[Freeipa-users] Re: Correct ownership for /etc/httpd/alias/ipasession.key

2018-01-02 Thread Hans Spaans via FreeIPA-users
Ian Pilcher via FreeIPA-users schreef op 2018-01-03 05:25: > On Jan 2, 2018 22:20, "Hans Spaans via FreeIPA-users" wrote: > > Ian Pilcher via FreeIPA-users schreef op 2018-01-03 04:03: > > Can someone check the correct ownership and permissions of > >

[Freeipa-users] Re: Correct ownership for /etc/httpd/alias/ipasession.key

2018-01-02 Thread Ian Pilcher via FreeIPA-users
Better to be lucky than good. ;-) Thanks! On Jan 2, 2018 22:20, "Hans Spaans via FreeIPA-users" < freeipa-users@lists.fedorahosted.org> wrote: > Ian Pilcher via FreeIPA-users schreef op 2018-01-03 04:03: > >> Can someone check the correct ownership and permissions of >>

[Freeipa-users] Re: Correct ownership for /etc/httpd/alias/ipasession.key

2018-01-02 Thread Hans Spaans via FreeIPA-users
Ian Pilcher via FreeIPA-users schreef op 2018-01-03 04:03: Can someone check the correct ownership and permissions of /etc/httpd/alias/ipasession.key? I have a feeling I may have messed mine up as I was copying the directory around. I currently have: -rw---. 1 root root 32 Sep 27

[Freeipa-users] Re: Renew expired certs with certmonger

2018-01-02 Thread Qing Chang via FreeIPA-users
Thank you Florence. It was in fact because I did not have renewal master. I actually sent in an update by replying to my initial email about how it was fixed but that email appears to be lost. I wonder how we got to the situation that we do not have a renewal master. That's probably also the

[Freeipa-users] Re: How to disable browser-based Kerberos?

2018-01-02 Thread Robbie Harwood via FreeIPA-users
Anthony Clark via FreeIPA-users writes: > Please ignore, bad copy and paste. > > Version 22 of the ipa.conf (the second pasted config section) is the one > that works correctly. > > Is there a way to disable Kerberos browser-side popup password box in >

[Freeipa-users] Re: I can't login with ipa user

2018-01-02 Thread Robbie Harwood via FreeIPA-users
"Miguel Angel Coa M. via FreeIPA-users" writes: > I'm connect my Centos 5.6 to IPA server (VERSION: 4.5.0). The > connection with ipa-client is ok, but i try login with ipa user from > server client but say ".. user does not exist" > > [root@av125 ~]# su

[Freeipa-users] Re: I can't login with ipa user

2018-01-02 Thread Rob Crittenden via FreeIPA-users
Miguel Angel Coa M. via FreeIPA-users wrote: > Hello, > I'm connect my Centos 5.6 to IPA server (VERSION: 4.5.0). The connection > with ipa-client is ok, but i try login with ipa user from server client > but say ".. user does not exist" > > > [..] > [root@av125 ~]# su -

[Freeipa-users] Re: Failed to read service file. Hostname does not match any master server in LDAP

2018-01-02 Thread Rob Crittenden via FreeIPA-users
pgb205 wrote: > We have a number of servers in different pops. When I say intermittent I > mean it doesn't just happen on the > same server again and again but rather on random servers each time. > There is no pattern as far as which > pop or time of day etc. > > I do ipactl status and see

[Freeipa-users] Add principal alias to a service from the client

2018-01-02 Thread Robson Ramos Barreto via FreeIPA-users
Hi Guys I need to add principal alias to a service from the client in which it is managed by. >From the client I have the following script: --- kinit -k -t /etc/krb5.keytab ipa service-add myservice/myclient.example.com ipa service-add-principal myservice/myclient.example.com myservice/

[Freeipa-users] Re: api scripts

2018-01-02 Thread Jens Timmerman via FreeIPA-users
Hi Andrew, On 26/12/2017 16:35, Andrew Meyer wrote: > Jens, > I'm not familiar w/ Python.  How do I pass the url, user and realm to > it?  Do I do something like this - './freeipaclient.py url=myurl > user=username' ? > If you're not familiar with python my code is probably not useful for you.