[Freeipa-users] Re: Issues with pki-tomcat - CA

2019-06-11 Thread Rob Crittenden via FreeIPA-users
Ian Kumlien via FreeIPA-users wrote: > Hi, > > I've been confused by this a while... But from talking to people on > #freeipa@freenode this might be the real issue: > > certutil -d /etc/pki/pki-tomcat/alias/ -L |grep cert-pki-ca > Server-Cert cert-pki-ca

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
Thanks you for all informations. Karim Bourenane +33686464439 +32475753687 Le mar. 11 juin 2019 à 15:33, John Keates a écrit : > IPA als already highly available, from the service side using DNS and > multiple records for all services, on the web side: every server has a > working web

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Peter Fern via FreeIPA-users
On 11/6/19 11:33 pm, John Keates via FreeIPA-users wrote: IPA als already highly available, from the service side using DNS and multiple records for all services, on the web side: every server has a working web interface. If you want to redirect users to any working interface, a generic load

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread John Keates via FreeIPA-users
IPA als already highly available, from the service side using DNS and multiple records for all services, on the web side: every server has a working web interface. If you want to redirect users to any working interface, a generic load balancer without keepalive works, redirect them to the IP

[Freeipa-users] Issues with pki-tomcat - CA

2019-06-11 Thread Ian Kumlien via FreeIPA-users
Hi, I've been confused by this a while... But from talking to people on #freeipa@freenode this might be the real issue: certutil -d /etc/pki/pki-tomcat/alias/ -L |grep cert-pki-ca Server-Cert cert-pki-ca u,u,u --- I have been trying ipa-.cert-fix, which

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
Thanks François, for your reply. The goal, is to have the service IPA available always, if the server 1 will be down, and also for load sharing. I thought about roundrobin dns, but sharing service is not mastered for effective sharing and the life test is not present. Bien à vous Mr Karim

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread François Cami via FreeIPA-users
On Tue, Jun 11, 2019 at 2:54 PM Karim Bourenane wrote: > > Thanks François, for your reply. > > The goal, is to have the service IPA available always, if the server 1 will > be down, and also for load sharing. Load-balancing is normally done automatically by servers/replicas and clients. If

[Freeipa-users] Re: [HAProxy / Keepalive] After installation

2019-06-11 Thread François Cami via FreeIPA-users
Hi Karim, On Tue, Jun 11, 2019 at 1:56 PM Karim Bourenane via FreeIPA-users wrote: > > Hello team > > Hope you are well. > > After an existing installation, we decide to implement a Haproxy + Keepalive > in all our IPA's servers. > > The haproxy / keepalive work weel but now the IPA doent run

[Freeipa-users] [HAProxy / Keepalive] After installation

2019-06-11 Thread Karim Bourenane via FreeIPA-users
Hello team Hope you are well. After an existing installation, we decide to implement a Haproxy + Keepalive in all our IPA's servers. The haproxy / keepalive work weel but now the IPA doent run weel, because he want to listen on all interface in the servers. Ho i can to modify the IPA (+ all

[Freeipa-users] Re: error in FreeIPA UI login page

2019-06-11 Thread Florence Blanc-Renaud via FreeIPA-users
On 6/11/19 7:13 AM, Elham Sadat Azarian via FreeIPA-users wrote: Hi. its the ipaclient-install.log 2019-06-11T04:45:38Z DEBUG Logging to /var/log/ipaclient-install.log 2019-06-11T04:45:38Z DEBUG ipa-client-install was invoked with arguments [] and options: {'no_dns_sshfp': False, 'force':