[Freeipa-users] Re: groups imported incorrectly (made compat tree look out of sync memberUid)

2021-06-02 Thread Rob Crittenden via FreeIPA-users
Scott Serr via FreeIPA-users wrote: > A few months ago, using IPA 4.8.7, I imported users and groups from > OpenLDAP: > > ipa -v migrate-ds --with-compat \ > --bind-dn="cn=Manager,dc=example,dc=com" \ > --user-container="ou=People,dc=example,dc=com" \ > --user-objectclass="posixAccount" \ >

[Freeipa-users] groups imported incorrectly (made compat tree look out of sync memberUid)

2021-06-02 Thread Scott Serr via FreeIPA-users
A few months ago, using IPA 4.8.7, I imported users and groups from OpenLDAP: ipa -v migrate-ds --with-compat \ --bind-dn="cn=Manager,dc=example,dc=com" \ --user-container="ou=People,dc=example,dc=com" \ --user-objectclass="posixAccount" \ --group-container="ou=Group,dc=example,dc=com" \

[Freeipa-users] Re: ipa-replica-install failing - operations error: the changelog directory already exists and is not empty

2021-06-02 Thread Sinh Lam via FreeIPA-users
Hi Flo - Thank you for the instructions. Everything is back to normal and I was able to bring up a new replica in the process after the steps were done. Sinh On June 2, 2021 at 12:46:22 AM, Florence Renaud (f...@redhat.com) wrote: Hi, thanks for the confirmation. In this case, you can fix

[Freeipa-users] Solve freeipa 'fragility' via orchestrated containers & whole-container upgrade?

2021-06-02 Thread Harry G. Coin via FreeIPA-users
Long time freeipa users have faced a certain 'fragility' freeipa has inherited, mostly as a result of freeipa being the 'band director' over a number of distinct subsystems maintained by various groups across the world. This or that 'little upgrade' in a seemingly small sub-part of freeipa

[Freeipa-users] Re: IPA RA expired, other certificates renewed

2021-06-02 Thread Rob Crittenden via FreeIPA-users
Jan Bundesmann via FreeIPA-users wrote: > Hi, thanks for your answer, > > That seems in line with not being able to communicate with the CA: > ``` > [root@ldap2 requests]# ipa cert-show 1 > ipa: ERROR: cannot connect to > 'https://ldap1:443/ca/agent/ca/displayBySerial': >

[Freeipa-users] Re: IPA RA expired, other certificates renewed

2021-06-02 Thread Jan Bundesmann via FreeIPA-users
Hi, thanks for your answer, That seems in line with not being able to communicate with the CA: ``` [root@ldap2 requests]# ipa cert-show 1 ipa: ERROR: cannot connect to 'https://ldap1:443/ca/agent/ca/displayBySerial': (SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired.

[Freeipa-users] Re: IPA RA expired, other certificates renewed

2021-06-02 Thread Jan Bundesmann via FreeIPA-users
Hi, thanks for your answer, That seems in line with not being able to communicate with the CA: ``` [root@ldap2 requests]# ipa cert-show 1 ipa: ERROR: cannot connect to 'https://ldap1:443/ca/agent/ca/displayBySerial': (SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired.

[Freeipa-users] Re: IPA RA expired, other certificates renewed

2021-06-02 Thread Rob Crittenden via FreeIPA-users
Jan Bundesmann via FreeIPA-users wrote: > Hi there, > > I need some suggestions for a certificate related problem. > The setup has 2 servers, let's call them ldap1 and ldap2 with ldap1 being the > primary system with the CA. > The certificates were to expire on june 15. > I checked on june 1st

[Freeipa-users] IPA RA expired, other certificates renewed

2021-06-02 Thread Jan Bundesmann via FreeIPA-users
Hi there, I need some suggestions for a certificate related problem. The setup has 2 servers, let's call them ldap1 and ldap2 with ldap1 being the primary system with the CA. The certificates were to expire on june 15. I checked on june 1st and on ldap1 certmonger had renewed all certificates,

[Freeipa-users] Re: ipa-replica-install failing - operations error: the changelog directory already exists and is not empty

2021-06-02 Thread Florence Renaud via FreeIPA-users
Hi, thanks for the confirmation. In this case, you can fix the issue with the following procedure: To fix the master that was missing the "cn=changelog5,cn=config" entry follow these steps: [1] Remove the directory /var/lib/dirsrv/slapd-XXX/cldb [2] Use ldapmodify and add this entry dn: