[Freeipa-users] What is the meaning of "kpasswd: Clients credentials have been revoked getting initial ticket"

2019-12-11 Thread lune voo via FreeIPA-users
Hello everyone. I contact you because I have a problem when I reinitialize some passwords for other users. I created a login in IPA and I added this login into the admins group. Then I was able to perform some password changes for other accounts, using : 1. ipa passwd to set a one time password

[Freeipa-users] Re: Using shortname on old sssd (rhel6)

2019-12-11 Thread John Desantis via FreeIPA-users
Hello, > My issue is on the rhel6 servers: sssd there is 1.13.3, so multi-domain isn't > available... Which is a bummer for me because we have 1000+ rhel6 servers and > this is going to be a pain to have sometimes longnames, sometimes shortnames. > Has anyone work around this already? I

[Freeipa-users] Re: Using shortname on old sssd (rhel6)

2019-12-11 Thread Louis Abel via FreeIPA-users
As far as I know, it isn't possible on 1.13.3. You would need to get a newer SSSD version (not recommended from a RHEL support standpoint). See this from the archive: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/7DYBLORRYGV2IV3D3NUGRV47QV5CVHIA/

[Freeipa-users] FreeIPA - EL8 - smart card login

2019-12-11 Thread Winfried de Heiden via FreeIPA-users
Running FreeIPA 4.7.1, on CentOS 8, I configured IPA-server to use smartcard login follwoing

[Freeipa-users] Using shortname on old sssd (rhel6)

2019-12-11 Thread S Toulmonde via FreeIPA-users
Hello all! I'm migration our old LDAP infra to IPA 4.6.5 (rhel 7) with an external trust to Windows. Previously, all users were their shortname because we replicated AD users to LDAP. Most users reside in AD, but we have *nix-only users in LDAP. Everything seems fine for rhel7+ because sssd