[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Bart via FreeIPA-users
Thank you Jakub for your hints. I created a brand new instance of FreeIPA client and connected it to the existing servers. Now I cannot resolve anytthing on a client (getent group $group, getent passwd $user yield no results). For the same exact users/groups I tested on the client, they get

[Freeipa-users] Re: Announcing SSSD 1.16.1

2018-06-07 Thread AvigdorFin via FreeIPA-users
How do I report a suspected Bug against sssd? I have a problem with sssd 1.14 1.15 1.16 but not 1.13. The problem is with small tree of files that is created on /tmp/adcli-krb5-X every 5 minutes. The problem might be connected to adcli 0.8.1 and not 0.7.5 Thanks in advance, Avigdor

[Freeipa-users] Re: Announcing SSSD 1.16.1

2018-06-07 Thread Rob Crittenden via FreeIPA-users
AvigdorFin via FreeIPA-users wrote: > How do I report a suspected Bug against sssd? > I have a problem with sssd 1.14 1.15 1.16 but not 1.13. > > The problem is with small tree of files that is created on > /tmp/adcli-krb5-X  every 5 minutes. > The problem might be connected to adcli 0.8.1

[Freeipa-users] Re: Announcing SSSD 1.16.1

2018-06-07 Thread Sumit Bose via FreeIPA-users
On Thu, Jun 07, 2018 at 04:39:09PM +0300, AvigdorFin via FreeIPA-users wrote: > How do I report a suspected Bug against sssd? > I have a problem with sssd 1.14 1.15 1.16 but not 1.13. > > The problem is with small tree of files that is created on > /tmp/adcli-krb5-X every 5 minutes. > The

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Bart via FreeIPA-users
Thank you Alexander, that was the root cause. I added optimizations to my setup that you together with Jakub described in this article: https://jhrozek.wordpress.com/2015/08/19/performance-tuning-sssd-for-large-ipa-ad-trust-deployments/ and things started working on the client side. There is a

[Freeipa-users] Re: Announcing SSSD 1.16.1

2018-06-07 Thread AvigdorFin via FreeIPA-users
Yes, I tried this option in sssd.conf, it didn't help. Please see Bug 1588596 that I opened with more information. Thanks, On Thu, Jun 7, 2018 at 5:50 PM Sumit Bose via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > On Thu, Jun 07, 2018 at 04:39:09PM +0300, AvigdorFin via

[Freeipa-users] Re: keycloak

2018-06-07 Thread Rob Crittenden via FreeIPA-users
Andrew Meyer via FreeIPA-users wrote: > what is the difference between keycloak and freeipa? They are apples and oranges. IPA is an Identity Management system and keycloak is an IdP (for SAML2, OAuth, etc). > Is there a free version of this?  Is that what ipsilon is?  If not is > there a repo

[Freeipa-users] Re: Cannot log in as an AD user to FreeIPA client but can log in to server

2018-06-07 Thread Jakub Hrozek via FreeIPA-users
On Thu, Jun 07, 2018 at 03:48:16PM -, Bart via FreeIPA-users wrote: > Thank you Alexander, that was the root cause. I added optimizations to my > setup that you together with Jakub described in this article: >

[Freeipa-users] double domain?

2018-06-07 Thread Kat via FreeIPA-users
hi Where would be a good place to look in either sssd or somewhere in the system if we are seeing a mixture of UserID lookups in this format: usern...@domain.example.com  <--- this makes sense BUT - also seeing: usern...@domain.example.com@domain.eexample.com  <--- This does not?? I am

[Freeipa-users] keycloak

2018-06-07 Thread Andrew Meyer via FreeIPA-users
what is the difference between keycloak and freeipa? Is there a free version of this?  Is that what ipsilon is?  If not is there a repo for this?___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: double domain?

2018-06-07 Thread Jakub Hrozek via FreeIPA-users
On Thu, Jun 07, 2018 at 12:33:56PM -0500, Kat via FreeIPA-users wrote: > hi > > Where would be a good place to look in either sssd or somewhere in the > system if we are seeing a mixture of UserID lookups in this format: > > usern...@domain.example.com  <--- this makes sense > > BUT - also

[Freeipa-users] Setting up fileserver using Samba shares and FreeIPA

2018-06-07 Thread Kristian Petersen via FreeIPA-users
I am trying to get a file server set up using RHEL 7.5, Samba, and Red Hat IdM 4.5.0 I have an older file server that works and hav been using it as a template for build this new one from scratch. However, right now I can't get smb to start. I keep getting errors about ipasam.c in journalctl:

[Freeipa-users] Re: keycloak

2018-06-07 Thread John Dennis via FreeIPA-users
On 06/07/2018 02:22 PM, Andrew Meyer via FreeIPA-users wrote: what is the difference between keycloak and freeipa? Is there a free version of this?  Is that what ipsilon is?  If not is there a repo for this? All 3 are IdP's (Identity Providers) of some ilk. FreeIPA is based on Kerberos and

[Freeipa-users] Re: keycloak

2018-06-07 Thread Jochen Hein via FreeIPA-users
Rob Crittenden via FreeIPA-users writes: > I don't know where Keycloak upstream is. Look at http://www.keycloak.org Jochen -- This space is intentionally left blank. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To

[Freeipa-users] Re: keycloak

2018-06-07 Thread Andrew Meyer via FreeIPA-users
Thanks for the clarification! On Thursday, June 7, 2018 2:32 PM, Jochen Hein via FreeIPA-users wrote: Rob Crittenden via FreeIPA-users writes: > I don't know where Keycloak upstream is. Look at http://www.keycloak.org Jochen -- This space is intentionally left blank.

[Freeipa-users] Re: Setting up fileserver using Samba shares and FreeIPA

2018-06-07 Thread Alexander Bokovoy via FreeIPA-users
On to, 07 kesä 2018, Kristian Petersen via FreeIPA-users wrote: I am trying to get a file server set up using RHEL 7.5, Samba, and Red Hat IdM 4.5.0 I have an older file server that works and hav been using it as a template for build this new one from scratch. However, right now I can't get

[Freeipa-users] DNS A Record Disappears after IPA Server reboot

2018-06-07 Thread Mariusz Stolarczyk via FreeIPA-users
Hi all, Whenever I have to reboot my IPA server I loose one of my IPA client's DNS A Record. Curiously all of the IPA client related SSHFP records are intact as well as the reverse lookup record. The only thing that was slightly different about this client is at some point the IP address was

[Freeipa-users] Re: Setting up fileserver using Samba shares and FreeIPA

2018-06-07 Thread Kristian Petersen via FreeIPA-users
I would have sworn my keytab was OK, but it wasn't and after re-doing that, it all came up like magic. I feel kinda dumb, but thanks for the pointers, Alexander. On Thu, Jun 7, 2018 at 3:47 PM, Alexander Bokovoy wrote: > On to, 07 kesä 2018, Kristian Petersen via FreeIPA-users wrote: > >> I am