[Freeipa-users] Re: ipa-ca-install fails on directory manager password

2020-02-09 Thread Alexander Bokovoy via FreeIPA-users
On su, 09 helmi 2020, Nicholas DeMarco via FreeIPA-users wrote: After successfully promoting an IPA server to a replica, ipa-ca-install fails with "Directory Manager password is invalid" This noob would appreciate a command and example to verify I have the correct directory manager password.

[Freeipa-users] Re: sss_ssh_authorizedkeys slow on IPA-server

2020-02-09 Thread Sumit Bose via FreeIPA-users
On Sun, Feb 09, 2020 at 11:06:46PM +0200, Alexander Bokovoy via FreeIPA-users wrote: > On su, 09 helmi 2020, Winfried de Heiden via FreeIPA-users wrote: > > Hi all, > > For some reason, for a particular user, sss_ssh_authorizedkeys is extremely > > slow on the IPA-server: > > time

[Freeipa-users] ipa-ca-install fails on directory manager password

2020-02-09 Thread Nicholas DeMarco via FreeIPA-users
After successfully promoting an IPA server to a replica, ipa-ca-install fails with "Directory Manager password is invalid" This noob would appreciate a command and example to verify I have the correct directory manager password. I've looked through this page:

[Freeipa-users] Re: sss_ssh_authorizedkeys slow on IPA-server

2020-02-09 Thread Alexander Bokovoy via FreeIPA-users
On su, 09 helmi 2020, Winfried de Heiden via FreeIPA-users wrote: Hi all, For some reason, for a particular user, sss_ssh_authorizedkeys is extremely slow on the IPA-server: time /usr/bin/sss_ssh_authorizedkeys ~real 0m9.520suser 0m0.022ssys 0m0.018s It will return all the public

[Freeipa-users] Re: sss_ssh_authorizedkeys slow on IPA-server

2020-02-09 Thread Christophe TREFOIS via FreeIPA-users
Have you check authentication source order in nsswitch.conf ? Maybe there it hit some timeout or so. From: Winfried de Heiden via FreeIPA-users Sent: dimanche 9 février 2020 13:55 To: freeipa-users@lists.fedorahosted.org Cc: Winfried de Heiden Subject: [Freeipa-users] sss_ssh_authorizedkeys

[Freeipa-users] sss_ssh_authorizedkeys slow on IPA-server

2020-02-09 Thread Winfried de Heiden via FreeIPA-users
Hi all, For some reason, for a particular user, sss_ssh_authorizedkeys is extremely slow on the IPA-server: time /usr/bin/sss_ssh_authorizedkeys ~real0m9.520suser 0m0.022ssys 0m0.018s It will return all the public keys, but is is slow, causing SSH-login delays using a ssh-keys. On

[Freeipa-users] Re: How to restrict FreeIPA's from registering external IPs on DNS?

2020-02-09 Thread Natxo Asenjo via FreeIPA-users
hi Vinícius, On Fri, Feb 7, 2020 at 9:29 PM Vinícius Ferrão via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hello, > > My FreeIPA server have two IP addresses. It registers itself with the > internal and the external addresses. There’s a way to only register the IPs > from