[Freeipa-users] IPA/dirsrv hang

2021-09-21 Thread Kathy Zhu via FreeIPA-users
Hi list, one of my ipa server (dirsrv) hang this morning. "ipactl status" no output and did not return. With nsslapd-errorlog-level being set to 16384, however, very few log entries. I rebooted the server to recover. But after reboot, ipa hang again then I have to reboot it. I collected

[Freeipa-users] Re: on a client logs increase size very quickly

2021-09-21 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > > > On 21/09/2021 13:26, Rob Crittenden wrote: >> lejeczek via FreeIPA-users wrote: >>> Hi guys. >>> >>> I've noticed I think a patter, such that when IPA clientA does lots of >>> ssh to a former IPA clientB (or might be to any non-IPA host?) then logs >>>

[Freeipa-users] Re: on a client logs increase size very quickly

2021-09-21 Thread lejeczek via FreeIPA-users
On 21/09/2021 13:26, Rob Crittenden wrote: lejeczek via FreeIPA-users wrote: Hi guys. I've noticed I think a patter, such that when IPA clientA does lots of ssh to a former IPA clientB (or might be to any non-IPA host?) then logs size go up rapidly. Logs: sssd_ssh.log, sssd_private.lot.log,

[Freeipa-users] Re: on a client logs increase size very quickly

2021-09-21 Thread lejeczek via FreeIPA-users
On 21/09/2021 13:26, Rob Crittenden wrote: lejeczek via FreeIPA-users wrote: Hi guys. I've noticed I think a patter, such that when IPA clientA does lots of ssh to a former IPA clientB (or might be to any non-IPA host?) then logs size go up rapidly. Logs: sssd_ssh.log, sssd_private.lot.log,

[Freeipa-users] Re: User login

2021-09-21 Thread Rob Crittenden via FreeIPA-users
Florence Renaud via FreeIPA-users wrote: > Hi, > I am not sure I understand what you mean. The below screenshot should be > the first thing you see when you go to https://ipaserver.com/ipa/ui/ > (unless you need to accept the security exception if the CA is not > trusted yet by the browser). > >

[Freeipa-users] Re: User login

2021-09-21 Thread Florence Renaud via FreeIPA-users
Hi, I am not sure I understand what you mean. The below screenshot should be the first thing you see when you go to https://ipaserver.com/ipa/ui/ (unless you need to accept the security exception if the CA is not trusted yet by the browser). Is a custom configuration applied to the http instance

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-21 Thread pp via FreeIPA-users
Thank you. Just to clarify I currently have both "secret" and "requiredSecret" set. Originally "requiredSecret" did not match the ipa secret while "secret" did. I changed "requiredSecret" to also match to fix my issue. ___ FreeIPA-users mailing list --

[Freeipa-users] Re: on a client logs increase size very quickly

2021-09-21 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > Hi guys. > > I've noticed I think a patter, such that when IPA clientA does lots of > ssh to a former IPA clientB (or might be to any non-IPA host?) then logs > size go up rapidly. > Logs: sssd_ssh.log, sssd_private.lot.log, > In terms of IPA client configs -

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-21 Thread Rob Crittenden via FreeIPA-users
pp via FreeIPA-users wrote: >> The strange thing is this upgrade code has been in IPA since 4.9.0 so >> its unclear why it decided to break now, and in the way it did. >> >> It should only change the attribute from requiredSecret to secret if >> "tomcat version" reports a version >= 9.0.31.0. >

[Freeipa-users] User login

2021-09-21 Thread Per Qvindesland via FreeIPA-users
Hi There is one thing that i have never really understood, when a user goes to https://ipaserver.com/ipa/ui/ he/she get's a Apache login prompt and has to click cancel a coulple of times before getting to the Ipa login screen.It seems to be caused by /etc/httpd/conf.d/ipa.conf which has the

[Freeipa-users] on a client logs increase size very quickly

2021-09-21 Thread lejeczek via FreeIPA-users
Hi guys. I've noticed I think a patter, such that when IPA clientA does lots of ssh to a former IPA clientB (or might be to any non-IPA host?) then logs size go up rapidly. Logs: sssd_ssh.log, sssd_private.lot.log, In terms of IPA client configs - those are vanilla default, nothing added for

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-21 Thread pp via FreeIPA-users
> The strange thing is this upgrade code has been in IPA since 4.9.0 so > its unclear why it decided to break now, and in the way it did. > > It should only change the attribute from requiredSecret to secret if > "tomcat version" reports a version >= 9.0.31.0. Yes, I noticed the python function