[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-24 Thread Rob Crittenden via FreeIPA-users
Ralph Crongeyer via FreeIPA-users wrote: > So it does allow me to login, however there is a popup that says: > "Some operations failed.", and a link "View details", when I click on > that it shows: > "invalid 'PKINIT enabled server': all masters must have IPA master role"   > And there is a button

[Freeipa-users] Re: kpasswd: Client not found in Kerberos database getting initial ticket

2018-10-24 Thread Robbie Harwood via FreeIPA-users
lune voo writes: > Hello Robbie. > > That's also the strange part, the kpasswd does not work after that. Can you post kerb logs for the failure? Thanks, --Robbie signature.asc Description: PGP signature ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Abstracted NTP server configuration

2018-10-24 Thread Rob Crittenden via FreeIPA-users
Andrey Bychkov via FreeIPA-users wrote: > Hello, I fixed design page. > > https://www.freeipa.org/page/V4/NTP_Servers_Configuration Tibor, do you have any input on this? As I read this it will be up to the end-user to install their favorite NTP client package, right? Otherwise installation is

[Freeipa-users] Re: Setting up Ubuntu client on free IPA

2018-10-24 Thread John Petrini via FreeIPA-users
sssd should be installed as a dependency when you install freeipa-client. The sssd file itself is /etc/sssd/sssd.conf. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: kpasswd: Client not found in Kerberos database getting initial ticket

2018-10-24 Thread lune voo via FreeIPA-users
Hello Robbie. That's also the strange part, the kpasswd does not work after that. Best regards. Lune Le mer. 24 oct. 2018 à 19:38, Robbie Harwood a écrit : > lune voo via FreeIPA-users > writes: > > > Hello everyone. > > > > I send you this mail because I encountered a strange problem

[Freeipa-users] Re: Setting up Ubuntu client on free IPA

2018-10-24 Thread Jatinder Kumar via FreeIPA-users
Hi, Thanks for the information, But in ubuntu, there is not "sssd" file. On Thu, Oct 25, 2018 at 12:14 AM Kristian Petersen wrote: > It is basically the same as on CentOS. The package you install is > freeipa-client instead of ipa-client, but the command to enroll the host is > the same. > >

[Freeipa-users] Fwd: Setting up Ubuntu client on free IPA

2018-10-24 Thread Jatinder Kumar via FreeIPA-users
Hi, Actually, I had installed freeipa server on my centos7 machine. But in my organization, we are using Ubuntu. Could you please give the steps so that i can add my ubuntu servers as a client in freeipa for ssh access management. Thank you jatinder

[Freeipa-users] Re: Setting up Ubuntu client on free IPA

2018-10-24 Thread Kristian Petersen via FreeIPA-users
It is basically the same as on CentOS. The package you install is freeipa-client instead of ipa-client, but the command to enroll the host is the same. On Wed, Oct 24, 2018 at 12:05 PM Jatinder Kumar via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi, > > Actually, I had

[Freeipa-users] Setting up Ubuntu client on free IPA

2018-10-24 Thread Jatinder Kumar via FreeIPA-users
Hi, Actually, I had installed freeipa server on my centos7 machine. But in my organization, we are using Ubuntu. Could you please give the steps so that i can add my ubuntu servers as a client in freeipa for ssh access management. Thank you jatinder

[Freeipa-users] Re: kpasswd: Client not found in Kerberos database getting initial ticket

2018-10-24 Thread Robbie Harwood via FreeIPA-users
lune voo via FreeIPA-users writes: > Hello everyone. > > I send you this mail because I encountered a strange problem trying to set > a password for a user I just created. > > First, I created the user with ipa user-add and for the following result : > Added user > > Then I added this user into

[Freeipa-users] Re: Account creation via API not assigning uidNumber

2018-10-24 Thread Alexander Bokovoy via FreeIPA-users
On ke, 24 loka 2018, Callum Smith via FreeIPA-users wrote: Dear Rob, I'm using the python-freeipa library: (client is initialised and logged in - tested and working with other calls such as user_show etc) client.user_add( options.username, options.first_name,

[Freeipa-users] kpasswd: Client not found in Kerberos database getting initial ticket

2018-10-24 Thread lune voo via FreeIPA-users
Hello everyone. I send you this mail because I encountered a strange problem trying to set a password for a user I just created. First, I created the user with ipa user-add and for the following result : Added user Then I added this user into a password policy group and it worked fine : Then I

[Freeipa-users] Re: Account creation via API not assigning uidNumber

2018-10-24 Thread Callum Smith via FreeIPA-users
Dear Rob, I'm using the python-freeipa library: (client is initialised and logged in - tested and working with other calls such as user_show etc) client.user_add( options.username, options.first_name, options.last_name, options.name, mail=options.mail,

[Freeipa-users] Re: ipa-replica-manage --force replica.server fails

2018-10-24 Thread Ralph Crongeyer via FreeIPA-users
So it does allow me to login, however there is a popup that says: "Some operations failed.", and a link "View details", when I click on that it shows: "invalid 'PKINIT enabled server': all masters must have IPA master role" And there is a button that says "OK", when I click on that it shows this:

[Freeipa-users] Re: Cannot add externally-signed IPA CA certificate

2018-10-24 Thread Dmitry Perets via FreeIPA-users
Sorry, I've figured it out myself... The problem was not with the Root CA certificate, the reported error is misleading here. Actually, the problem was with the certificate generated for the FreeIPA itself. It had CA:FALSE, because I forgot to select the right extension profile when signing

[Freeipa-users] Re: freeipa-server failied to instal - Debian

2018-10-24 Thread Milos Cuculovic via FreeIPA-users
Thank you Timo, In the meantime I installed the freeipa-server on another clean Ubuntu server, which worked well. Then installed the client on this one, which also worked well. Would be good however to understand what’s the issue with the first server. Milos > On 24 Oct 2018, at 13:20, Timo

[Freeipa-users] Cannot add externally-signed IPA CA certificate

2018-10-24 Thread Dmitry Perets via FreeIPA-users
Hi, I am trying to configure FreeIPA as a SubCA, and the "RootCA" is self-made with openssl. So I've signed the FreeIPA's request with my self-signed "root ca" certificate, but it looks like FreeIPA doesn't like it: ipa-server-install --external-cert-file=/root/rootca/rootcacert.pem

[Freeipa-users] Re: can clients or servers be pinned to named Active Directory servers to bypass DNS auto-discovery?

2018-10-24 Thread Chris Dagdigian via FreeIPA-users
Thanks! Replies in line Alexander Bokovoy wrote on 10/24/18 8:40 AM: On ke, 24 loka 2018, Chris Dagdigian via FreeIPA-users wrote: Is it possible to override the AD integration use of DNS queries to find AD controllers and replace the auto-discovery with a named list of domain controllers?

[Freeipa-users] Re: can clients or servers be pinned to named Active Directory servers to bypass DNS auto-discovery?

2018-10-24 Thread Alexander Bokovoy via FreeIPA-users
On ke, 24 loka 2018, Chris Dagdigian via FreeIPA-users wrote: Is it possible to override the AD integration use of DNS queries to find AD controllers and replace the auto-discovery with a named list of domain controllers? Where? In 'ipa trust-add' or in SSSD? The former has already a mechanism

[Freeipa-users] Re: Account creation via API not assigning uidNumber

2018-10-24 Thread Rob Crittenden via FreeIPA-users
Callum Smith wrote: > Dear Rob, > > Running v4.5.0 (CentOS 7.4 distribution) > API version 2.228 > > Setting it to -1 gives: > ValidationError: invalid 'uid': must be at least 1 Need more information on what exactly it is you are doing. rob > > Regards, > Callum > > -- > > Callum Smith >

[Freeipa-users] can clients or servers be pinned to named Active Directory servers to bypass DNS auto-discovery?

2018-10-24 Thread Chris Dagdigian via FreeIPA-users
Is it possible to override the AD integration use of DNS queries to find AD controllers and replace the auto-discovery with a named list of domain controllers? We've got a setup in an AWS VPC and we've found that out of the 100 or so domain controllers in DNS that a few of them refuse to talk

[Freeipa-users] Re: Account creation via API not assigning uidNumber

2018-10-24 Thread Callum Smith via FreeIPA-users
Dear Rob, Running v4.5.0 (CentOS 7.4 distribution) API version 2.228 Setting it to -1 gives: ValidationError: invalid 'uid': must be at least 1 Regards, Callum -- Callum Smith Research Computing Core Wellcome Trust Centre for Human Genetics University of Oxford e.

[Freeipa-users] Re: Account creation via API not assigning uidNumber

2018-10-24 Thread Rob Crittenden via FreeIPA-users
Callum Smith via FreeIPA-users wrote: > Dear All, > > When using the API to create an account, if I don't specify the > uidnumber I get this error: > > missing attribute "uidNumber" required by object class "posixAccount" > > I was expecting the uidNumber to function thus: "system will assign

[Freeipa-users] Account creation via API not assigning uidNumber

2018-10-24 Thread Callum Smith via FreeIPA-users
Dear All, When using the API to create an account, if I don't specify the uidnumber I get this error: missing attribute "uidNumber" required by object class "posixAccount" I was expecting the uidNumber to function thus: "system will assign one if not provided" Am I missing something?

[Freeipa-users] Re: freeipa-server failied to instal - Debian

2018-10-24 Thread Timo Aaltonen via FreeIPA-users
On 24.10.2018 09:57, Milos Cuculovic via FreeIPA-users wrote: > Anyone who could help? You are mixing Debian and Ubuntu repositories, I don't think that's a proper solution in the long run. Server install on Ubuntu 18.10 should work more or less, stock 18.04 has issues, and Debian is missing some

[Freeipa-users] Re: ipa.service "fails" to start

2018-10-24 Thread Florence Blanc-Renaud via FreeIPA-users
On 10/23/18 5:24 AM, None via FreeIPA-users wrote: Hi Flo, the journalctl reports that request is rejected, error 2. dogtag-ipa-ca-renew-agent-submit[29544]: Forwarding request to dogtag-ipa-renew-agent dogtag-ipa-renew-agent-submit[29558]: GET

[Freeipa-users] Re: freeipa-server failied to instal - Debian

2018-10-24 Thread Milos Cuculovic via FreeIPA-users
Anyone who could help? Milos Cuculovic > On 15 Oct 2018, at 14:29, Milos Cuculovic wrote: > > I am trying to install after an uninstall the freeipa-server package on > Debian, which is now failing. I normally removed all packages and config > files, something seems to still cause issues. The