[Freeipa-users] Re: Documentation on Upgrade FreeIPA to use TLS

2023-09-25 Thread Marcelo Carvalho via FreeIPA-users
Hi Tomasz. This was one question to myself I made and on my understanding TLS has been use, but I need confirmation. Please, how can we confirm that TLS is been used? Can you please advise? Many thanks Marcelo ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Documentation on Upgrade FreeIPA to use TLS

2023-09-25 Thread Marcelo Carvalho via FreeIPA-users
I have downloaded and used cipherscan ./cipherscan.txt 127.0.0.1 I belie this does it. Correct? Please advise. Many thanks Marcelo ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Documentation on Upgrade FreeIPA to use TLS

2023-09-25 Thread Rob Crittenden via FreeIPA-users
Marcelo Carvalho via FreeIPA-users wrote: > I have downloaded and used cipherscan > > ./cipherscan.txt 127.0.0.1 > > I belie this does it. Correct? You don't need to scan all the available ciphers unless you want to do that as well. If you just want to verify that the IPA servers have TLS

[Freeipa-users] Documentation on Upgrade FreeIPA to use TLS

2023-09-25 Thread Marcelo Carvalho via FreeIPA-users
Hi everybody. I am back in charge of some freeipa servers and would like to check for best documentation on upgrading FreeIPA to use TLS. I have found:

[Freeipa-users] Re: FreeIPA Trust with Microsoft Active Directory Domain Controllers.

2023-09-25 Thread Marcelo Carvalho via FreeIPA-users
Thank you so much Alexander. I will dive into that. Many thanks Marcelo. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: Documentation on Upgrade FreeIPA to use TLS

2023-09-25 Thread Tomasz Torcz via FreeIPA-users
On Mon, Sep 25, 2023 at 04:05:33PM -, Marcelo Carvalho via FreeIPA-users wrote: > Hi everybody. > > I am back in charge of some freeipa servers and would like to check for best > documentation on upgrading FreeIPA to use TLS. Why dou you think FreeIPA isn't using TLS? How do you check?

[Freeipa-users] Re: Plans for integrating DHCP

2023-09-25 Thread Ellsworth, Nathan Andrew via FreeIPA-users
There is an interesting design document already for DHCP with FreeIPA. https://www.freeipa.org/page/DHCP_Integration_Design ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Plans for integrating DHCP

2023-09-25 Thread Charles Hedrick via FreeIPA-users
We did most of this, and have been using it for a few years. However it depends upon the ISC DHCP server, which is now EOL. The replacement, KEA, does not support LDAP, and there are no plans for it to. I think the reason is that they didn't want to put dynamic addresses in LDAP, because LDAP

[Freeipa-users] Re: Get running FreeIPA in Docker in Docker

2023-09-25 Thread Jan Pazdziora via FreeIPA-users
On Fri, Sep 22, 2023 at 12:03:19PM -, Jay Smith via FreeIPA-users wrote: > Thank you very much for your hint Ulf. That's working for me. > > docker run -it \ > -h ${MK_FREEIPA_SERVER_DOMAIN_NAME} \ > --name ipa \ > --sysctl net.ipv6.conf.all.disable_ipv6=0 \ > -v

[Freeipa-users] Re: How to I get FreeIPA running in Docker Swarm?

2023-09-25 Thread Jan Pazdziora via FreeIPA-users
On Fri, Sep 22, 2023 at 12:10:50PM -, Jay Smith via FreeIPA-users wrote: > I have the following Setup. > > MK_INTERNAL_SUB_DOMAIN=example.test > MK_FREEIPA_SERVER_REALM=EXAMPLE.TEST > MK_FREEIPA_SERVER_DS_PASSWORD=password > MK_FREEIPA_SERVER_ADMIN_PASSWORD=password >

[Freeipa-users] Re: Recovering from certificate exparation issues

2023-09-25 Thread Rob Crittenden via FreeIPA-users
Cristian Le via FreeIPA-users wrote: > Ok, let me walk through some of the specific errors, and I will also > censor out some of the output since this is going to the public > mail-list as well. > > Starting from the beginning. > - I have set the date to `1 month` before certificate expired with

[Freeipa-users] automount keys on multiple domains

2023-09-25 Thread Nathanaël Blanchet via FreeIPA-users
Hello, I have a trusted AD domain levant.abes.fr I'm trying to get my to auto.home map get working with automount keys. Everything is ok with the wildcard on the trusted domain * vm701-dev.couchant.abes.fr:/export/home/levant.abes.fr/& In addition to this, is there a way to do the same with the

[Freeipa-users] Re: Another Cert Expiration Problem

2023-09-25 Thread Rob Crittenden via FreeIPA-users
Russ Long via FreeIPA-users wrote: > Any other advice here? I have also tried setting system back to when > certificates were valid, restarting certmonger and pki-tomcatd, and running > getcert resubmit on the affected certs, this moves them to a "Monitoring" > status, but they still never

[Freeipa-users] Re: Another Cert Expiration Problem

2023-09-25 Thread Russ Long via FreeIPA-users
Rob, Thanks so much, running that command, and then the `ipa-cert-fix` with the server in current time appears to have fixed the issue. I did manually run a `getcert resubmit -i ID_HERE` for a couple certs that were still showing CA_UNREACHABLE in `getcert list`, but not sure if that was

[Freeipa-users] Keytab issues after upgrade to Fedora 38

2023-09-25 Thread Djerk Geurts via FreeIPA-users
Today was my second attempt to lift FreeIPA servers to Fedora 38 from 37. Again it failed. Sync and healthchecks were fine, but an (admin) user can't log into the WebUI and can't do sudo. Login works because I do key based authentication. Kinit admin works, but kinit alone doesn't. I have a

[Freeipa-users] Re: Managing FreeIPA installations without Trusts between them

2023-09-25 Thread dweller dweller via FreeIPA-users
Alexander, thank you for explanation. Maybe you can consult on where can a newbee that want to contribute implementing Global Catalog within FreeIPA in order to support IPA-IPA trust relationtship should start? Are those open issues are the main factor that held implementation of that feature?

[Freeipa-users] FreeIPA Trust with Microsoft Active Directory Domain Controllers.

2023-09-25 Thread Marcelo Carvalho via FreeIPA-users
I need to create a trust between a MS Domain Controller and my FreeIPA. Documentation I found is https://www.freeipa.org/page/Active_Directory_trust_setup Can anybody confirm that the above is the most recommended documentation related to FreeIPA Trust with Microsoft Active Directory Domain

[Freeipa-users] Re: Managing FreeIPA installations without Trusts between them

2023-09-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 вер 2023, dweller dweller via FreeIPA-users wrote: Alexander, thank you for explanation. Maybe you can consult on where can a newbee that want to contribute implementing Global Catalog within FreeIPA in order to support IPA-IPA trust relationtship should start? Are those open issues

[Freeipa-users] Re: FreeIPA Trust with Microsoft Active Directory Domain Controllers.

2023-09-25 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 25 вер 2023, Marcelo Carvalho via FreeIPA-users wrote: I need to create a trust between a MS Domain Controller and my FreeIPA. Documentation I found is https://www.freeipa.org/page/Active_Directory_trust_setup Can anybody confirm that the above is the most recommended documentation

[Freeipa-users] Re: Migration of DNS Zones and it's records from one FreeIPA server to other

2023-09-25 Thread Rafael Jeffman via FreeIPA-users
Hello, On Mon, Sep 25, 2023 at 2:41 AM Srikanth C via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > > Hi, > > I am looking for the process to migrate the DNS Zones and it's records from one FreeIPA to other FreeIPA server. I have gone through the documentation but didn't find any