[Freeipa-users] Cannot log in to the FreeIPA replica UI with AD credentials

2017-10-19 Thread Bart J via FreeIPA-users
Hi all, I set up an instance of FreeIPA server and established trust with AD domain. I configured AD users and they can successfully log in to the web UI. Then, I set up a replica. Although the trust is visible for that instance both in the web UI and CLI, AD users cannot log in to it, nor can

[Freeipa-users] Re: ERROR: CIFS server communication error: Memory allocation error (both may be "None") upon establishing trust

2017-10-13 Thread Bart J via FreeIPA-users
I found out that the reason why establishing trust didn't work was IPv6 stack. It wasn't fully configured on FreeIPA's side as we didn't use it but there were IPv6 DNS entries with AD domain controller name present. I remember that I read somewhere that you need to be able to reach all of the

[Freeipa-users] Re: ERROR: CIFS server communication error: Memory allocation error (both may be "None") upon establishing trust

2017-09-08 Thread Bart J via FreeIPA-users
I invoked this command with --external=true, but result is the same: ipa trust-add --type=ad my.domain.com --admin adminaccount --password --external=true Active Directory domain administrator's password: ipa: ERROR: CIFS server communication error: code "-1073741801", message "Memory

[Freeipa-users] ERROR: CIFS server communication error: Memory allocation error (both may be "None") upon establishing trust

2017-09-07 Thread Bart J via FreeIPA-users
Hi all, I have been trying to set up one-way trust for quite a while. I thought I have everything sorted out but when I tried to move from test environment to production, I received error below upon trying to set up trust with ipa trust add: ipa trust-add --type=ad my.domain.com --admin

[Freeipa-users] Re: Kvno error on validating one-way trust: "kvno: Decrypt integrity check failed while getting credentials"

2017-09-06 Thread Bart J via FreeIPA-users
Thank you. I checked in my test environment and setting trust with administrative credentials works. I got mixed results for Windows 2012 and Windows 2008 R2 because I previously had set up trust using administrative credentials for Windows 2012. Later, even though I deleted it on FreeIPA's