[Freeipa-users] Re: Migration from NIS, hashed passwords, "Pre-authentication failed: Invalid argument while getting initial credentials"

2021-12-17 Thread Simon Matthews via FreeIPA-users
Thanks for the help. Unfortunately, I must have missed something: the password that I set with "setattr userpassword=<>" is not accepted. I set up another VM, configured it using the ipa-client-install script, and I can do "su " on the client, but both a ssh login of a "passwd" command fails

[Freeipa-users] Re: building bind-dyndb-ldap v11.9 on centos 7

2021-12-17 Thread Dave Macias via FreeIPA-users
Thank you for that! That was very insightful. I dont think im going to try to update bind on these systems. Will stick with v11.1 then. Thank you again! On Fri, Dec 17, 2021 at 5:09 PM Alexander Bokovoy wrote: > On pe, 17 joulu 2021, Dave Macias via FreeIPA-users wrote: > >Hello, > > > >First

[Freeipa-users] Re: Migration from NIS, hashed passwords, "Pre-authentication failed: Invalid argument while getting initial credentials"

2021-12-17 Thread Alexander Bokovoy via FreeIPA-users
On pe, 17 joulu 2021, Simon Matthews via FreeIPA-users wrote: Thanks for this clear explanation. What's the simplest way to test that I have properly imported the passwords? As I said in my response: --- So you need to authenticate prior to be able to use Kerberos -- either

[Freeipa-users] Re: building bind-dyndb-ldap v11.9 on centos 7

2021-12-17 Thread Alexander Bokovoy via FreeIPA-users
On pe, 17 joulu 2021, Dave Macias via FreeIPA-users wrote: Hello, First time poster to this mailing list. Hopefully it's the right list. I am trying to build this package on centos7 but i am unsuccessful.. bind-dyndb-ldap versions tied to specific bind versions. On RHEL 7 we have bind 9.11.4

[Freeipa-users] Re: Migration from NIS, hashed passwords, "Pre-authentication failed: Invalid argument while getting initial credentials"

2021-12-17 Thread Simon Matthews via FreeIPA-users
Thanks for this clear explanation. What's the simplest way to test that I have properly imported the passwords? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] building bind-dyndb-ldap v11.9 on centos 7

2021-12-17 Thread Dave Macias via FreeIPA-users
Hello, First time poster to this mailing list. Hopefully it's the right list. I am trying to build this package on centos7 but i am unsuccessful.. I am though able to successfully build it under rocky linux 8 with the below steps: dnf install -y bind-devel make autoconf automake libtool

[Freeipa-users] Re: Migration from NIS, hashed passwords, "Pre-authentication failed: Invalid argument while getting initial credentials"

2021-12-17 Thread Alexander Bokovoy via FreeIPA-users
On pe, 17 joulu 2021, Simon Matthews via FreeIPA-users wrote: Platform is a fully-updated CentOS 7 instance. I have installed ipa-server-4.6.8-5.el7.centos.9.x86_64 and all the dependent packages. The RedHat documentation tells you to use a script that sets all passwords to the same fixed

[Freeipa-users] Migration from NIS, hashed passwords, "Pre-authentication failed: Invalid argument while getting initial credentials"

2021-12-17 Thread Simon Matthews via FreeIPA-users
Platform is a fully-updated CentOS 7 instance. I have installed ipa-server-4.6.8-5.el7.centos.9.x86_64 and all the dependent packages. The RedHat documentation tells you to use a script that sets all passwords to the same fixed string, however, I would like to use the hashed passwords from my

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-12-17 Thread Alexander Bokovoy via FreeIPA-users
Hi Sam, On pe, 17 joulu 2021, Sam Morris wrote: On Fri, 2021-12-17 at 06:59 +0200, Alexander Bokovoy wrote: On to, 16 joulu 2021, Sam Morris via FreeIPA-users wrote: > > The CA has its own upgrade code which runs unconditionally and I think > > that's how both secret and requiredSecret got

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-12-17 Thread Sam Morris via FreeIPA-users
On Fri, 2021-12-17 at 06:59 +0200, Alexander Bokovoy wrote: > On to, 16 joulu 2021, Sam Morris via FreeIPA-users wrote: > > > The CA has its own upgrade code which runs unconditionally and I think > > > that's how both secret and requiredSecret got added to server.xml. I > > > wasn't able to

[Freeipa-users] sssd dereference processing timeout error

2021-12-17 Thread Stijn De Weirdt via FreeIPA-users
hi all, we have a bunch of RHEL84 sssd client for our ipa setup (also based on RHEL84), and we are seeing auth failures due to "dereference processing failed [110]: Connection timed out" does anyone have any idea where these might come from and what service/logfile on the ipa server is