[Freeipa-users] Re: Should all IPA masters in domain be returned by sssctl

2020-09-18 Thread Ranbir via FreeIPA-users
On 2020-09-16 18:28, Ranbir via FreeIPA-users wrote: On Wed, 2020-09-16 at 13:02 +0200, Sumit Bose via FreeIPA-users wrote: sssctl should show all the IPA servers which can be found with a DNS SRV query. Does e.g. host -t SRV _ldap._tcp.your.ipa.domain show more servers than the sssctl

[Freeipa-users] Re: BadRequest when using freeipa-python

2020-09-18 Thread Rob Crittenden via FreeIPA-users
Ronald Wimmer via FreeIPA-users wrote: > On 18.09.20 13:04, Rafael Jeffman via FreeIPA-users wrote: >> >> On Thu, Sep 17, 2020 at 9:59 AM Ronald Wimmer via FreeIPA-users >> > > wrote: >> >> Anyone using freeipa-python here? When I try to use >> >>

[Freeipa-users] Re: BadRequest when using freeipa-python

2020-09-18 Thread Ronald Wimmer via FreeIPA-users
On 18.09.20 13:04, Rafael Jeffman via FreeIPA-users wrote: On Thu, Sep 17, 2020 at 9:59 AM Ronald Wimmer via FreeIPA-users > wrote: Anyone using freeipa-python here? When I try to use client.host_mod('myserver.mydomain.at

[Freeipa-users] Re: IPA CA request ID reuse issue

2020-09-18 Thread Boris Sukhinin via FreeIPA-users
> Would you mind having a look through the DS error and access logs on > the affected system, to see if there are any clues about why the VLV > index became inconsistent? It seems there are no records of VLV-related errors in DS logs. The only messages in error log that contain 'vlv' term are

[Freeipa-users] Re: BadRequest when using freeipa-python

2020-09-18 Thread Rafael Jeffman via FreeIPA-users
On Thu, Sep 17, 2020 at 9:59 AM Ronald Wimmer via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Anyone using freeipa-python here? When I try to use > > client.host_mod('myserver.mydomain.at', userclass='SomeUserClass') > > the user class is set correctly on the host above but I

[Freeipa-users] Re: Renewing a failed to auto-renewal certificate

2020-09-18 Thread Florence Blanc-Renaud via FreeIPA-users
On 9/17/20 10:12 PM, Stuart McRobert via FreeIPA-users wrote: Dear All, Thanks to everyone for their help with this. In summary the problem was an inconsistency between the certificate stored in a file and in ldap, as described at the bottom of flo's blog: