[Freeipa-users] DNS Zone Serial Number

2017-09-22 Thread Andrey Ptashnik via FreeIPA-users
Team, How can I make sure that DNS zones are in sync between multiple masters? Is it normal for DNS zone to have different serial number on each replica? Thank you, Andrey ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubsc

[Freeipa-users] Web UI errors after update to ipa-server 4.5/centos 7.4

2017-09-22 Thread Mark Esman via FreeIPA-users
After upgrading two freeipa servers (replicas of each other) from ipa-server-4.4.0-14.el7.centos.7.x86_64 to ipa-server-4.5.0-21.el7.centos.1.2.x86_64 during the recent Centos 7.3 to 7.4 update, one of the servers is having Web UI errors. ipactl status show all services up and running on both ser

[Freeipa-users] basics of openssh and freeipa integration

2017-09-22 Thread freeipa-users--- via FreeIPA-users
Assume my new freeipa server is on 7.4 centos, and my client freeipa hosts are on fedora 25. Assume I create a freeipa user "jdoe" with a NFS4 automounted home dir, to be available on the fedora hosts. The goal is to ssh remotely into any fedora client host as "jdoe" and be authenticated by the c

[Freeipa-users] ipactl status Failed to get list of services to probe status! Configured hostname 'replica.company.domain' does not match any master server in LDAP: No master found because of error: n

2017-09-22 Thread pgb205 via FreeIPA-users
Get this error when trying to restart ipa service on apparently not working replica. This iscat /etc/redhat-releaseCentOS Linux release 7.3.1611 (Core)andipa-server-4.4.0-14.el7.centos.7.x86_64 and389-ds-base-1.3.5.10-20.el7_3.x86_64  ausearch -m avc -ts today slapd log shows the following [22/S

[Freeipa-users] Re: [+] Re: ipa-server-install fails on fresh install

2017-09-22 Thread John R. Shannon via FreeIPA-users
I upgraded to 4.6.1 today. The same problem persists. On 09/15/17 13:17, John R. Shannon wrote: > Attached > > On 09/15/17 12:58, Alexander Bokovoy wrote: >> On pe, 15 syys 2017, Rob Crittenden via FreeIPA-users wrote: >>> John R. Shannon via FreeIPA-users wrote: Attached >>> >>> It is faili

[Freeipa-users] Re: IPA replica appears in LDAP conflicts

2017-09-22 Thread Rob Crittenden via FreeIPA-users
Andrey Ptashnik via FreeIPA-users wrote: > Team, > > When I run LDAP search for conflicting records I see that one replica is > listed as a conflicting record. Do you know how that may have happened and > can I safely remove it? > > # ldapsearch -xLLL -D "cn=Directory Manager" -W -b "dc=aws,dc=

[Freeipa-users] Re: Is it safe to upgrade to 7.4 ?

2017-09-22 Thread Sameer Gurung via FreeIPA-users
How did you upgrade in centos 7? Can't find the upgrade in the repos On 22-Sep-2017 9:04 PM, "Ronald Wimmer via FreeIPA-users" < freeipa-users@lists.fedorahosted.org> wrote: > I upgraded from 7.3 to 7.4 on CentOS without a single issue. > > Cheers, > Ronald > _

[Freeipa-users] IPA replica appears in LDAP conflicts

2017-09-22 Thread Andrey Ptashnik via FreeIPA-users
Team, When I run LDAP search for conflicting records I see that one replica is listed as a conflicting record. Do you know how that may have happened and can I safely remove it? # ldapsearch -xLLL -D "cn=Directory Manager" -W -b "dc=aws,dc=cccis,dc=com" "nsds5ReplConflict=*" dn | perl -p00e 's

[Freeipa-users] Re: Is it safe to upgrade to 7.4 ?

2017-09-22 Thread Ronald Wimmer via FreeIPA-users
I upgraded from 7.3 to 7.4 on CentOS without a single issue. Cheers, Ronald ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Announcing FreeIPA 4.6.1

2017-09-22 Thread Tomas Krizek via FreeIPA-users
The FreeIPA team would like to announce FreeIPA 4.6.1 release! It can be downloaded from http://www.freeipa.org/page/Downloads. Builds for Fedora 26 and 27 are available in the official @freeipa/freeipa-4-6 COPR repository [1]. == Highlights in 4.6.1 == === Known Issues === * PyPI packages are

[Freeipa-users] Re: ipa-server-install failing at wait_for_open_ports

2017-09-22 Thread Eric Scholwin via FreeIPA-users
Just wanted to provide an update. I was able to fix the issue and get ipa-server-install to finish correctly. By default, my company turns off ipv6 during kickstart by disabling ipv6 in etc/sysctl.conf. We removed that and continued to have issues so I did a little more digging and found that wh

[Freeipa-users] sudo not working with hostgroups

2017-09-22 Thread Michael Gusek via FreeIPA-users
Hello, we are using FreeIPA in the current version 4.5 under current CentOS 7. In order to grant access we are using sudo rules in conjunction with host groups. We have found that these rules do not work under Debian 8/9 and Ubuntu 16.04, but with Centos 6/7. Suggestions from the web require a set

[Freeipa-users] Re: ipa-server-install failing at wait_for_open_ports

2017-09-22 Thread Tiemen Ruiten via FreeIPA-users
Besides checking your hosts file, also double-check that localhost actually has an ipv6 address. On 22 September 2017 at 07:43, Maciej Drobniuch via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hey Eric, > > To me looks like either the /etc/hosts file is wrongly configured/dns >