Long story short, we had to redeploy part of our FreeIPA cluster. As far as
I know I followed all of the proper procedures and everything seems to be
working from the client side however we are getting a TON of these messages
in krb5kdc.log
ipa3.example.com krb5kdc[31232](info): TGS_REQ (8 etypes
Hi Ernedyn and Harry,
Does this mean that FreeIPA doesn't have this functionality?
Aker I understand is a different piece of software not related with FreeIPA? My
version is 4.6.8.
About those bugs mentioned, is this referring to the Aker implementation with
FreeIPA?
Thank you for your help.
Hi Ian,
with IPA 4.6.8 you just need to follow the 389ds doc.
The procedure was more complex in version < 3.2.2 because there were two
389ds instances (one for the regular suffix and one for the Certificate
Server) and the password has to be manually synchronized between the 2, and
the replica
Florence Renaud via FreeIPA-users wrote:
> Hi Ian,
> with IPA 4.6.8 you just need to follow the 389ds doc.
> The procedure was more complex in version < 3.2.2 because there were two
> 389ds instances (one for the regular suffix and one for the Certificate
> Server) and the password has to be