[Freeipa-users] Re: ipa-setup-ca

2024-03-25 Thread Omar via FreeIPA-users
Attached file here. Thanks, //omar On Fri, Mar 22, 2024 at 4:53 AM Florence Blanc-Renaud wrote: > Hi, > > you can download freeipa-healthcheck and run ipa-healthcheck command on > the master/replica, it would help you identify any inconsistency in the > configuration. > > Otherwise, we need

[Freeipa-users] Re: ipa-setup-ca

2024-03-25 Thread Omar Pagan via FreeIPA-users
Hello Flo, sorry for the delay, I ran the ipa-healthcheck and all I got was warnings. I'm going to try attaching the file here. I replaced the ldap01.app.uaap.maxar.com with a new one with the DN= ldap.app.uaap.maxar.com and DNS aliases for ldap[01..03].app.uaap.maxar.com because it made

[Freeipa-users] Re: Revoked certificates not appearing in CRL

2024-03-25 Thread Sam Morris via FreeIPA-users
On 23/03/2024 13:48, Sam Morris via FreeIPA-users wrote: It looks like my CRL renewal master (RHEL 8) is not producing the CRL correctly. This was because it had "ca.certStatusUpdateInterval=0" set in /etc/pki/pki-tomcat/ca/CS.cfg - ouch. I think I got into this state when I decommissioned

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Natxo Asenjo wrote: On Mon, Mar 25, 2024 at 2:50 PM Alexander Bokovoy wrote: On Пан, 25 сак 2024, Natxo Asenjo wrote: >On Mon, Mar 25, 2024 at 1:49 PM Alexander Bokovoy >wrote: >> Can you give more details about this ID? >> > >is this a local user account ? > >On both

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Natxo Asenjo via FreeIPA-users
On Mon, Mar 25, 2024 at 2:50 PM Alexander Bokovoy wrote: > On Пан, 25 сак 2024, Natxo Asenjo wrote: > >On Mon, Mar 25, 2024 at 1:49 PM Alexander Bokovoy > >wrote: > > >> Can you give more details about this ID? > >> > > > >is this a local user account ? > > > >On both client and server involved

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Natxo Asenjo wrote: On Mon, Mar 25, 2024 at 1:49 PM Alexander Bokovoy wrote: Here we can see ID 2000 cannot be mapped to any domain and thus the ID cannot be resolved: (2024-03-25 11:17:07): [be[idm.domain.local]] [sss_domain_get_state] (0x1000): [RID#150] Domain

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Natxo Asenjo via FreeIPA-users
On Mon, Mar 25, 2024 at 1:49 PM Alexander Bokovoy wrote: > > Here we can see ID 2000 cannot be mapped to any domain and thus the ID > cannot be resolved: > > (2024-03-25 11:17:07): [be[idm.domain.local]] [sss_domain_get_state] > (0x1000): [RID#150] Domain idm.domain.local is Active > (2024-03-25

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Natxo Asenjo wrote: hi, apparently a log I attached is a bit too large and awaits moderation. Could I send it directly to you, mr Bokovoy? If it is different from the one attached to the previous email, sure. Thanks in advance. Regards, Natxo On Mon, Mar 25, 2024 at

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Natxo Asenjo wrote: hi, i have added debug = 9 to the domain/idm.domain.local in the sssd.conf of the idm server and restarted sssd. I have no hits on the server on the time when the client does a lookup using id user@domain and finding nothing (no such user) this is the

[Freeipa-users] Re: upgrade idm servers rhel 7 to 8 problems

2024-03-25 Thread Natxo Asenjo via FreeIPA-users
hi, apparently a log I attached is a bit too large and awaits moderation. Could I send it directly to you, mr Bokovoy? Thanks in advance. Regards, Natxo On Mon, Mar 25, 2024 at 12:19 PM Natxo Asenjo wrote: > hi, > > i have added debug = 9 to the domain/idm.domain.local in the sssd.conf of >

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-03-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 сак 2024, Riccardo Rotondo via FreeIPA-users wrote: Hi, I'm writing here because, 6 years after, I have the same question cknight previously asked. Any update on that? My users only login to web UI and can't perform ldap search so the only way they can obtain users info it's from

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2024-03-25 Thread Riccardo Rotondo via FreeIPA-users
Hi, I'm writing here because, 6 years after, I have the same question cknight previously asked. Any update on that? My users only login to web UI and can't perform ldap search so the only way they can obtain users info it's from the "Users" page ("#/e/user/details/userame") I understand