[Freeipa-users] Re: Setting up authentication for apache webserver (part 2) -- User is not unique

2022-01-11 Thread Grant Janssen via FreeIPA-users
this is normal (and desirable), the user is added in both users/accounts tree and the compat tree. I have had issues with nested groups when I fail to use the compat tree in my LDAP integrations. - grant ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Setting up authentication for apache webserver (part 2) -- User is not unique

2022-01-11 Thread Rob Crittenden via FreeIPA-users
Simon Matthews via FreeIPA-users wrote: > I seem to get two entries every time I create new user. This is causing the > webserver authentication to fail with the message about "User is not unique": > > [Tue Jan 11 20:42:16.645046 2022] [authnz_ldap:debug] [pid 21005] > mod_authnz_ldap.c(505):

[Freeipa-users] Setting up authentication for apache webserver (part 2) -- User is not unique

2022-01-11 Thread Simon Matthews via FreeIPA-users
I seem to get two entries every time I create new user. This is causing the webserver authentication to fail with the message about "User is not unique": [Tue Jan 11 20:42:16.645046 2022] [authnz_ldap:debug] [pid 21005] mod_authnz_ldap.c(505): [client 10.14.0.18:59704] AH01691: auth_ldap

[Freeipa-users] DNS forward zone - ? - does not forward

2022-01-11 Thread lejeczek via FreeIPA-users
Hi guys I have a basic fwd zone: -> $ ipa dnsforwardzone-show private.lot. --all --rights   dn: idnsname=private.lot.,cn=dns,dc=mine,dc=private   Zone name: private.lot.   Active zone: TRUE   Zone forwarders: 10.3.1.221, 10.3.1.222   Forward policy: only   attributelevelrights: {'objectclass':

[Freeipa-users] Re: Setting up authentication for apache webserver.

2022-01-11 Thread Simon Matthews via FreeIPA-users
> Simon Matthews via FreeIPA-users wrote: > > Remove the leading spaces on all the lines. A leading space is a > continuation marker in LDIF so the contents are being treated as a > single line. > > rob Thank you. That worked! ___ FreeIPA-users

[Freeipa-users] Re: Setting up authentication for apache webserver.

2022-01-11 Thread Rob Crittenden via FreeIPA-users
Simon Matthews via FreeIPA-users wrote: >> Simon Matthews via FreeIPA-users wrote: >> >> I'm lost. What users did you delete? A basic IPA installation contains >> only one user: admin. And that is a required account. >> >> The process you're following is to create a bind account in IPA. This is >>

[Freeipa-users] Re: Setting up authentication for apache webserver.

2022-01-11 Thread Simon Matthews via FreeIPA-users
> Simon Matthews via FreeIPA-users wrote: > > I'm lost. What users did you delete? A basic IPA installation contains > only one user: admin. And that is a required account. > > The process you're following is to create a bind account in IPA. This is > done by tweaking the ldif on the wiki page

[Freeipa-users] Re: Fresh freeipa instance (2 node cluster) does not start anymore

2022-01-11 Thread Rob Crittenden via FreeIPA-users
Jan Arnold via FreeIPA-users wrote: > Hello, > > I'm facing an issue with my newly setup freeipa instance. I narrowed it down > to the following: > > on each node there are two instances of the dirsrv running > > systemctl output: > > ● dirsrv@my-name-NET.serviceloaded failed failed

[Freeipa-users] Re: shutdown/poweroff freeipa hang if replication exists?

2022-01-11 Thread Rob Crittenden via FreeIPA-users
Harry G. Coin wrote: > > On 1/7/22 09:17, Rob Crittenden wrote: >> Harry G. Coin via FreeIPA-users wrote: >>> For the last few months, shutdown/poweroff of freeipa server systems >>> hangs until systemd forcibly terminates freeipa.  During that time I see >>> ns-slapd at nearly full CPU

[Freeipa-users] Re: Setting up authentication for apache webserver.

2022-01-11 Thread Rob Crittenden via FreeIPA-users
Simon Matthews via FreeIPA-users wrote: > I should also mention that I ran a script to delete most of the users. If > this (httpbind) is a user that is automatically configured when I set up my > ip installation, that might explain this. I'm lost. What users did you delete? A basic IPA

[Freeipa-users] DoD Common Access Card for authentication

2022-01-11 Thread Stephen Berg, Code 7309 via FreeIPA-users
Where can I find documentation for getting authentication using DoD CAC's working?  The script I got using ipa-advise hasn't seemed to set this up correctly (or maybe just not completley) on the server where I tried it.  Using a client that is bound to just that server and none of the other

[Freeipa-users] Fresh freeipa instance (2 node cluster) does not start anymore

2022-01-11 Thread Jan Arnold via FreeIPA-users
Hello, I'm facing an issue with my newly setup freeipa instance. I narrowed it down to the following: on each node there are two instances of the dirsrv running systemctl output: ● dirsrv@my-name-NET.serviceloaded failed failed389 Directory Server my-name-NET. ●