[Freeipa-users] Installing 3rd party PEM format Certificate on FreeIPA Server

2022-04-10 Thread GAURAV Pande via FreeIPA-users
Hi Guys , OS : Centos 7.9 FreeIPA Server version: 4.6.8 I was referencing to this link : https://www.freeipa.org/page/Using_3rd_part_certificates_for_HTTP/LDAP for installing 3rd party Certificate for HTTP and LDAP services of FreeIPA to make it secure . I see in this kb article .crt format

[Freeipa-users] Re: Which Ubuntu OS version have FreeIPA version 4.7.x ?

2022-04-07 Thread GAURAV Pande via FreeIPA-users
Thanks Florence . ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

[Freeipa-users] Which Ubuntu OS version have FreeIPA version 4.7.x ?

2022-04-07 Thread GAURAV Pande via FreeIPA-users
Hi Guys , Apologies for dumb question if it sounds but could you let me know which Ubuntu version comes with FreeIPA 4.7.x versions ? Couldn't find any solid reference . Thanks ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To

[Freeipa-users] Re: Can i register Centos 7 Machine using FreeIPA Client version 4.6.8 to FreeIPA server Machine on Centos 8 using 4.9.8 version?

2022-03-28 Thread GAURAV Pande via FreeIPA-users
Thanks for Clarification Alexander ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: Can i register Centos 7 Machine using FreeIPA Client version 4.6.8 to FreeIPA server Machine on Centos 8 using 4.9.8 version?

2022-03-28 Thread GAURAV Pande via FreeIPA-users
Hi Alexander , Thanks for the suggestion could you let me know what OS type has formal support ? bBy Centos 8 i meant here Centos 8 stream ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Can i register Centos 7 Machine using FreeIPA Client version 4.6.8 to FreeIPA server Machine on Centos 8 using 4.9.8 version?

2022-03-28 Thread GAURAV Pande via FreeIPA-users
Hi Guys , Appreciate any help on this thread . Thanks ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Can i register Centos 7 Machine using FreeIPA Client version 4.6.8 to FreeIPA server Machine on Centos 8 using 4.9.8 version?

2022-03-27 Thread GAURAV Pande via FreeIPA-users
Hi Team , Had a general query related to FreeIPA :- Can i register Centos 7 Machine using FreeIPA Client version 4.6.8 to FreeIPA server Machine on Centos 8 using 4.9.8 version? Thanks ___ FreeIPA-users mailing list --

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-27 Thread GAURAV Pande via FreeIPA-users
Thanks Flo & Rob on helping here. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: Could find /var/lib/ipa/certs & /var/lib/ipa/private directories on FreeIPA Server.

2022-03-27 Thread GAURAV Pande via FreeIPA-users
Okay thanks a lot Florence! ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: Could find /var/lib/ipa/certs & /var/lib/ipa/private directories on FreeIPA Server.

2022-03-25 Thread GAURAV Pande via FreeIPA-users
Hi Florence , Thanks again for detailed info , where can we see /var/lib/ipa/private content (i suppose it has private key) for FreeIPA 4.6.8 Version? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email

[Freeipa-users] Re: Could find /var/lib/ipa/certs & /var/lib/ipa/private directories on FreeIPA Server.

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Hi Guys , Could anyone let me know regardless of the github repo where can i find default certs (location) which FreeIPA uses ? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Okay Rob so i guess Centos 8 base should also work then , just checking ? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Hi Rob , Thanks for prompt reply but i see the repo using dnf command and installing certbot client as well under intial setup script so my query still remain's on what OS version can we run this repo regardless of the support? ___ FreeIPA-users

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Hi Florence , Rob FreeIPA Version is : 4.6.8 Apologies if i might sound stupid here but iam kinda confuse , could you let me know what exactly needs removal and how can i remove it or command via yum ? Also regarding statement : "freeipa-letsencrypt does not support RHEL 7-based systems"

[Freeipa-users] Could find /var/lib/ipa/certs & /var/lib/ipa/private directories on FreeIPA Server.

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Hi Team . FreeIPA Version : 4.6.8 I was going through the freeipa team provided letsencrypt repo (https://github.com/freeipa/freeipa-letsencrypt) where they are saying to take backup of certs and private directories and they are even used in one of the scripts renew-le.sh but in my freeIPA

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Also here is the output of command asked : [gp185132@idm ~]$ sudo httpd -t -D DUMP_VHOSTS VirtualHost configuration: *:443 is a NameVirtualHost default server idm.ncrcanary.apibox.ml (/etc/httpd/conf.d/nss.conf:81) port 443 namevhost idm.ncrcanary.apibox.ml

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-24 Thread GAURAV Pande via FreeIPA-users
Hi , Thanks for further suggestion regarding seeing apache logs i see two types of logs under /var/log/httpd 1. ssl_error_log which seems to give ID related error in certificate : [gp185132@idm log]$ sudo cat httpd/ssl_error_log [Wed

[Freeipa-users] Re: httpd service failed when Configuring Let's Encrypt Certificate

2022-03-23 Thread GAURAV Pande via FreeIPA-users
Hi , Thanks for reply on Journal its saying below error , but there is no pre-exisitng process running on port 80/443 :- [gp185132@idm ~]$ sudo netstat -tulnp | grep -w 80 [gp185132@idm ~]$ [gp185132@idm ~]$ sudo netstat -tulnp | grep -w 443

[Freeipa-users] httpd service failed when Configuring Let's Encrypt Certificate

2022-03-23 Thread GAURAV Pande via FreeIPA-users
Hi Team , FreeIPA server version :- 4.6.8 I was trying securing freeipa-server with-lets-encrypt-ssl-certificate and in between the process i noticed that http suddenly failed , Iam listing down the steps that i followed so far (not complete as httpd got dead in between ) . Iam fairly new to

[Freeipa-users] Does FreeIPA(Server/Client) need Firewalld and SElinux Service on a Centos 7 VM enabled ?

2022-03-04 Thread GAURAV Pande via FreeIPA-users
Hi Team , New in this space , could you please let us know if Firewalld and SELinux service should be enabled as a Pre-requisite for installation of FreeIPA server/Client ? looking forward for your response . Thanks. ___ FreeIPA-users mailing list --

[Freeipa-users] Re: FreeIPA httpd service stopped suddenly and not restarting !

2022-03-04 Thread GAURAV Pande via FreeIPA-users
The version for FreeIPA we are using is below on a Centos 7 $ ipa --version VERSION: 4.6.8, API_VERSION: 2.237 ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] FreeIPA httpd service stopped suddenly and not restarting !

2022-03-03 Thread GAURAV Pande via FreeIPA-users
Hi Team , We had a strange issue where our FreeIPA GUI was down when checked from backend server the httpd service is not starting and we are not able to figure it out based on errors from var/log/httpd what can be the issue , helpful if anyone can help here . Thanks $ sudo ipactl restart

[Freeipa-users] Re: How to disable password Change on FreeIPA client for user who login First time .

2022-03-03 Thread GAURAV Pande via FreeIPA-users
Hi , Thanks for prompt response the link is not opening (404 error) could you share the issue details here ? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] How to disable password Change on FreeIPA client for user who login First time .

2022-03-02 Thread GAURAV Pande via FreeIPA-users
Hi Team , I have a FreeIPA client registered successfully on FreeIPA server under Host section , but when a user try to login first time he is always asked to change is password , it seems a default behavior ? If yes could you let me know how can we change this or what configuration are

[Freeipa-users] Re: Ports Connectivity required between FreeIPA client and FreeIPA Server for Adding FreeIPA client host to FreeIPA server GUI.

2022-03-02 Thread GAURAV Pande via FreeIPA-users
Thanks Rob for prompt reply , but could you point out the exact url for this reference ? Apologies as iam not able to track it from above shared one. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email

[Freeipa-users] Ports Connectivity required between FreeIPA client and FreeIPA Server for Adding FreeIPA client host to FreeIPA server GUI.

2022-03-02 Thread GAURAV Pande via FreeIPA-users
Hi Guys , I am new to FreeIPA could you let me know what ports connectivity will be needed between FreeIPA Client & FreeIPA servers located on different networks and having same domain in order to register the Client Host successfully on FreeIPA server ? Hoping to hear back on this . Thanks

[Freeipa-users] FreeIPA logs retention Period

2021-12-16 Thread GAURAV Pande via FreeIPA-users
Hi Team , Could you please help me understand or tell what is the log retention period for FreeIPA ? Couldnt get a clean/clear answer to this anywhere .How can we find out this information . Thanks ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Is FreeIPA affected by log4shell?

2021-12-13 Thread GAURAV Pande via FreeIPA-users
below rpm is installed as a dependency for free IPA server install version 4.6.8 on Oracle Linux 7 . log4j-1.2.17-16.el7_4.noarch.rpm can this be confirmed that it doesnt have any impact on the same ? ___ FreeIPA-users mailing list --

[Freeipa-users] Re: CVE-2021-44228 log4j2 Vulnerbility | FreeIPA version 4.6.8

2021-12-12 Thread GAURAV Pande via FreeIPA-users
Below are the log4J jar i can see on my server where freeIPA 4.6.8 is being installed. Are these related to freeIPA ? sudo find / -xdev -type f -name '*log4j*.jar' /usr/share/java/log4j.jar /usr/share/java/slf4j/log4j-over-slf4j.jar /usr/share/java/slf4j/slf4j-log4j12.jar

[Freeipa-users] CVE-2021-44228 log4j2 Vulnerbility | FreeIPA version 4.6.8

2021-12-12 Thread GAURAV Pande via FreeIPA-users
Hi Team , Could you please let me know if FreeIPA version 4.6.8 is being impacted with CVE-2021-44228 log4j2 Vulnerability ? and if Yes , what changes can be applied to remediate it ? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org