[Freeipa-users] Re: krb5_child always reports going offline when trying to login

2019-06-05 Thread Sumit Bose via FreeIPA-users
On Thu, Jun 06, 2019 at 04:38:03AM +, Robert Sturrock via FreeIPA-users wrote: > Hi All. > > I have a small test installation of IPA (RHEL7, > ipa-server-4.6.4-10.el7_6.3.x86_64) in a sync arrangement with our local AD > (passwords sync’d via Passsync). > > When trying to login to the IPA

[Freeipa-users] krb5_child always reports going offline when trying to login

2019-06-05 Thread Robert Sturrock via FreeIPA-users
Hi All. I have a small test installation of IPA (RHEL7, ipa-server-4.6.4-10.el7_6.3.x86_64) in a sync arrangement with our local AD (passwords sync’d via Passsync). When trying to login to the IPA server as myself (rns) or other IPA user, sssd seems to report going offline in krb5_child.log af

[Freeipa-users] Re: Minimal ipa configuration (inside docker)

2019-06-05 Thread Dmitry Perets via FreeIPA-users
> Dmitry Perets via FreeIPA-users wrote: > > The directory /var/lib/ipa-client/sysrestore has to exist and must > contain at least one file > > rob This is when I am embarassed that I didn't find time to look into the code myself =) Thank you very much, it worked perfectly! ___

[Freeipa-users] Re: Minimal ipa configuration (inside docker)

2019-06-05 Thread Rob Crittenden via FreeIPA-users
Dmitry Perets via FreeIPA-users wrote: > Hi, > > Could you please help me configuring ipa tool inside the docker container > which is not enrolled? > > I have a parent Linux VM that is enrolled in FreeIPA. On top of it I run a > docker container, and I mount the entire /etc/ipa and /etc/krb5.c

[Freeipa-users] Re: Minimal ipa configuration (inside docker)

2019-06-05 Thread Dmitry Perets via FreeIPA-users
TBH another problem is that REST API for vaults is not as easy as I thought... The call "vault_retrieve_internal" is a not so simple, I see that it requires to generate a session_key and the secret will be returned encrypted with it... I'd appreciate if someone could point me to a working snippe

[Freeipa-users] Re: FreeIPA, OSX, DockerDesktop

2019-06-05 Thread Alexander Bokovoy via FreeIPA-users
On ke, 05 kesä 2019, James James via FreeIPA-users wrote: mkdir -p /tmp/ip-data/etc/selinux/config $ docker rm -f freeipa-server-container freeipa-server-container $ docker run --name freeipa-server-container -ti -h ipa.example.test --read-only -v /tmp/ip-data:/data:Z freeipa-server --sysctl ne

[Freeipa-users] Re: FreeIPA, OSX, DockerDesktop

2019-06-05 Thread James James via FreeIPA-users
mkdir -p /tmp/ip-data/etc/selinux/config $ docker rm -f freeipa-server-container freeipa-server-container $ docker run --name freeipa-server-container -ti -h ipa.example.test --read-only -v /tmp/ip-data:/data:Z freeipa-server --sysctl net.ipv6.conf.all.disable_ipv6=0 tar: .configfiles-noreplace/e

[Freeipa-users] Re: Minimal ipa configuration (inside docker)

2019-06-05 Thread Dmitry Perets via FreeIPA-users
> > Regarding your docker issue; IPA expects more than just a file and a config > directory, you > can check the source code for ipaclient, the cli and the modules it imports, > you’ll see a > large amount of checks it’s using to find out if the install is OK and > working. > If you just want t

[Freeipa-users] Re: FreeIPA, OSX, DockerDesktop

2019-06-05 Thread James James via FreeIPA-users
$ docker run --name freeipa-server-container -ti -h ipa.example.test --read-only -v /tmp/ip-data:/data:Z freeipa-server --sysctl net.ipv6.conf.all.disable_ipv6=0 tar: etc/pam.d/password-auth: Cannot utime: No such file or directory tar: etc/pam.d/fingerprint-auth: Cannot utime: No such file or di

[Freeipa-users] Re: Minimal ipa configuration (inside docker)

2019-06-05 Thread John Keates via FreeIPA-users
Keep in mind that when you use RHEL, features that aren’t available (due to supported versions restrictions) should probably not be hacked/bypassed because that would probably void your support just as well. If you want something unsupported you might as well use something else (Fedora, CentOS),

[Freeipa-users] Minimal ipa configuration (inside docker)

2019-06-05 Thread Dmitry Perets via FreeIPA-users
Hi, Could you please help me configuring ipa tool inside the docker container which is not enrolled? I have a parent Linux VM that is enrolled in FreeIPA. On top of it I run a docker container, and I mount the entire /etc/ipa and /etc/krb5.conf (both in read-only mode). My goal is just to be

[Freeipa-users] Re: FreeIPA DNS keeps losing certain A records

2019-06-05 Thread Kees Bakker via FreeIPA-users
Do you perhaps have DHCP updating DNS? On 04-06-19 20:10, Kristian Petersen via FreeIPA-users wrote: For the last few months I have noticed that certain A records keep disappearing from my DNS.  I have put them back manually multiple times and the same thing happens again.  The SSHFP stuff in