[Freeipa-users] Re: Keycloak with FreeIPA federation / expired Password

2020-03-23 Thread Rob Crittenden via FreeIPA-users
Jonatan Zint via FreeIPA-users wrote: > Hey rob, > > thanks for quick reply. Am I doing something utterly stupid? Usually I > use ADS for ldap adminstration, I confirmed i use cn=Directory Manager > for connection, and I am not able to find > cn=ipa_pwd_extop,cn=plugins,cn=config . > > Same

[Freeipa-users] Re: Keycloak with FreeIPA federation / expired Password

2020-03-23 Thread Jonatan Zint via FreeIPA-users
Hey rob, thanks for quick reply. Am I doing something utterly stupid? Usually I use ADS for ldap adminstration, I confirmed i use cn=Directory Manager for connection, and I am not able to find cn=ipa_pwd_extop,cn=plugins,cn=config . Same with ldapsearch: ldapsearch -x -D "cn=Directory Manager"

[Freeipa-users] Re: Expired Certificates, rolling back time didn't help

2020-03-23 Thread Bhavin Vaidya via FreeIPA-users
Hello, We carried out following steps, but certificates will still not renew. stop ntpd fall back to 2018-05-11 (Mar 11th, 2018) ipactl stop started all but ntpd service manually systemctl restart certomonger Waited for more than an hour, but certificates still didn't get update. Now our other

[Freeipa-users] Re: Keycloak with FreeIPA federation / expired Password

2020-03-23 Thread Rob Crittenden via FreeIPA-users
Jonatan Zint via FreeIPA-users wrote: > Hello! > > I have a simple setup running keycloak 9.0.0 setup with LDAP user federation > to my FreeIPA instance (4.8). > Runs smooth so far, but everytime a user changes his password in keycloak it > is marked expired in FreeIPA and gets prompted to

[Freeipa-users] Keycloak with FreeIPA federation / expired Password

2020-03-23 Thread Jonatan Zint via FreeIPA-users
Hello! I have a simple setup running keycloak 9.0.0 setup with LDAP user federation to my FreeIPA instance (4.8). Runs smooth so far, but everytime a user changes his password in keycloak it is marked expired in FreeIPA and gets prompted to change it once trying to login in FreeIPA. The very

[Freeipa-users] Fail to login to IPA server after installation with IPA accounts

2020-03-23 Thread Scott Reed via FreeIPA-users
Hi, I'm running a single server with multiple clients. The OS is Centos 7. When I installed the server, I created the accounts and then installed the clients. Overall, the installations went great, and I checked the clients that I could login with the new accounts that were created. All

[Freeipa-users] Re: Managing different Sub CAs in FreeIPA without their shared Root CA

2020-03-23 Thread Florence Blanc-Renaud via FreeIPA-users
On 3/20/20 12:32 PM, Alex P via FreeIPA-users wrote: I continued setting this up. From the externally signed ipa root CA I was trying to create a nested structure of additional CAs. However this doesn't seem to be supported. Is that correct? Here is similar of what I tried: Root (externally

[Freeipa-users] Re: FreeIPA ReadTheDocs site

2020-03-23 Thread Alexander Bokovoy via FreeIPA-users
Hi Dirk, On ma, 23 maalis 2020, Dirk Streubel via FreeIPA-users wrote: Hello Alexander, is there i could do in my "downtime" let me know. Thanks for volunteering! ;) We have a bunch of design pages in https://www.freeipa.org/page/V4_Designs It would be nice to convert them to

[Freeipa-users] Re: FreeIPA ReadTheDocs site

2020-03-23 Thread Dirk Streubel via FreeIPA-users
Hello Alexander, is there i could do in my "downtime" let me know. Regards Dirk Am 21.03.20 um 07:30 schrieb Alexander Bokovoy via FreeIPA-users: > Hi, > > Thanks to Christian Heimes' work, we now have auto-generated FreeIPA > documentation at https://freeipa.readthedocs.io/en/latest/. It

[Freeipa-users] Re: Can't SSH to client after migrate

2020-03-23 Thread Alexander Bokovoy via FreeIPA-users
On ma, 23 maalis 2020, Faraz Younus via FreeIPA-users wrote: I enrolled my client using below command previously it was working for other old freeipa server with 3.0 version, Now I enrolled this client 3.0 version with new IPA server with version 4.6. ipa-client-install --mkhomedir