[Freeipa-users] Re: Password policy by ip

2023-11-22 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
On 22 Nov 2023, at 14:49, Alexander Bokovoy wrote: On Аўт, 21 ліс 2023, Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: Hi, I recently started to use FreeIPA for ldap login for my mail server (dovecot). I wonder if it is possible to disable user locking when fail requests come from

[Freeipa-users] Re: ipa CLI doesn't work due to revoked TGT following S4U2PROXY_NO_HEADER_PAC

2023-11-22 Thread Kroon PC, Peter via FreeIPA-users
Hi all, So, apparently Outlook web (which I'm bound to because work, and linux) can't properly quote inline replies >< I removed `disable_pac=true` from /var/kerberos/krb5kdc/kdc.conf around the time I sent the previous mail, then restarted the server, tested, and sent the mail. However, pure

[Freeipa-users] Re: Password policy by ip

2023-11-22 Thread Alexander Bokovoy via FreeIPA-users
On Аўт, 21 ліс 2023, Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: Hi, I recently started to use FreeIPA for ldap login for my mail server (dovecot). I wonder if it is possible to disable user locking when fail requests come from dovecot. That’s because it already has fail2ban

[Freeipa-users] Re: ipa CLI doesn't work due to revoked TGT following S4U2PROXY_NO_HEADER_PAC

2023-11-22 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 20 ліс 2023, Kroon PC, Peter wrote: Hi all, I went for option B and deleted some offending groups and users, and adjusted the gidNumber of those that remained. Running `/usr/libexec/ipa/oddjob/org.freeipa.server.config-enable-sid --add-sids` produces the following logs:

[Freeipa-users] Re: Install FreeIPA with own CA and SUBCA

2023-11-22 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 22 ліс 2023, KERVELLEC Joseph via FreeIPA-users wrote: Hello, I am trying to install FreeIPA with my own CA and certutil reject my RootCA (Certificate type not approuved for application). The issue is when certutil verifies the RootCA with the certusage SSL CA (option -u L). My rootCA

[Freeipa-users] Install FreeIPA with own CA and SUBCA

2023-11-22 Thread KERVELLEC Joseph via FreeIPA-users
Hello, I am trying to install FreeIPA with my own CA and certutil reject my RootCA (Certificate type not approuved for application). The issue is when certutil verifies the RootCA with the certusage SSL CA (option -u L). My rootCA does not include sslCA in nsscertype. There is a way to