabled* can you su - [user] to - This seems backwards ? users with 'su-l' *disabled* can su - [user] that has service enabled ....

2018-10-23 Thread Morgan Cox via FreeIPA-users
Thanks Jakub, That clears everything up. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html

[Freeipa-users] Re: Inconsistencies in account preserved status

2018-10-23 Thread Roderick Johnstone via FreeIPA-users
On 22/10/2018 21:27, Florence Blanc-Renaud wrote: On 10/22/18 2:10 PM, Roderick Johnstone via FreeIPA-users wrote: Hi This is ipa-server-4.5.4-10.el7_5.4.4.x86_64 on RHEL7.5. I've got four preserved accounts (out of a few hundred preserved accounts). On two of the servers they are showing