[Freeipa-users] Re: Upgrading from EL7.9 to EL8

2022-06-17 Thread Alexander Bokovoy via FreeIPA-users
On pe, 17 kesä 2022, Harald Dunkel via FreeIPA-users wrote: Hi Alex, On 2022-06-15 16:23:53, Alexander Bokovoy via FreeIPA-users wrote: The same as with not doing backports to older OSes, FreeIPA depends on a *particular set* of integrated services and libraries, not just any. We choose to avo

[Freeipa-users] Re: ID Views change sudo rules for local user

2022-06-17 Thread Alessandro Fort via FreeIPA-users
On 17/06/2022 12.46, Grant Janssen wrote: what does "sudo -l -U " show? My experience flushing sss_cache has rarely been successful. When I experience issues with user sudo permissions, I restart sssd. Fixes it every time. - grant On Jun 17, 2022, at 00:53, Alessandro Fort via FreeIPA-users

[Freeipa-users] Re: ID Views change sudo rules for local user

2022-06-17 Thread Grant Janssen via FreeIPA-users
what does "sudo -l -U " show? My experience flushing sss_cache has rarely been successful. When I experience issues with user sudo permissions, I restart sssd. Fixes it every time. - grant On Jun 17, 2022, at 00:53, Alessandro Fort via FreeIPA-users mailto:freeipa-users@lists.fedorahosted.org>

[Freeipa-users] Re: Upgrading from EL7.9 to EL8

2022-06-17 Thread Harald Dunkel via FreeIPA-users
Hi Alex, On 2022-06-15 16:23:53, Alexander Bokovoy via FreeIPA-users wrote: The same as with not doing backports to older OSes, FreeIPA depends on a *particular set* of integrated services and libraries, not just any. We choose to avoid some of tough to solve upgrade issues by doing upgrade by

[Freeipa-users] ID Views change sudo rules for local user

2022-06-17 Thread Alessandro Fort via FreeIPA-users
Hi, I have a local user (let's call it local) that has NOPASSWD set in /etc/sudoers. When I apply an ID view to change my FreeIPA user's (let's call it domain) username, UID, GID, shell and home to that of local, whenever I try to use sudo after logging in with either domain or local, domain'

[Freeipa-users] kdb5_util: Plugin does not support the operation performing Kerberos version 5 release 1.11 dump

2022-06-17 Thread rui liang via FreeIPA-users
> Oh, I see.Thank you for your guidance > > My system is Ubuntu16.04 Freeipa4.3, because the current CA cert has expired > and there > are > problems, it is difficult to repair, so I want to rebuild the new environment > to recover > the user data on the old cluster, is there any good scheme rec