[Freeipa-users] Expired Certificates.

2019-01-16 Thread Bhavin Vaidya via FreeIPA-users
Hello, We rebooted our Primary FreeIPA server (ds01) and then it will not start pki-tomcatd, Kerberos will also not work, though it starts. We realized that 2 certificates have expired. we tried stopped ipa, stopped NTP, going back to Dec 14th, 2018 and restarted certmonger, bring back date but

[Freeipa-users] Re: fiddling with Win2016 trust - users

2019-01-16 Thread Alexander Bokovoy via FreeIPA-users
On ke, 16 tammi 2019, lejeczek via FreeIPA-users wrote: hi guys After a longer break from Windowze, I had Win2012 trust okey in the past, now I'm fiddling with Win2016 and have this question: After trust (one-way coming from AD) established okey should AD's users be immediately available to/

[Freeipa-users] Re: fiddling with Win2016 trust - users

2019-01-16 Thread John Keates via FreeIPA-users
There is no enumeration support, but if you want to figure out if your connection works, try getent on a group or user (or using id on a group or user). If those don’t work the AD Trust might not be working correctly. I start the trusts on the IPA side and use Domain Admin creds (and not a secret

[Freeipa-users] fiddling with Win2016 trust - users

2019-01-16 Thread lejeczek via FreeIPA-users
hi guys After a longer break from Windowze, I had Win2012 trust okey in the past, now I'm fiddling with Win2016 and have this question: After trust (one-way coming from AD) established okey should AD's users be immediately available to/in IPA? Usual things such as id, ipa user-show do find