[Freeipa-users] Re: Free IPA DNS Issues

2023-10-11 Thread Pradeep KNS via FreeIPA-users
Hey, Do we have any docs regarding this? Also where to set tuning settings like suppose if i want to make any changes on ipa server how frequently it will apply the changes to clients? Coz once i remove the users public key first its allowing him into ssh server first and second attempt he is

[Freeipa-users] Re: Free IPA DNS Issues

2023-10-11 Thread Pradeep KNS via FreeIPA-users
Hi, Thanks for the links Alexander,I tried to setup as per the documents it is working without any issues. Problem: I tried to bring the ipa server down and I am still able to communicate with ssh-key mechanism.How it is possible and how it is allowing me to communicate.Ideally when the ipa

[Freeipa-users] Re: Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: You have to use some identity to bind to LDAP. For example, use your own user account. $ ldapsearch -x -H ldap://new.ipa1 \ -D uid=finn,cn=users,cn=accounts,dc=example,dc=com -W \

[Freeipa-users] Re: Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Finn Fysj via FreeIPA-users
> On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: > > You have to use some identity to bind to LDAP. For example, use your own > user account. > > $ ldapsearch -x -H ldap://new.ipa1 \ >-D uid=finn,cn=users,cn=accounts,dc=example,dc=com -W \ >-b

[Freeipa-users] Re: Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: memberof and ipaSSHPubKey attributes are only allowed to be read, searched and compared by authenticated LDAP connections. If your connection is anonymous, you have no access to those

[Freeipa-users] Re: Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Finn Fysj via FreeIPA-users
> On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: > > memberof and ipaSSHPubKey attributes are only allowed to be read, > searched and compared by authenticated LDAP connections. If your > connection is anonymous, you have no access to those attributes. > > > The configuration below

[Freeipa-users] Re: Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 11 кас 2023, Finn Fysj via FreeIPA-users wrote: I've setup two new IPA nodes which I migrated users & groups from an old IPA server. When I do a ldapsearch -x uid=test-user on my client I'm not able to receive LDAP attributes such as memberof and ipaSshPubKey. However, this is possible

[Freeipa-users] Cannot receive LDAP attributes 'memberof' and 'ipaSshPubKey' on new IPA nodes.

2023-10-11 Thread Finn Fysj via FreeIPA-users
I've setup two new IPA nodes which I migrated users & groups from an old IPA server. When I do a ldapsearch -x uid=test-user on my client I'm not able to receive LDAP attributes such as memberof and ipaSshPubKey. However, this is possible if I log onto the IPA nodes and do the ldapsearch. I

[Freeipa-users] Re: Migration sequencing

2023-10-11 Thread Alexander Bokovoy via FreeIPA-users
On Аўт, 10 кас 2023, Johnnie W Adams wrote: On Tue, Oct 10, 2023 at 2:48 AM Alexander Bokovoy wrote: On Пан, 09 кас 2023, Johnnie W Adams via FreeIPA-users wrote: >Hi, folks, > > We've got a small shop with around a hundred RHEL boxes and a small >user base currently authenticating