[Freeipa-users] FreeIPA 4.5.2 with AD Trust - Web UI trouble

2017-06-29 Thread Jason Hensley via FreeIPA-users
Hello, I have setup a pair of FreeIPA 4.5.2 servers. One via ipa-server-install, the other via ipa-replica-install. I have tried them both as trust controllers and I have tried them in a controller/agent setup. My problem is that no AD users can login to the self service UI on the secondary

[Freeipa-users] New to FreeIPA cant figure out integrated DNS.

2017-06-29 Thread euanhaahrmail2--- via FreeIPA-users
I have been trying to install FreeIPA with integrated dns i found installing freeipa easy without dns but anything todo with the dns portion of it exceeding complicated. I have a internel dns server that i have been using to store all the host names of my internel pcs and then for anything exter

[Freeipa-users] Error running ipa-certupdate

2017-06-29 Thread Jeff Fouchard via FreeIPA-users
On our clients when attempting to run ipa-certupdate we are seeing the following error: ipa.ipapython.ipaldap.SchemaCache: DEBUG: retrieving schema for SchemaCache url=ldap://ldap2.int.ba.mydomain.local:389 conn= ipa.ipaclient.ipa_certupdate.CertUpdate: DEBUG: File "/usr/lib/python2.7/site-packa

[Freeipa-users] Re: { possibly offtopic } -- can sssd.conf alone be configured to copy the custom AD ID Ranges used by IPA server?

2017-06-29 Thread Jakub Hrozek via FreeIPA-users
On Thu, Jun 29, 2017 at 08:41:25AM -0400, Chris Dagdigian wrote: > Jakub Hrozek via FreeIPA-users wrote: > > If not, have you considered pointing the clients towards the compat tree > > and using a plain LDAP setup, if your vendor supports that? > > > Appreciate the replies to even a non-IPA usag

[Freeipa-users] Re: { possibly offtopic } -- can sssd.conf alone be configured to copy the custom AD ID Ranges used by IPA server?

2017-06-29 Thread Chris Dagdigian via FreeIPA-users
Jakub Hrozek via FreeIPA-users wrote: If not, have you considered pointing the clients towards the compat tree and using a plain LDAP setup, if your vendor supports that? Appreciate the replies to even a non-IPA usage question. This list has a tremendous signal:noise ratio. The info above s

[Freeipa-users] Errors after Upgrading from Fedora 23 to Fedora 25

2017-06-29 Thread dntosas--- via FreeIPA-users
Hello World! I got an installation with FreeIPA server 4.2.4 in Fedora 23 and all worked fine I decided to upgrade to Fedora 25 via dnf-upgrade-plugin All the upgrade proc goes smooth and as a result my freeipa rpm packages also upgraded (from 4.2.4 to 4.4.4) Now, the problem is that nothing

[Freeipa-users] Re: kinit not working for some accounts

2017-06-29 Thread Tiemen Ruiten via FreeIPA-users
Nevermind, the users didn't have a password set. On 29 June 2017 at 12:02, Tiemen Ruiten wrote: > Hello, > > I've just noticed that kinit is not working for several but not all > accounts in our FreeIPA domain (4.4.0-14.el7.centos.7). I get the following > error: > > on the client: > > [root@cae

[Freeipa-users] kinit not working for some accounts

2017-06-29 Thread Tiemen Ruiten via FreeIPA-users
Hello, I've just noticed that kinit is not working for several but not all accounts in our FreeIPA domain (4.4.0-14.el7.centos.7). I get the following error: on the client: [root@caesium tiemen]# KRB5_TRACE=/dev/stdout kinit *dba* [7827] 1498729905.996951: Resolving unique ccache of type KEYRING

[Freeipa-users] Re: { possibly offtopic } -- can sssd.conf alone be configured to copy the custom AD ID Ranges used by IPA server?

2017-06-29 Thread Sumit Bose via FreeIPA-users
On Wed, Jun 28, 2017 at 08:22:12PM +0200, Jakub Hrozek via FreeIPA-users wrote: > On Wed, Jun 28, 2017 at 01:03:45PM -0400, Chris Dagdigian via FreeIPA-users > wrote: > > Hi folks, > > > > > > I have a set of servers that CANNOT become enrolled IDM clients due to a > > vendor refusing to support