[Freeipa-users] Re: IPA Replica can't authenticate users

2024-04-19 Thread John Doe via FreeIPA-users
10:10 AM John Doe wrote: > >> >> >> Den mån 15 apr. 2024 kl 09:35 skrev Florence Blanc-Renaud > >: >> >>> Hi, >>> >>> On Mon, Apr 15, 2024 at 9:03 AM John Doe via FreeIPA-users < >>> freeipa-users@lists.fedorahosted.org&g

[Freeipa-users] Re: IPA Replica can't authenticate users

2024-04-15 Thread John Doe via FreeIPA-users
Den mån 15 apr. 2024 kl 09:35 skrev Florence Blanc-Renaud : > Hi, > > On Mon, Apr 15, 2024 at 9:03 AM John Doe via FreeIPA-users < > freeipa-users@lists.fedorahosted.org> wrote: > >> I'm playing around with IPA trying to figure out how to set it up to be >> redun

[Freeipa-users] IPA Replica can't authenticate users

2024-04-15 Thread John Doe via FreeIPA-users
I'm playing around with IPA trying to figure out how to set it up to be redundant. The problem is that the IPA Replica isn't able to authenticate AD users if IPA Master is down. My setup; One Windows Server set up with Active Direcory Domain Services, Active Directory Certificate Services and DNS

[Freeipa-users] Re: HowTo renew IPA certificate when IPA is acting as a Sub CA to MS Windows Certificate Authority Services

2023-09-20 Thread John Doe via FreeIPA-users
Thaks a million Rob. Your comments are highly appreciated. Please see my answers below. Den tis 19 sep. 2023 kl 20:52 skrev Rob Crittenden : > John Doe via FreeIPA-users wrote: > > Thank you so much for your support. Your comments set me on the right > > track. Namely that the

[Freeipa-users] Re: HowTo renew IPA certificate when IPA is acting as a Sub CA to MS Windows Certificate Authority Services

2023-09-19 Thread John Doe via FreeIPA-users
> On Няд, 03 вер 2023, John Doe via FreeIPA-users wrote: > >I'm currently trying to evaluate if we may use IPA server to help manage > our park of Linux Clients > >When installing the IPA server I used the following commands; > >sudo ipa-server-install --external-ca --

[Freeipa-users] HowTo renew IPA certificate when IPA is acting as a Sub CA to MS Windows Certificate Authority Services

2023-09-03 Thread John Doe via FreeIPA-users
I'm currently trying to evaluate if we may use IPA server to help manage our park of Linux Clients When installing the IPA server I used the following commands; sudo ipa-server-install --external-ca --external-ca-type=ms-cs sudo ipa-server-install --external-cert-file=/home/$USER/ipa.cer

[Freeipa-users] Re: freeipa-client-install stopping on libcurl error

2020-08-29 Thread john doe via FreeIPA-users
good - reading more around the error log section you specified a principal problem in this testbed emerges: it tries to run '/usr/bin/nsupdate -g /etc/ipa/.dns_update.txt' > Could not update DNS SSHFP records. the zone is not delegated hence it couldn't update it. Is there a way to run

[Freeipa-users] freeipa-client-install stopping on libcurl error

2020-08-29 Thread john doe via FreeIPA-users
can't pass the expection below on freeipa-client-install: > libcurl failed to execute the HTTP POST transaction, explaining: Problem > with the SSL CA cert (path? access rights?) Not sure if this is causative to the message, curling - the cacert manually works without a hitch. FreeIPA