[Freeipa-users] Re: IPA broken after dnf update on CentOS 8

2022-01-17 Thread Abhinav Chittora via FreeIPA-users
Hi Florence, I have checked all the logs files that you mentioned and there is not a single event with ERROR log level. In my case, the installation is failed after configuring the dirserv and trying to restart pki-tomcatd@pki-tomcatd.service and the service timed out. Here the information that

[Freeipa-users] Automatic direcotry deletion on user removal

2022-01-17 Thread akshay p via FreeIPA-users
Hi, I was wondering if there is a way to automatically delete home directory on user deletion. If not i would like to learn and possibly do something that would enable me to do such a task. I ask you for pointers and thoughts on this matter. Thank you.

[Freeipa-users] Re: KDC Self Signed Certificate Creation

2022-01-17 Thread Rob Crittenden via FreeIPA-users
Mark Selby via FreeIPA-users wrote: > My company has 6 FreeIPA servers across 3 different locations. Five of the > six servers are ok, but one we could not login to. The error messages pointed > to the expired certificate located at `/var/kerberos/krb5kdc/kdc.crt` > > My question is how do I

[Freeipa-users] Re: Importing automount maps

2022-01-17 Thread Rob Crittenden via FreeIPA-users
Simon Matthews via FreeIPA-users wrote: > The Redhat documentation provides a script for importing automount maps. The > script also uses ldapadd to add some data into the LDAP server. This part > doesn't appear to work. It's not clear to me that this part needs to work. > > The part of the

[Freeipa-users] Re: Importing automount maps

2022-01-17 Thread Simon Matthews via FreeIPA-users
The Redhat documentation that I am referring to is here: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/configuring_and_managing_identity_management/assembly_migrating-from-nis-to-identity-management_configuring-and-managing-idm I just noticed that the doc is for RH

[Freeipa-users] Importing automount maps

2022-01-17 Thread Simon Matthews via FreeIPA-users
The Redhat documentation provides a script for importing automount maps. The script also uses ldapadd to add some data into the LDAP server. This part doesn't appear to work. It's not clear to me that this part needs to work. The part of the script is: basedn=$(ipa env basedn | tr -d

[Freeipa-users] KDC Self Signed Certificate Creation

2022-01-17 Thread Mark Selby via FreeIPA-users
My company has 6 FreeIPA servers across 3 different locations. Five of the six servers are ok, but one we could not login to. The error messages pointed to the expired certificate located at `/var/kerberos/krb5kdc/kdc.crt` My question is how do I "properly" renew or recreate this certificate. I

[Freeipa-users] KDC Self Signed Certificate Creation

2022-01-17 Thread Mark Selby via FreeIPA-users
My company has 6 FreeIPA servers across 3 different locations. Five of the six servers are ok, but one we could not login to. The error messages pointed to the expired certificate located at `/var/kerberos/krb5kdc/kdc.crt` My question is how do I "properly" renew or recreate this certificate. I

[Freeipa-users] Replica KRA install - Certificate at same location is already used

2022-01-17 Thread lejeczek via FreeIPA-users
Hi guys. Is this critical on its face and un/reinstall is necessary or some troubleshooting can still reveal it's all good? ...   [4/10]: destroying installation admin user   [5/10]: enabling ephemeral requests   [6/10]: restarting KRA   [7/10]: configure certmonger for renewals   [8/10]:

[Freeipa-users] Re: After OS/IPA updates Employee attributes in web app are blank

2022-01-17 Thread Rob Crittenden via FreeIPA-users
Scott Serr via FreeIPA-users wrote: > On 1/12/22 11:43 AM, Rob Crittenden wrote: > >> Scott Serr via FreeIPA-users wrote: >>> Attributes in the Employee Information section of the user web page >>> are blank following a series of OS/IPA updates.  >>> The "ipa user-find --all" cli command shows

[Freeipa-users] Re: on stand-alone detached master - force-add KRA - ?

2022-01-17 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > On 17/01/2022 16:20, Rob Crittenden wrote: >> lejeczek via FreeIPA-users wrote: >>> Hi guys >>> >>> Is it possible on a detached master to setup KRA, as if it was first >>> master? >> What is a detached master and why do you need to "force" install a KRA >> on

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Harry G. Coin via FreeIPA-users
On 1/17/22 11:08, lejeczek via FreeIPA-users wrote: On 17/01/2022 16:06, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Alexander Bokovoy via FreeIPA-users
On ma, 17 tammi 2022, lejeczek via FreeIPA-users wrote: On 17/01/2022 16:06, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Alexander Bokovoy via FreeIPA-users
On ma, 17 tammi 2022, Harry G. Coin wrote: On 1/17/22 10:26, Alexander Bokovoy wrote: On ma, 17 tammi 2022, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread lejeczek via FreeIPA-users
On 17/01/2022 16:06, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that

[Freeipa-users] Re: Some ipa user passwords did not work after update

2022-01-17 Thread Alexander Bokovoy via FreeIPA-users
On ma, 17 tammi 2022, Rob Crittenden via FreeIPA-users wrote: Ronald Wimmer via FreeIPA-users wrote: On 13.01.22 09:29, Ronald Wimmer via FreeIPA-users wrote: Today the problem reappeared. I cannot login with the admin user.  The error message I get is "The password or username you entered is

[Freeipa-users] Re: Some ipa user passwords did not work after update

2022-01-17 Thread Rob Crittenden via FreeIPA-users
Ronald Wimmer via FreeIPA-users wrote: > On 13.01.22 09:29, Ronald Wimmer via FreeIPA-users wrote: >> Today the problem reappeared. I cannot login with the admin user.  The >> error message I get is "The password or username you entered is >> incorrect". kinit also does not work. >> >> It seems

[Freeipa-users] Re: on stand-alone detached master - force-add KRA - ?

2022-01-17 Thread lejeczek via FreeIPA-users
On 17/01/2022 16:20, Rob Crittenden wrote: lejeczek via FreeIPA-users wrote: Hi guys Is it possible on a detached master to setup KRA, as if it was first master? What is a detached master and why do you need to "force" install a KRA on it? Assuming it's a server from an existing installation

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Harry G. Coin via FreeIPA-users
On 1/17/22 10:26, Alexander Bokovoy wrote: On ma, 17 tammi 2022, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived"

[Freeipa-users] Re: IPA broken after dnf update on CentOS 8

2022-01-17 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, What versions are you using? # cat /etc/redhat-release # rpm -qa ipa-server pki-server java-1.8.0-openjdk 389-ds-base There were known issues with some jdk versions, as well as incompatibilities between versions of 389-ds-base and pki-server. The following troubleshooting page

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Alexander Bokovoy via FreeIPA-users
On ma, 17 tammi 2022, Harry G. Coin via FreeIPA-users wrote: On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that

[Freeipa-users] Re: on stand-alone detached master - force-add KRA - ?

2022-01-17 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > Hi guys > > Is it possible on a detached master to setup KRA, as if it was first > master? What is a detached master and why do you need to "force" install a KRA on it? Assuming it's a server from an existing installation you've removed all replication with,

[Freeipa-users] on stand-alone detached master - force-add KRA - ?

2022-01-17 Thread lejeczek via FreeIPA-users
Hi guys Is it possible on a detached master to setup KRA, as if it was first master? many thanks, L. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread Harry G. Coin via FreeIPA-users
On 1/17/22 05:30, lejeczek via FreeIPA-users wrote: On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that integrated Samba serves up under different hostname/domain

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread lejeczek via FreeIPA-users
On 16/01/2022 20:25, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that integrated Samba serves up under different hostname/domain and serves non-enrolled clients(win 10) too. With new

[Freeipa-users] Re: DoD Common Access Card for authentication

2022-01-17 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, the official documentation for Smart Card + IdM is available at https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/managing_smart_card_authentication/index It also contains a troubleshooting section at the end that may help you narrow down the issue. HTH, flo On

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread lejeczek via FreeIPA-users
On 17/01/2022 09:18, lejeczek via FreeIPA-users wrote: On 17/01/2022 06:19, Alexander Bokovoy wrote: On su, 16 tammi 2022, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that integrated

[Freeipa-users] Re: HA / high availability service - ?

2022-01-17 Thread lejeczek via FreeIPA-users
On 17/01/2022 06:19, Alexander Bokovoy wrote: On su, 16 tammi 2022, lejeczek via FreeIPA-users wrote: Hi guys. I have an old - set up ~2 yrs ago - IPA domain which "survived" updates/upgrades till this day in such a way that integrated Samba serves up under different hostname/domain and