[Freeipa-users] Re: Replica from RHEL6 7 fails to create CA with clone URI mismatch

2017-07-19 Thread Endi Sukma Dewata via FreeIPA-users
- Original Message - > David Hendén via FreeIPA-users wrote: > > Hi all, > > > > I'm trying to set up a replica from RHEL6.9 FreeIPA 3.0.0 to RHEL7.3 RHEL > > 4.4.0. > > > > What I'm trying to achieve is an isolated FreeIPA 4.4 server that we could > > replace the original FreeIPA 3.0

[Freeipa-users] Re: Kerberized NFS for system users

2017-07-19 Thread Anton Semjonov via FreeIPA-users
Hello again. As a follow-up, I tried some further troubleshooting on two fresh virtual machines. The setup process was as follows: [both] - install CentOS via kickstart - change hostname - ipa-client-install - ipa-client-automount - install @Network File System Client / @File and Storage Server

[Freeipa-users] Re: keys for cert - how to get those?

2017-07-19 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > hello fallas > > those certs I see with: > $ ipa cert-find > is it possible to get private key(s) for a given cert? With means of > (any)command line? Not from the CA, no. The CA doesn't store the private keys for the certificates it issues and never sees

[Freeipa-users] Re: can't upgrade IPA because of certificate alias problem

2017-07-19 Thread Rob Crittenden via FreeIPA-users
Fraser Tweedale via FreeIPA-users wrote: > On Thu, Jul 13, 2017 at 03:02:02PM +, Charles Hedrick via FreeIPA-users > wrote: >> I’ve installed ipa. Originally I did the default install, without DNS. >> >> I then updated to a commercial cert. Notes at the end. >> >> I just did a yum update.

[Freeipa-users] Re: Update signing certificate

2017-07-19 Thread Rob Crittenden via FreeIPA-users
Jatin Nansi via FreeIPA-users wrote: > You can not use ipa-getcert to request / issue certificates from an > external CA. Issuing certificates now needs to be managed by the > external CA's tools. You should also disable the old CA from starting up > on IPA server. I guess it depends what the

[Freeipa-users] Re: Replica from RHEL6 7 fails to create CA with clone URI mismatch

2017-07-19 Thread Rob Crittenden via FreeIPA-users
David Hendén via FreeIPA-users wrote: > Hi all, > > I'm trying to set up a replica from RHEL6.9 FreeIPA 3.0.0 to RHEL7.3 RHEL > 4.4.0. > > What I'm trying to achieve is an isolated FreeIPA 4.4 server that we could > replace the original FreeIPA 3.0 infrastrcuture with. The way I'm doing this

[Freeipa-users] Re: docker container user no matching entries in passwd file

2017-07-19 Thread Lukas Slebodnik via FreeIPA-users
On (17/07/17 09:54), Thomas Lau via FreeIPA-users wrote: >docker-​host# docker run --user=testaccount1 -d -p 9001:9001 e7b263ac54e2 >990c220ccb30b5012e7e5aa45f7e9345098cdb867328302daff567474055de02 >docker: Error response from daemon: linux spec user: unable to find user >testaccount1: no