[Freeipa-users] Re: Samba 4.10.16-17.el7_9 and IPA 4.6.8-5.el7.centos.10 updates broke SMB Kerberos authentication

2022-01-01 Thread Konstantin M. Khankin via FreeIPA-users
lso, current FreeIPA > versions do not support login to Windows systems in a trusted Active > Directory forest. The latter is being worked on. > > > > >Happy New Year! :) > > > > > >чт, 30 дек. 2021 г. в 20:03, Alexander Bokovoy : > > > >> On to, 30 joulu 2021,

[Freeipa-users] Re: Samba 4.10.16-17.el7_9 and IPA 4.6.8-5.el7.centos.10 updates broke SMB Kerberos authentication

2021-12-31 Thread Konstantin M. Khankin via FreeIPA-users
CentOS 7? Happy New Year! :) чт, 30 дек. 2021 г. в 20:03, Alexander Bokovoy : > On to, 30 joulu 2021, Konstantin M. Khankin via FreeIPA-users wrote: > >Hello! > > > >I have several SMB shares served by Samba using Kerberos accounts managed > >by FreeIPA. I have no AD in

[Freeipa-users] Re: Samba 4.10.16-17.el7_9 and IPA 4.6.8-5.el7.centos.10 updates broke SMB Kerberos authentication

2021-12-30 Thread Konstantin M. Khankin via FreeIPA-users
Wanted to verify if my users have PAC and seems like they don't: # net ads kerberos pac dump --option='realm = MYDOMAIN.LOC' --option='kerberos method = system keytab' -s /dev/null local_service=host/client.mydomain@mydomain.loc -U me Enter me's password: ../../source3/libads/authdata.c:300:

[Freeipa-users] Samba 4.10.16-17.el7_9 and IPA 4.6.8-5.el7.centos.10 updates broke SMB Kerberos authentication

2021-12-30 Thread Konstantin M. Khankin via FreeIPA-users
Hello! I have several SMB shares served by Samba using Kerberos accounts managed by FreeIPA. I have no AD integrations and no AD itself. Windows clients are configured using this guide, linux clients use ipa-client and

[Freeipa-users] Re: Can't reinstate replica from scratch after it was off for 6 months

2020-09-14 Thread Konstantin M. Khankin via FreeIPA-users
Thank you, that worked. I'm now having issues passing the pki-tomcatd installation but that's another issue. пт, 21 авг. 2020 г. в 11:17, Florence Blanc-Renaud : > On 8/19/20 9:52 PM, Konstantin M. Khankin via FreeIPA-users wrote: > > TL;DR: Unfortunately this doesn't help. I see this o

[Freeipa-users] Re: Can't reinstate replica from scratch after it was off for 6 months

2020-08-20 Thread Konstantin M. Khankin via FreeIPA-users
complete. The ipa-client-install command was successful And after that ipa-replica-install fails as before. вт, 18 авг. 2020 г. в 23:56, Rob Crittenden : > Konstantin M. Khankin via FreeIPA-users wrote: > > Hi! > > > > Bumping this thread. Anyone has any ideas? > >

[Freeipa-users] Re: Can't reinstate replica from scratch after it was off for 6 months

2020-08-18 Thread Konstantin M. Khankin via FreeIPA-users
Hi! Bumping this thread. Anyone has any ideas? Thanks! вс, 9 авг. 2020 г., 08:23 Konstantin M. Khankin < khankin.konstan...@gmail.com>: > Hi! > > I run IPA on CentOS 7. I have two servers (Leader and Replica, though they > changed roles couple times because of reinstalls), had ca and domain >

[Freeipa-users] Can't reinstate replica from scratch after it was off for 6 months

2020-08-08 Thread Konstantin M. Khankin via FreeIPA-users
Hi! I run IPA on CentOS 7. I have two servers (Leader and Replica, though they changed roles couple times because of reinstalls), had ca and domain services on both of them, replication set up and working. I had to switch off Replica for 6 months. When I turned it on recently, I found expired