[Freeipa-users] Re: Confusion on LDAP changes for NIS automounts

2020-02-06 Thread Russell Jones via FreeIPA-users
For those that find this later, these settings will show up if you search cn=config specifically. No idea why it doesn't show up on a full dump. On Thu, Feb 6, 2020, 2:26 PM Russell Jones wrote: > Just some extra info. The entry is definitely in there, I just can't > figure out how to pull it

[Freeipa-users] Re: NIS client bound to FreeIPA, passwd file is asterisks instead of hash

2020-02-06 Thread Russell Jones via FreeIPA-users
Thanks! We want to auth with password though. Just found in the docs where it says NIS auth requires the hash to be set to crypt, so we are abandoning this idea. On Thu, Feb 6, 2020, 4:00 PM Rob Crittenden wrote: > Russell Jones via FreeIPA-users wrote: > > I have a client bound to FreeIPA

[Freeipa-users] Re: NIS client bound to FreeIPA, passwd file is asterisks instead of hash

2020-02-06 Thread Rob Crittenden via FreeIPA-users
Russell Jones via FreeIPA-users wrote: > I have a client bound to FreeIPA using NIS, however when doing a "ypcat > passwd" the password fields are an asterisk (*) instead of a password hash.  > > The NIS integration docs are a bit sparse - am I missing something to > allow NIS clients to

[Freeipa-users] NIS client bound to FreeIPA, passwd file is asterisks instead of hash

2020-02-06 Thread Russell Jones via FreeIPA-users
I have a client bound to FreeIPA using NIS, however when doing a "ypcat passwd" the password fields are an asterisk (*) instead of a password hash. The NIS integration docs are a bit sparse - am I missing something to allow NIS clients to authenticate against FreeIPA as an actual NIS client? Is

[Freeipa-users] Re: [EXTERNAL] Re: MediaWiki and FreeIPA ?

2020-02-06 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
Thanks, Rob. I will give it a try. __ Daniel E. White daniel.e.wh...@nasa.gov NICS Linux Engineer NASA Goddard Space Flight Center 8800 Greenbelt Road Building 14, Room

[Freeipa-users] Re: MediaWiki and FreeIPA ?

2020-02-06 Thread Rob Crittenden via FreeIPA-users
White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users wrote: > I have been trying various LDAP extensions without success. > > Most Google-able information is years old. > >   > > Anyone use this : > https://www.freeipa.org/page/Setting_up_MediaWiki_to_run_against_FreeIPA  ? My first foray

[Freeipa-users] Re: Confusion on LDAP changes for NIS automounts

2020-02-06 Thread Russell Jones via FreeIPA-users
Just some extra info. The entry is definitely in there, I just can't figure out how to pull it back out: [root@freeipa4 ~]# ldapadd -x -D "cn=Directory Manager" -W -f ./nis.txt Enter LDAP Password: adding new entry "nis-domain=+nis-map=auto.main,cn=NIS Server,cn=plugins,cn=config" ldap_add:

[Freeipa-users] MediaWiki and FreeIPA ?

2020-02-06 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
I have been trying various LDAP extensions without success. Most Google-able information is years old. Anyone use this : https://www.freeipa.org/page/Setting_up_MediaWiki_to_run_against_FreeIPA ? __

[Freeipa-users] Re: Confusion on LDAP changes for NIS automounts

2020-02-06 Thread Russell Jones via FreeIPA-users
I am logging in as the Directory Manager user. I downloaded an LDAP brower app and have also logged in as that user, and not seeing the entries anywhere there either. Here's what I am getting from a CLI standpoint: [root@freeipa4 ~]# ldapsearch -x -D "cn=Directory Manager" -W > output.txt Enter

[Freeipa-users] Re: Confusion on LDAP changes for NIS automounts

2020-02-06 Thread Rob Crittenden via FreeIPA-users
Russell Jones via FreeIPA-users wrote: > I have followed this documentation for enabling an automount to show up > for a NIS client that is bound to FreeIPA, and it worked as expected and > the NIS client can see the automount: > >

[Freeipa-users] Confusion on LDAP changes for NIS automounts

2020-02-06 Thread Russell Jones via FreeIPA-users
I have followed this documentation for enabling an automount to show up for a NIS client that is bound to FreeIPA, and it worked as expected and the NIS client can see the automount:

[Freeipa-users] Re: suggestion for password policy

2020-02-06 Thread Charles Hedrick via FreeIPA-users
OK, I was wrong. First, it doesn't appear the dict_file in kdc.conf does anything, at least not with the code used in freeipa. I suspect it’s because it only applies to users with password policies, and the standard kerberos code probably doesn’t see the freeipa global policy as a policy for