[Freeipa-users] Re: FreeIPA fails to start on CentOS 8

2019-11-15 Thread Andrew Meyer via FreeIPA-users
So since I was using an externally registered domain. The install script didn't create the SSHFP records. I am still working on delegating DNS to my FIPA server. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe

[Freeipa-users] Re: Can AD admins convert a 1-way trust to a 2-way trust without touching the freeIPA system?

2019-11-15 Thread Alexander Bokovoy via FreeIPA-users
On pe, 15 marras 2019, Chris Dagdigian via FreeIPA-users wrote: I just got CCd on an email chain concerning a conversion of 1-way AD trusts to 2-way trust for some realms and domains we use in one of the public cloud providers. The AD team is finally responding to all the issues they caused

[Freeipa-users] Re: Unable to authorize via HTTP

2019-11-15 Thread Rob Crittenden via FreeIPA-users
Tristan Weis via FreeIPA-users wrote: > Hey Rob, > thank you so much for your help! > > I just checked certutil... it works with the added -d database location. > Upon trying to create a new certificate for HTTP, ipa-getcert list gives me: > >> Request ID '20191115101517': >>status:

[Freeipa-users] Re: Unable to authorize via HTTP

2019-11-15 Thread Tristan Weis via FreeIPA-users
Hey Rob, thank you so much for your help! I just checked certutil... it works with the added -d database location. Upon trying to create a new certificate for HTTP, ipa-getcert list gives me: > Request ID '20191115101517': >status: CA_UNREACHABLE > ca-error: Server at

[Freeipa-users] Can AD admins convert a 1-way trust to a 2-way trust without touching the freeIPA system?

2019-11-15 Thread Chris Dagdigian via FreeIPA-users
I just got CCd on an email chain concerning a conversion of 1-way AD trusts to 2-way trust for some realms and domains we use in one of the public cloud providers. The AD team is finally responding to all the issues they caused us in the cloud by refusing a 2-way trust in the first place. It