[Freeipa-users] Re: Server Installation Error - [error] RuntimeError: failed to create DS instance Command '/usr/sbin/setup-ds.pl

2021-03-31 Thread Steve Reed via FreeIPA-users
Hi Florence, Thanks for the idea. I checked the services and there is no service running. I verified with systemctl |grep slapd And I did look at the logs. They all stop after the install failed. And checked the ports with netstat. 389 and 636 are not being used. Thanks for your time.

[Freeipa-users] Re: custom ssl cert install error

2021-03-31 Thread Rob Crittenden via FreeIPA-users
Ashwath Kumar via FreeIPA-users wrote: > Hello Team, > > Can you please help us to troubleshoot custom ssl certificate for freeipa > service. > > Getting below error while trying. > > [root@ldap1 certs]# ipa-server-certinstall --http robosoftincom.crt > robosoftincom.key > Directory Manager

[Freeipa-users] Re: FreeIPA server packages upgrade best practice

2021-03-31 Thread Rob Crittenden via FreeIPA-users
Suchismita Panda via FreeIPA-users wrote: > Hi, > > I would like to know the best practice for patching FreeIPA-Server > packages. We generally have daily patching enabled in our servers. Will > it be a good idea to do automatic patching of FreeIPA-Server packages? > > If we want to restrict the

[Freeipa-users] custom ssl cert install error

2021-03-31 Thread Ashwath Kumar via FreeIPA-users
Hello Team, Can you please help us to troubleshoot custom ssl certificate for freeipa service. Getting below error while trying. [root@ldap1 certs]# ipa-server-certinstall --http robosoftincom.crt robosoftincom.key Directory Manager password: Enter private key unlock password: The full

[Freeipa-users] FreeIPA server packages upgrade best practice

2021-03-31 Thread Suchismita Panda via FreeIPA-users
Hi, I would like to know the best practice for patching FreeIPA-Server packages. We generally have daily patching enabled in our servers. Will it be a good idea to do automatic patching of FreeIPA-Server packages? If we want to restrict the FreeIPA-Server packages from automatomatic upgrade and

[Freeipa-users] Re: Server Installation Error - [error] RuntimeError: failed to create DS instance Command '/usr/sbin/setup-ds.pl

2021-03-31 Thread Florence Blanc-Renaud via FreeIPA-users
On 3/31/21 3:35 PM, Scott Reed via FreeIPA-users wrote: I am not new to installing FreeIPA. This one has been a struggle. I came in to help some people on there server installation. Long story short. I found the ipa-dnskeysyncd.service constantly restarting. I went and uninstalled the

[Freeipa-users] Re: ModuleNotFoundError: No module named 'ipapython'

2021-03-31 Thread Stephan Boldt via FreeIPA-users
Goshhow stupid. I did not realize I was running ansible in dry-run mode (-C). Of course the installation of the required packages does not really happen in that mode, therefore ipapython was indeed not available. As soon as I got rid of the "-C" option all worked well. O man, I really should

[Freeipa-users] Server Installation Error - [error] RuntimeError: failed to create DS instance Command '/usr/sbin/setup-ds.pl

2021-03-31 Thread Scott Reed via FreeIPA-users
I am not new to installing FreeIPA. This one has been a struggle. I came in to help some people on there server installation. Long story short. I found the ipa-dnskeysyncd.service constantly restarting. I went and uninstalled the server, and found that the slapd- service broken and I

[Freeipa-users] Re: ModuleNotFoundError: No module named 'ipapython'

2021-03-31 Thread Thomas Woerner via FreeIPA-users
Hello Stephan, On 3/31/21 1:11 PM, Stephan Boldt via FreeIPA-users wrote: Hello, I want to install IdM / FreeIPA on a RHEL 8.3 VM using Ansible running on a CentOS 8 VM. I installed the ansible-freeipa package und set up inventory and playbook as shown in the docs. Running the playbook then

[Freeipa-users] ModuleNotFoundError: No module named 'ipapython'

2021-03-31 Thread Stephan Boldt via FreeIPA-users
Hello, I want to install IdM / FreeIPA on a RHEL 8.3 VM using Ansible running on a CentOS 8 VM. I installed the ansible-freeipa package und set up inventory and playbook as shown in the docs. Running the playbook then fails with the following message: TASK [ipaserver : Install - Server

[Freeipa-users] Re: Retrieve service keytab with host keytab authentication?

2021-03-31 Thread Alexander Bokovoy via FreeIPA-users
On ke, 31 maalis 2021, Peter Tselios via FreeIPA-users wrote: Hello, When I retrieve a service keytab, what I do is more or less this: ipa-getkeytab -a admin -P password -s service/client.example.com -k /path/to/keytab However, the ipa-getkeytab man page mention this: === -Y, --mech

[Freeipa-users] Retrieve service keytab with host keytab authentication?

2021-03-31 Thread Peter Tselios via FreeIPA-users
Hello, When I retrieve a service keytab, what I do is more or less this: ipa-getkeytab -a admin -P password -s service/client.example.com -k /path/to/keytab However, the ipa-getkeytab man page mention this: === -Y, --mech SASL mechanism to use if -D and -w are not specified. Use

[Freeipa-users] FreeIPA 4.9.3 released

2021-03-31 Thread Alexander Bokovoy via FreeIPA-users
The FreeIPA team would like to announce FreeIPA 4.9.3 release! It can be downloaded from http://www.freeipa.org/page/Downloads. Builds for Fedora distributions will be available from the official repository soon. == Highlights in 4.9.3 === Bug fixes FreeIPA 4.9.3 is a stabilization release