[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-22 Thread Duncan Colhoun via FreeIPA-users
Thanks - very helpful ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-22 Thread Duncan Colhoun via FreeIPA-users
Thanks ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-18 Thread Charles Hedrick via FreeIPA-users
The basic technology is solid and the admin tools reasonable. However it has the same problems as all large, integrated systems: if the system isn’t in exactly the state they expect, significant administrative operations such as upgrading version or adding a replica will fail. Those things are

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-08 Thread Jochen Hein via FreeIPA-users
Hi, Duncan Colhoun via FreeIPA-users writes: > Can I get some feedback on the overall experience setting up and > running Free-IPA. I am looking at implementing Free-IPA to > enhance/replace an OpenLDAP environment. I'm running a small FreeIPA (2 servers)

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-08 Thread Duncan Colhoun via FreeIPA-users
Hi Angus Thanks for the feedback ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-08 Thread Angus Clarke via FreeIPA-users
Main gripe (which doesn't have any plans for resolution) - no facility for read-only replicas in untrusted sites. On 8 May 2018 at 12:04, Angus Clarke wrote: > Hi Duncan > > A few things I've learned: > > Understand how replication agreements work as part of your

[Freeipa-users] Re: Overall users experience with Free-IPA

2018-05-08 Thread Angus Clarke via FreeIPA-users
Hi Duncan A few things I've learned: Understand how replication agreements work as part of your planning. Choose a suitable location for the live CA server. Deploy a replica by promoting an sssd client. Unless you have a reason not to, always use --setup-ca to the ipa-replica-install command