[Freeipa-users] Re: freeipa cluster. replication ok but "secondary" DNS not recognized as DNS role.

2017-06-13 Thread Martin Bašti via FreeIPA-users
On 13.06.2017 21:52, Tiran Efrat via FreeIPA-users wrote: Hi, I setup a while a go a freeIPA cluster and all records are replicated. The issue is that I found out the secondary DNS was probably configured as caching dns as it's not recognized as a DNS role on the web gui. How can i configure

[Freeipa-users] Re: DNS zone origin record search

2017-06-13 Thread John Morris via FreeIPA-users
On 06/12/2017 11:28 AM, Martin Bašti wrote: On 11.06.2017 01:20, John Morris via FreeIPA-users wrote: This works to find a single DNS record: $ ipa dnsrecord-find example.com --name=ipa-ca --pkey-only Record name: ipa-ca Number of entries retur

[Freeipa-users] freeipa cluster. replication ok but "secondary" DNS not recognized as DNS role.

2017-06-13 Thread Tiran Efrat via FreeIPA-users
Hi,I setup a while a go a freeIPA cluster and all records are replicated.The issue is that I found out the  secondary DNS was probably configured as caching dns as it's not recognized as a DNS role on the web gui.How can i configure it to be a replicate DNS role correctly (note that the original

[Freeipa-users] Re: replication problem

2017-06-13 Thread Eric Renfro via FreeIPA-users
In my particular case, I'm not using the client installation prior to the replica installation. Though I have tried that method as well, resulting in the very same issues regardless. I'm using this to do the installation currently: ipa-replica-install --unattended \ --no-ntp --mkhomedir --ski

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Alexander Bokovoy via FreeIPA-users
On ti, 13 kesä 2017, Rob Crittenden via FreeIPA-users wrote: Alexander Bokovoy wrote: On ti, 13 kesä 2017, Rob Crittenden wrote: Alexander Bokovoy via FreeIPA-users wrote: On ti, 13 kesä 2017, Chris Dagdigian via FreeIPA-users wrote: Hi folks, Fixing a topology and replication issue caused m

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Rob Crittenden via FreeIPA-users
Alexander Bokovoy wrote: > On ti, 13 kesä 2017, Rob Crittenden wrote: >> Alexander Bokovoy via FreeIPA-users wrote: >>> On ti, 13 kesä 2017, Chris Dagdigian via FreeIPA-users wrote: Hi folks, Fixing a topology and replication issue caused my IDM infrastructure to forget about ro

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Alexander Bokovoy via FreeIPA-users
On ti, 13 kesä 2017, Rob Crittenden wrote: Alexander Bokovoy via FreeIPA-users wrote: On ti, 13 kesä 2017, Chris Dagdigian via FreeIPA-users wrote: Hi folks, Fixing a topology and replication issue caused my IDM infrastructure to forget about roughly 30 enrolled client hosts. Though this woul

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Alexander Bokovoy via FreeIPA-users
On ti, 13 kesä 2017, Rob Crittenden via FreeIPA-users wrote: Chris Dagdigian via FreeIPA-users wrote: Hi folks, Fixing a topology and replication issue caused my IDM infrastructure to forget about roughly 30 enrolled client hosts. Though this would be trivial to fix via an ansible playbook tha

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Rob Crittenden via FreeIPA-users
Alexander Bokovoy via FreeIPA-users wrote: > On ti, 13 kesä 2017, Chris Dagdigian via FreeIPA-users wrote: >> Hi folks, >> >> Fixing a topology and replication issue caused my IDM infrastructure >> to forget about roughly 30 enrolled client hosts. >> >> Though this would be trivial to fix via an an

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Alexander Bokovoy via FreeIPA-users
On ti, 13 kesä 2017, Chris Dagdigian via FreeIPA-users wrote: Hi folks, Fixing a topology and replication issue caused my IDM infrastructure to forget about roughly 30 enrolled client hosts. Though this would be trivial to fix via an ansible playbook that runs the IPA client install command

[Freeipa-users] Re: ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Rob Crittenden via FreeIPA-users
Chris Dagdigian via FreeIPA-users wrote: > Hi folks, > > Fixing a topology and replication issue caused my IDM infrastructure to > forget about roughly 30 enrolled client hosts. > > Though this would be trivial to fix via an ansible playbook that runs > the IPA client install command again with t

[Freeipa-users] ipa 4.4.0-14 not honoring "ipa-client-install --force-join" command?

2017-06-13 Thread Chris Dagdigian via FreeIPA-users
Hi folks, Fixing a topology and replication issue caused my IDM infrastructure to forget about roughly 30 enrolled client hosts. Though this would be trivial to fix via an ansible playbook that runs the IPA client install command again with the "--force-join" argument. Manpage and docs sugg

[Freeipa-users] Re: replication problem

2017-06-13 Thread Rob Crittenden via FreeIPA-users
Eric Renfro via FreeIPA-users wrote: > Hmmm.. > > Well, in my case specifically, the failed ipa-replica-install does in > fact have the nsslapd-rootpw entry, however, changing this in a recovery > process does no good during an ipa-replica-install. I think this is a red herring. The client promot

[Freeipa-users] Re: replication problem

2017-06-13 Thread Eric Renfro via FreeIPA-users
Hmmm.. Well, in my case specifically, the failed ipa-replica-install does in fact have the nsslapd-rootpw entry, however, changing this in a recovery process does no good during an ipa-replica-install. Eric -Original Message- Date: Tue, 13 Jun 2017 10:51:13 -0400 Subject: [Freeipa-users

[Freeipa-users] Re: [Freeipa-users]FreeIPA and TACACS+

2017-06-13 Thread Andrew Meyer via FreeIPA-users
Another question, how hard would it be to separate the this setup?  FreeIPA on one server and TACACS+ from shrubbery on another? On Monday, June 12, 2017 3:34 PM, Andrew Meyer via FreeIPA-users wrote: Correct.  So I would skip the adding of the pam module and just create a new pam con

[Freeipa-users] Re: replication problem

2017-06-13 Thread Mark Reynolds via FreeIPA-users
On 06/13/2017 10:34 AM, Eric Renfro via FreeIPA-users wrote: > Huh.. Well, who'da thunk it. I just literally reported the same kind of > trouble I was having, which looks like it matches this same situation, > with the ipa-replica-install failing to initiate replication because of > Invalid passw

[Freeipa-users] Re: replication problem

2017-06-13 Thread Mark Reynolds via FreeIPA-users
On 06/13/2017 09:49 AM, Adrian HY wrote: > Hi Mark, my problem is during the replica installation. I can't use > ldapmodify because *cn=directory manager * does not have the password > assigned. Did you remove the password from the config? There is always a password set during the install. Anyw

[Freeipa-users] Re: replication problem

2017-06-13 Thread Ludwig Krispenz via FreeIPA-users
If the problem occurs during the new installation of DS, you need to get a modification of the IPA install script, setting this parameter befor setting up replication. Otherwise there is a hack to modify the configuration template: /usr/share/dirsrv/data/template-dse.ldif and add the nsslapd-m

[Freeipa-users] Re: replication problem

2017-06-13 Thread Eric Renfro via FreeIPA-users
Huh.. Well, who'da thunk it. I just literally reported the same kind of trouble I was having, which looks like it matches this same situation, with the ipa-replica-install failing to initiate replication because of Invalid password, because the password for some reason does not seem to be being set

[Freeipa-users] Re: replication problem

2017-06-13 Thread Adrian HY via FreeIPA-users
Hi Mark, my problem is during the replica installation. I can't use ldapmodify because *cn=directory manager * does not have the password assigned. Regards. On Mon, Jun 12, 2017 at 1:38 PM, Mark Reynolds wrote: > > > On 06/11/2017 01:49 PM, Adrian HY via FreeIPA-users wrote: > > I think I detec

[Freeipa-users] Re: Ansible and ipa-client-install

2017-06-13 Thread David Kupka via FreeIPA-users
On Mon, Jun 12, 2017 at 12:20:38PM +0200, Christian Heimes via FreeIPA-users wrote: > On 2017-06-12 10:50, Florence Blanc-Renaud via FreeIPA-users wrote: > > Hi, > > > > the team is starting investigations regarding the deployment of IPA > > using Ansible, and we would like to get community feedb

[Freeipa-users] Re: Replication failing on some records

2017-06-13 Thread Nick Campion via FreeIPA-users
On 12/06/17 18:29, Mark Reynolds wrote: > > > On 06/12/2017 07:32 AM, Nick Campion via FreeIPA-users wrote: >> >> Thanks Mark, >> >> So this example is a user password change using kinit, the password >> has been changed on freeipa02 but not then replicated to the others. >> This happens for othe

[Freeipa-users] FreeIPA Replica Install issue on CentOS 7.3 and ipa 4.4.0

2017-06-13 Thread Eric Renfro via FreeIPA-users
I've been trying to rebuild my FreeIPA server that I run on CentOS 7.3. Previously, I was running FreeIPA 4.2.x and upgraded over time to 4.4.0 now, but somewhere along the lines, it totally broke and failed. For me it's not a big deal because it serves very little in a home cluster lab, but I want

[Freeipa-users] Re: replication problem

2017-06-13 Thread Givaldo Lins via FreeIPA-users
Could you inform OS, release, ipa-server version and domain level? Cheers, Givaldo Lins De: "Adrian HY" Para: "FreeIPA users list" Cc: "Givaldo Lins" Enviadas: Segunda-feira, 12 de junho de 2017 9:36:54 Assunto: Re: [Freeipa-users] Re: replication problem Hi Givaldo, I tried to reini