[Freeipa-users] Re: Postfix and FreeIPA

2022-04-20 Thread Harry G. Coin via FreeIPA-users
Hi Francis Generally I avoid 'top posting', but as I've only a couple things to add: Re: Spamassasin and integrations:  You can see the choices I made by visiting here:   https://rockstablesystems.com/home/mail/ It's still a preview, people who on a bad day have better grammar than mine on a g

[Freeipa-users] Re: Postfix and FreeIPA

2022-04-20 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
= On 2022-04-20 16:39, Harry G. Coin via FreeIPA-users wrote: Hi Francis Hi Harry, Thanks a lot for your input on this! I integrated freeipa with postfix/dovecot, and many other anti-spam / address validation capabilities.  I can tell you -- it's quite a bumpy ride.  I can imagine - did

[Freeipa-users] Re: Ldapsearch on employeenumber requires Directory Manager access?

2022-04-20 Thread Jim Kinney via FreeIPA-users
Hmm. My setup had the employeenumber not checked in the permissions for that role. It's working now. On April 20, 2022 11:24:53 AM EDT, Rob Crittenden wrote: >Jim Kinney via FreeIPA-users wrote: >> I need to compare a number stored on CAC with the one in >employeenumber >> in IdM. I have a non-

[Freeipa-users] Re: Ldapsearch on employeenumber requires Directory Manager access?

2022-04-20 Thread Rob Crittenden via FreeIPA-users
Jim Kinney via FreeIPA-users wrote: > I need to compare a number stored on CAC with the one in employeenumber > in IdM. I have a non-admin bind user for this and other generic LDAP > data access for 3rd party needs. But only the Directory Manager can pull > that field. > > Is there a permission se

[Freeipa-users] Ldapsearch on employeenumber requires Directory Manager access?

2022-04-20 Thread Jim Kinney via FreeIPA-users
I need to compare a number stored on CAC with the one in employeenumber in IdM. I have a non-admin bind user for this and other generic LDAP data access for 3rd party needs. But only the Directory Manager can pull that field. Is there a permission setting to allow a system account to access tha

[Freeipa-users] Re: c9s - Java update brakes IPA - ?

2022-04-20 Thread Endi Dewata via FreeIPA-users
Hi, We're in the middle of updating PKI packages (jss, tomcatjss, ldapjdk, pki-core). The old one requires Java 11, but the new one requires Java 17. The problem is the pki-core update got stuck due to gating issues. Is it possible for you to downgrade the packages for now? -- Endi S. Dewata On

[Freeipa-users] Re: Postfix and FreeIPA

2022-04-20 Thread Harry G. Coin via FreeIPA-users
Hi Francis I integrated freeipa with postfix/dovecot, and many other anti-spam / address validation capabilities.  I can tell you -- it's quite a bumpy ride.  A 'good plan' has more to do with your model of how 'real people' would expect to map onto domains, accounts and the like.  To do it p

[Freeipa-users] Re: c9s - Java update brakes IPA - ?

2022-04-20 Thread lejeczek via FreeIPA-users
On 20/04/2022 15:02, Chris Kelley via FreeIPA-users wrote: PKI packages require Java 17 in CentOS 9 Stream: https://gitlab.com/redhat/centos-stream/rpms/pki-core/-/blob/c9s/pki-core.spec#L66. What version(s) of java-*-openjdk-headless do you have? java-17-openjdk-headless should have been pu

[Freeipa-users] Re: c9s - Java update brakes IPA - ?

2022-04-20 Thread Chris Kelley via FreeIPA-users
PKI packages require Java 17 in CentOS 9 Stream: https://gitlab.com/redhat/centos-stream/rpms/pki-core/-/blob/c9s/pki-core.spec#L66. What version(s) of java-*-openjdk-headless do you have? java-17-openjdk-headless should have been pulled as a dependency when you pulled the PKI packages. ___

[Freeipa-users] Re: c9s - Java update brakes IPA - ?

2022-04-20 Thread lejeczek via FreeIPA-users
On 20/04/2022 13:58, Alexander Bokovoy wrote: On ke, 20 huhti 2022, lejeczek via FreeIPA-users wrote: Hi guys. @devel perhaps could comment if it's Java among package updates which breaks PKI ? ... ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='whale.mine.private', port

[Freeipa-users] Re: c9s - Java update brakes IPA - ?

2022-04-20 Thread Alexander Bokovoy via FreeIPA-users
On ke, 20 huhti 2022, lejeczek via FreeIPA-users wrote: Hi guys. @devel perhaps could comment if it's Java among package updates which breaks PKI ? ... ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='whale.mine.private', port=8080): Max retries exceeded with url: /ca/admin

[Freeipa-users] c9s - Java update brakes IPA - ?

2022-04-20 Thread lejeczek via FreeIPA-users
Hi guys. @devel perhaps could comment if it's Java among package updates which breaks PKI ? ... ipa-pki-wait-running: Connection failed: HTTPConnectionPool(host='whale.mine.private', port=8080): Max retries exceeded with url: /ca/admin/ca/getStatus (Caused by NewConnectionError('object at

[Freeipa-users] Re: Use SSH keys in FreeIPA to access local account on server?

2022-04-20 Thread Sander Steffann via FreeIPA-users
Hi, > On 20 Apr 2022, at 09:44, Jonathan Vaughn via FreeIPA-users > wrote: > > We have some systems which are FreeIPA connected, but (most) users don't log > in as themselves, there's a local system account they use instead (simplifies > file ownership for website changes and such, for exampl

[Freeipa-users] Use SSH keys in FreeIPA to access local account on server?

2022-04-20 Thread Jonathan Vaughn via FreeIPA-users
We have some systems which are FreeIPA connected, but (most) users don't log in as themselves, there's a local system account they use instead (simplifies file ownership for website changes and such, for example). Is there a way to have their public keys automatically accepted for this local user,