[Freeipa-users] Re: Would like to set up a "least privilege" admin only capable of managing POSIX groups, not users.

2023-08-17 Thread Chris Cowan via FreeIPA-users
Christian, I want full admin meaning all group management. (CRUD). Add/remove group, change attributes, membership, etc... Was already aware of the manager members and that I could assign both users or groups. I have been using that and it works as I would expect. So, I will be

[Freeipa-users] Re: Would like to set up a "least privilege" admin only capable of managing POSIX groups, not users.

2023-08-17 Thread Christian Heimes via FreeIPA-users
On 17/08/2023 18.31, Chris Cowan via FreeIPA-users wrote: Reading through the docs carefully, but I'm just wondering if anyone else has done this, and if there are any "gotchas" I have to worry about? FreeIPA has role-based access control that lets you define fine-grained permissions,

[Freeipa-users] Re: Would like to set up a "least privilege" admin only capable of managing POSIX groups, not users.

2023-08-17 Thread Rob Crittenden via FreeIPA-users
Chris Cowan via FreeIPA-users wrote: > Reading through the docs carefully, but I'm just wondering if anyone else has > done this, and if there are any "gotchas" I have to worry about? It depends on what you mean by manage. There are two privileges for group management by default: Group

[Freeipa-users] Would like to set up a "least privilege" admin only capable of managing POSIX groups, not users.

2023-08-17 Thread Chris Cowan via FreeIPA-users
Reading through the docs carefully, but I'm just wondering if anyone else has done this, and if there are any "gotchas" I have to worry about? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: FreeIPA in Containers - Ready for Prod?

2023-08-17 Thread Ronald Wimmer via FreeIPA-users
We are running it successfully on VMs for several thousand IPA clients. Am 17. August 2023 11:44:53 MESZ schrieb Jonas R via FreeIPA-users : >Thank you for your fast reply, Ronald! > >I guess we'll go for VMs then. >___ >FreeIPA-users mailing list --

[Freeipa-users] Re: FreeIPA in Containers - Ready for Prod?

2023-08-17 Thread Jonas R via FreeIPA-users
Thank you for your fast reply, Ronald! I guess we'll go for VMs then. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: FreeIPA in Containers - Ready for Prod?

2023-08-17 Thread Ronald Wimmer via FreeIPA-users
As I understood the devs the only option would be an all-in-one container as splitting up the components would introduce several challenges that would need to be solved. And everything in one container is exactly the opposite what a container should be... So... we do not consider the current

[Freeipa-users] Re: Segfault from dnssec-keyfroml

2023-08-17 Thread Yavor Marinov via FreeIPA-users
The only difference is the number of files I think. Are those should be identical on both? master: https://imgur.com/a/YeZRpXX replica: https://imgur.com/a/8iEWZXJ my previous message is awaiting approval because I tried to use screenshots :) On Thu, Aug 17, 2023 at 11:58 AM Alexander Bokovoy

[Freeipa-users] FreeIPA in Containers - Ready for Prod?

2023-08-17 Thread Jonas R via FreeIPA-users
Hello all, we have setup a test system with FreeIPA running on a docker (swarm) host and are very happy with the tool. Now we are moving forward towards the planning for implementation and considering wthether to run in in Containers or VMs. On the FreeIPA website it says "the team also

[Freeipa-users] Re: Segfault from dnssec-keyfroml

2023-08-17 Thread Alexander Bokovoy via FreeIPA-users
On Чцв, 17 жні 2023, Yavor Marinov wrote: Hey Alex, thanks for your answer ;) Here is the information you requested for: -- # /usr/lib/systemd/system/ipa-dnskeysyncd.service [Unit] Description=IPA key daemon [Service]

[Freeipa-users] Re: Segfault from dnssec-keyfroml

2023-08-17 Thread Alexander Bokovoy via FreeIPA-users
On Чцв, 17 жні 2023, Yavor Marinov via FreeIPA-users wrote: Hello all, I have a running IPA and replica 4.10 on Alma 9 and lately i can see some errors starting from ipa-ods-exporter and involving some other services. The error is constant on the master and obviously is spawned from starting

[Freeipa-users] Segfault from dnssec-keyfroml

2023-08-17 Thread Yavor Marinov via FreeIPA-users
Hello all, I have a running IPA and replica 4.10 on Alma 9 and lately i can see some errors starting from ipa-ods-exporter and involving some other services. The error is constant on the master and obviously is spawned from starting ipa-ods-exporter. Below is the exact error from dnssec-keyfroml