[Freeipa-users] Re: certgmonger not able to renew a certificate: 2100 (Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (C

2023-09-04 Thread Sam Morris via FreeIPA-users
On Mon, Sep 04, 2023 at 04:42:59PM +0300, Alexander Bokovoy via FreeIPA-users wrote: > On Пан, 04 вер 2023, Sam Morris via FreeIPA-users wrote: > > I've made some slight progress. I noticed that at the same time, the KDC > > logs these messages: > > > >==> /var/log/krb5kdc.log <== > >Sep

[Freeipa-users] Re: 2FA only for certain hosts/host groups

2023-09-04 Thread Ronald Wimmer via FreeIPA-users
On 30.03.23 11:15, Ronald Wimmer via FreeIPA-users wrote: On 29.03.23 23:06, Sam Morris via FreeIPA-users wrote: On 29/03/2023 21:48, Ronald Wimmer via FreeIPA-users wrote: On 29.03.23 22:30, Ronald Wimmer via FreeIPA-users wrote: Is it possible to enforce the second factor for a user only when

[Freeipa-users] Unable to compile class for JSP during CA installation

2023-09-04 Thread Konstantin Sapozhnikov via FreeIPA-users
Hello! We cant't install IPA Replica on Oracle Linux Server 8.8. When I try to install ipa-ca-install receive in ipareplica-ca-install.log: Unable to compile class for JSPDescription The server encountered an unexpected condition that prevented it from fulfilling the request.Exception< /b>org.ap

[Freeipa-users] IPA and cron(d)

2023-09-04 Thread Ronald Wimmer via FreeIPA-users
Hi, we found out that the behavior on our OL9 servers differs from the older ones. If a user should be able to use cron on a specific host (service in HBAC rule) this works on entry containing the respective user needs to exist in /etc/cron.allow on the server itself. Is this the desired behav

[Freeipa-users] Re: certgmonger not able to renew a certificate: 2100 (Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (C

2023-09-04 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 04 вер 2023, Sam Morris via FreeIPA-users wrote: I've made some slight progress. I noticed that at the same time, the KDC logs these messages: ==> /var/log/krb5kdc.log <== Sep 04 09:46:17 ipa5.ipa.example.com krb5kdc[183962](info): TGS_REQ : handle_authdata (-1765328371) Sep 04

[Freeipa-users] Re: certgmonger not able to renew a certificate: 2100 (Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (C

2023-09-04 Thread Sam Morris via FreeIPA-users
On Fri, Sep 01, 2023 at 01:59:00PM -0400, Rob Crittenden via FreeIPA-users wrote: > Sam Morris via FreeIPA-users wrote: > > Hi folks, I've got a machine where certmonger is unable to renew a > > certificate request: > > > > # getcert list -i 20220519165212 > > Number of certificates and r