[Freeipa-users] Re: Free-IPA to RHEL IPA: ipa-crlgen-manage not present, manual options

2023-05-10 Thread John Burns via FreeIPA-users
Thank you! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidel

[Freeipa-users] Re: Yum-based upgrade causes group lookup failures.

2023-05-10 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, thanks for confirming, and glad you got it working! flo On Wed, May 10, 2023 at 4:46 PM Jeff Goddard wrote: > Flo, > > I must have made multiple edits before posting last about still > seeing issues. HAving parsed the rundeck config file again, and setting the > appropriate values as suggest

[Freeipa-users] Load balancing LDAP connection multiple IdM servers

2023-05-10 Thread James Steen via FreeIPA-users
My team has asked me to investigate the introduction of two additional IPA server into our infrastructure. This means a total of 3 servers. We also want to be able to load balance between these servers since we already have client connected to our existing ipa server through LDAP. I came across

[Freeipa-users] Load balancing LDAP connection multiple IdM servers

2023-05-10 Thread James Steen via FreeIPA-users
My team has asked me to investigate the introduction of two additional IPA server into our infrastructure. This means a total of 3 servers. We also want to be able to load balance between these servers since we already have client connected to our existing ipa server through LDAP. I came across

[Freeipa-users] Re: ipa migrate-ds - From EL7 to EL8/9

2023-05-10 Thread Finn Fysj via FreeIPA-users
> Hi, > > if you want to install a RHEL8 or RHEL9 server with the same domain name, > the recommended procedure would be to install a RHEL8 replica from your > RHEL7 server, then a RHEL9 replica from your RHEL8 server. > You can check this documentation: > >- Migrating your IdM environment fr

[Freeipa-users] IPA filters not working

2023-05-10 Thread Omar Pagan via FreeIPA-users
Hello, I have setup a bastion host with an IPA client in order to control access to the bastion host by groups. I have users in different groups, but I just got word that people outside the group / HBAC rule can access and login with their IPA credentials. Everything seems okay with the config

[Freeipa-users] Minimum Privileges to list OTP already-created token users via API (otptoken_find)

2023-05-10 Thread David Serrano Amarelle via FreeIPA-users
Hi, Does anyone know how to create user with the minimum privileges to list the users which have any OTP token created? I need to obtain this list via API (otptoken_find). It should be something alternative to assign "Full admin user" role. Thanks! __

[Freeipa-users] Minimum Privileges to list OTP already-created token users via API (otptoken_find)

2023-05-10 Thread David Serrano Amarelle via FreeIPA-users
Hi, Does anyone know how to create a user with the minimum privileges to list the users which have any OTP token created? I need to obtain this list via API (otptoken_find). It should be something alternative to assign "Full admin user" role. Thanks!

[Freeipa-users] Re: Free-IPA to RHEL IPA: ipa-crlgen-manage not present, manual options

2023-05-10 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Wed, May 10, 2023 at 12:03 AM John Burns via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Greetings! > > Can the actions within the two commands below can be done manually > (outside the RPM)? > > ipa-crlgen-manage status > ipa-crlgen-manage disable > You can refer to ht