[Freeipa-users] Re: cross-forest trust, client system cannot id AD users.

2017-10-19 Thread Steve Dainard via FreeIPA-users
Thanks Jakub and Justin, It definitely is related to the wheel group. For a quick explanation, the wheel group exists in AD with a gid of 10 so users who belong to that group automatically have wheel/sudo perms on EL systems (we use posix attributes in AD for all our users/groups). The easy fix

[Freeipa-users] Re: Unable to sign CSR with multiple CN in subject

2017-10-19 Thread Fraser Tweedale via FreeIPA-users
On Thu, Oct 19, 2017 at 10:40:12AM +, Joel Kåberg via FreeIPA-users wrote: > Hello > > I'm trying to sign an CSR which has multiple CN in the certificate > subject. When the certificate is signed it only contains one CN in > the subject (should be 2, site1.domain.tld and site2.domain.tld), >

[Freeipa-users] Re: Guidance on setting up locked down role for a local IPA user who can only do "ipa hbactest ... " command?

2017-10-19 Thread Alexander Bokovoy via FreeIPA-users
On to, 19 loka 2017, Chris Dagdigian via FreeIPA-users wrote: Hi folks, We have an absurdly complex multi-domain/multi-child AD forrest tied together on AWS via FreeIPA. I'm spending a lot of time debugging login issues and the "ipa hbactest" command is fantastic at "proving" out if

[Freeipa-users] Re: cross-forest trust, client system cannot id AD users.

2017-10-19 Thread Justin Stephenson via FreeIPA-users
On 10/19/2017 02:14 PM, Jakub Hrozek via FreeIPA-users wrote: On Tue, Oct 17, 2017 at 02:21:07PM -0700, Steve Dainard via FreeIPA-users wrote: Hello, I've installed a 60 day 'self supported' trial of red hat idm on rhel7. I've created a cross-forest trust with an AD domain (2012R2) which

[Freeipa-users] Re: cross-forest trust, client system cannot id AD users.

2017-10-19 Thread Jakub Hrozek via FreeIPA-users
On Tue, Oct 17, 2017 at 02:21:07PM -0700, Steve Dainard via FreeIPA-users wrote: > Hello, > > I've installed a 60 day 'self supported' trial of red hat idm on rhel7. > I've created a cross-forest trust with an AD domain (2012R2) which already > has posix attributes in ldap for users and groups. >

[Freeipa-users] Guidance on setting up locked down role for a local IPA user who can only do "ipa hbactest ... " command?

2017-10-19 Thread Chris Dagdigian via FreeIPA-users
Hi folks, We have an absurdly complex multi-domain/multi-child AD forrest tied together on AWS via FreeIPA. I'm spending a lot of time debugging login issues and the "ipa hbactest" command is fantastic at "proving" out if something should or should not work. I currently "kinit admin"

[Freeipa-users] One Machine not allowing kerberos auth

2017-10-19 Thread Jeremy Utley via FreeIPA-users
New FreeIPA deployment, and i have one server that is not allowing Kerberos to handle authentication, but instead is prompting for password with a valid kerberos ticket. All other machines are working normally. I've double-checked the /etc/ssh/sshd_config file, identical between the one not

[Freeipa-users] multiple sub-domains

2017-10-19 Thread Andrew Meyer via FreeIPA-users
I am running into an issue deploying FreeIPA.  I am converting from OpenLDAP.  However I have multiple sub-domain under my tld. So let's say I own example.com I have multiple zones under that where I have servers sitting.  All of these sub-domains are specific to VLANs as well.

[Freeipa-users] Re: Replica failure, could not perform interactive bind ... [GSSAPI]

2017-10-19 Thread Alexander Bokovoy via FreeIPA-users
On to, 19 loka 2017, Kees Bakker via FreeIPA-users wrote: On 19-10-17 15:07, Alexander Bokovoy wrote: On to, 19 loka 2017, Kees Bakker via FreeIPA-users wrote: [...] [18/Oct/2017:11:24:27 +0200] NSMMReplicationPlugin - agmt="cn=meTolinge.ghs.nl" (linge:389): Replication bind with GSSAPI auth

[Freeipa-users] Re: Replica failure, could not perform interactive bind ... [GSSAPI]

2017-10-19 Thread Kees Bakker via FreeIPA-users
On 19-10-17 15:07, Alexander Bokovoy wrote: > On to, 19 loka 2017, Kees Bakker via FreeIPA-users wrote: >> [...] >> [18/Oct/2017:11:24:27 +0200] NSMMReplicationPlugin - >> agmt="cn=meTolinge.ghs.nl" (linge:389): Replication bind with GSSAPI auth >> resumed >> >> Again, I would really appreciate

[Freeipa-users] Re: Replica failure, could not perform interactive bind ... [GSSAPI]

2017-10-19 Thread Alexander Bokovoy via FreeIPA-users
On to, 19 loka 2017, Kees Bakker via FreeIPA-users wrote: On 19-10-17 10:03, Kees Bakker via FreeIPA-users wrote: On 18-10-17 22:57, Robbie Harwood wrote: Kees Bakker writes: Since I've setup a replica it gives errors like these: [17/Oct/2017:11:36:55 +0200] slapd_ldap_sasl_interactive_bind

[Freeipa-users] Re: Cannot log in to the FreeIPA replica UI with AD credentials

2017-10-19 Thread Alexander Bokovoy via FreeIPA-users
On to, 19 loka 2017, Bart J via FreeIPA-users wrote: Hi all, I set up an instance of FreeIPA server and established trust with AD domain. I configured AD users and they can successfully log in to the web UI. Then, I set up a replica. Although the trust is visible for that instance both in the

[Freeipa-users] Re: Replica failure, could not perform interactive bind ... [GSSAPI]

2017-10-19 Thread Kees Bakker via FreeIPA-users
On 19-10-17 10:03, Kees Bakker via FreeIPA-users wrote: > On 18-10-17 22:57, Robbie Harwood wrote: >> Kees Bakker writes: >> >>> Since I've setup a replica it gives errors like these: >>> >>> [17/Oct/2017:11:36:55 +0200] slapd_ldap_sasl_interactive_bind - Error: >>> could not perform interactive

[Freeipa-users] Cannot log in to the FreeIPA replica UI with AD credentials

2017-10-19 Thread Bart J via FreeIPA-users
Hi all, I set up an instance of FreeIPA server and established trust with AD domain. I configured AD users and they can successfully log in to the web UI. Then, I set up a replica. Although the trust is visible for that instance both in the web UI and CLI, AD users cannot log in to it, nor can

[Freeipa-users] Unable to sign CSR with multiple CN in subject

2017-10-19 Thread Joel Kåberg via FreeIPA-users
Hello I'm trying to sign an CSR which has multiple CN in the certificate subject. When the certificate is signed it only contains one CN in the subject (should be 2, site1.domain.tld and site2.domain.tld), and furthermore only two alternative names (should be 3 – missing the site2.domain.tld),

[Freeipa-users] Re: Replica failure, could not perform interactive bind ... [GSSAPI]

2017-10-19 Thread Kees Bakker via FreeIPA-users
On 18-10-17 22:57, Robbie Harwood wrote: > Kees Bakker writes: > >> Since I've setup a replica it gives errors like these: >> >> [17/Oct/2017:11:36:55 +0200] slapd_ldap_sasl_interactive_bind - Error: could >> not perform interactive bind for id [] mech [GSSAPI]: LDAP error -2 (Local >> error)

[Freeipa-users] Re: Latest updates broke pki-tomcatd

2017-10-19 Thread Rob Crittenden via FreeIPA-users
Kristian Petersen wrote: I'm still struggling with this one and it seems at least partially responsible for the UI misbehaving as we discussed in another thread. Have you had any new insights regarding this? I'd start with looking at /var/log/pki/pki-tomcat/ca/debug. You want to find the