[Freeipa-users] Re: certmonger error on ubuntu

2019-11-18 Thread Bjarne Blichfeldt via FreeIPA-users
ah yes, certificates and renewal, I have spend so much time with that! A very good starting point for debugging is this excellent guide. https://floblanc.wordpress.com/2016/12/19/troubleshooting-certmonger-issues-with-freeipa/ Regards Bjarne Blichfeldt. From: Robson Francisco de Souza

[Freeipa-users] Re: certmonger error on ubuntu

2019-11-18 Thread Timo Aaltonen via FreeIPA-users
On 18.11.2019 4.03, Robson Francisco de Souza via FreeIPA-users wrote: > Hello! > > I've been running FreeIPA 4.3.1 on Ubuntu 16.04 for almost two years and > most certificates should expire within three weeks. As this deadline > approaches, I noticed certmonger has been unable to renew

[Freeipa-users] Re: IPA-automounted user home and git

2019-11-18 Thread François Cami via FreeIPA-users
Hi, On Mon, Nov 18, 2019 at 2:30 PM Ronald Wimmer via FreeIPA-users wrote: > > Today I've encountered a strange problem on a Centos 7.7 machine with > IPA automounted user homes. > > When I try to do a git clone in my home directory using SSH I it aborts > abnormally with the following error

[Freeipa-users] IPA-automounted user home and git

2019-11-18 Thread Ronald Wimmer via FreeIPA-users
Today I've encountered a strange problem on a Centos 7.7 machine with IPA automounted user homes. When I try to do a git clone in my home directory using SSH I it aborts abnormally with the following error message: remote: Enumerating objects: 4045, done. remote: Counting objects: 100%

[Freeipa-users] Re: one-way AD trust with shared secret - does it really work in 4.6.5 version?

2019-11-18 Thread lejeczek via FreeIPA-users
On 17/11/2019 17:00, Alexander Bokovoy wrote: > On su, 17 marras 2019, lejeczek via FreeIPA-users wrote: >> On 14/11/2019 11:44, Alexander Bokovoy wrote: >>> On to, 14 marras 2019, lejeczek via FreeIPA-users wrote: hi guys I've have AD trust work fine (gssapi), ssh & samba are

[Freeipa-users] Re: ipa-replica-install latest failure attempt:

2019-11-18 Thread Rob Crittenden via FreeIPA-users
Auerbach, Steven via FreeIPA-users wrote: > Executed ipa-replica-prepare on an RHEL 6.9 server running ipa-server > 3.0.0.1_51  (name : ipa01) > > Yum installed ipa-server, ipa-server-dns, bind-dyndb-ldap on the target > Linux 7.6 server (name: ipa04) > > Copied the file to the target server to

[Freeipa-users] SOC documentation

2019-11-18 Thread Shumel Rahman via FreeIPA-users
Hi I would like to know if you have any T's and other such documentation that would satisfy a SOC Audit? I understand that FreeIPA is Open Source but perhaps there some relevant documentation on this topic. FreeIPA is used by our organisation for access to a key application and as such falls into

[Freeipa-users] Re: SOC documentation

2019-11-18 Thread Angus Clarke via FreeIPA-users
Not directly answering your question but sharing some knowledge ... Similarly our IPA system falls under certain audit conditions, specifically with regard to user addition/deletion and what goup memberships have been ammended over some period of time (we base our sudo rules on group

[Freeipa-users] Password sync from AD sets passwords to expired

2019-11-18 Thread Eugene V via FreeIPA-users
FreeIPA 4.6.5 Windows 2019 Domain Controller We have 389 Directory Password Synchronization set up according to manual here: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/windows_integration_guide/pass-sync#windows-pass-sync When user changes their password in

[Freeipa-users] ipa-replica-install latest failure attempt:

2019-11-18 Thread Auerbach, Steven via FreeIPA-users
Executed ipa-replica-prepare on an RHEL 6.9 server running ipa-server 3.0.0.1_51 (name : ipa01) Yum installed ipa-server, ipa-server-dns, bind-dyndb-ldap on the target Linux 7.6 server (name: ipa04) Copied the file to the target server to which ipa-server 4.6.5-11.0.1 is installed (ipa04)

[Freeipa-users] Re: Password sync from AD sets passwords to expired

2019-11-18 Thread Rob Crittenden via FreeIPA-users
Eugene V via FreeIPA-users wrote: > FreeIPA 4.6.5 > > Windows 2019 Domain Controller > > We have 389 Directory Password Synchronization set up according to manual > here: > >

[Freeipa-users] ipa-ca-agent cert

2019-11-18 Thread N N via FreeIPA-users
Hello! I have ipa 4.6.4-10, and my certmonger do not update ipa-ca-agent cert. Subject DN: CN=ipa-ca-agent, O= How I can update it? I have few week before my certificate expire. I can't find documentation about it. ___ FreeIPA-users mailing list --