[Freeipa-users] Kerberos Issues

2021-05-20 Thread Mark Potter via FreeIPA-users
Long story short, we had to redeploy part of our FreeIPA cluster. As far as I know I followed all of the proper procedures and everything seems to be working from the client side however we are getting a TON of these messages in krb5kdc.log ipa3.example.com krb5kdc[31232](info): TGS_REQ (8 etypes

[Freeipa-users] Re: FreeIPA Bastion

2021-05-20 Thread G Col via FreeIPA-users
Hi Ernedyn and Harry, Does this mean that FreeIPA doesn't have this functionality? Aker I understand is a different piece of software not related with FreeIPA? My version is 4.6.8. About those bugs mentioned, is this referring to the Aker implementation with FreeIPA? Thank you for your help.

[Freeipa-users] Re: Changing directory manager password

2021-05-20 Thread Florence Renaud via FreeIPA-users
Hi Ian, with IPA 4.6.8 you just need to follow the 389ds doc. The procedure was more complex in version < 3.2.2 because there were two 389ds instances (one for the regular suffix and one for the Certificate Server) and the password has to be manually synchronized between the 2, and the replica

[Freeipa-users] Re: Changing directory manager password

2021-05-20 Thread Rob Crittenden via FreeIPA-users
Florence Renaud via FreeIPA-users wrote: > Hi Ian, > with IPA 4.6.8 you just need to follow the 389ds doc. > The procedure was more complex in version < 3.2.2 because there were two > 389ds instances (one for the regular suffix and one for the Certificate > Server) and the password has to be