[Freeipa-users] Re: freeipa client working on ubuntu 16.04 but not 14.04

2018-01-04 Thread Cody Rathgeber via FreeIPA-users
Thanks, Here's what I get in the sssd nss log with debug level set to 6; (Thu Jan 4 14:35:56 2018) [sssd[nss]] [sss_parse_name_for_domains] (0x0200): using default domain [(null)] (Thu Jan 4 14:35:56 2018) [sssd[nss]] [nss_cmd_getbynam] (0x0100): Requesting info for [*] from [] (Thu Jan 4

[Freeipa-users] Re: freeipa client working on ubuntu 16.04 but not 14.04

2018-01-04 Thread Jochen Hein via FreeIPA-users
Cody Rathgeber via FreeIPA-users writes: > I'm trying to deploy freeipa to an environment running a mix of ubuntu > 16.04 and 14.04 servers. > on 16.04 the servers join and can pull down users no problem, on 14.04 when > joining it'll throw a > > "Unable to

[Freeipa-users] Re: freeipa client working on ubuntu 16.04 but not 14.04

2018-01-04 Thread Rob Crittenden via FreeIPA-users
Cody Rathgeber via FreeIPA-users wrote: > Hello, > > I'm trying to deploy freeipa to an environment running a mix of ubuntu > 16.04 and 14.04 servers. > on 16.04 the servers join and can pull down users no problem, on 14.04 > when joining it'll throw a > > "Unable to find 'admin' user with

[Freeipa-users] freeipa client working on ubuntu 16.04 but not 14.04

2018-01-04 Thread Cody Rathgeber via FreeIPA-users
Hello, I'm trying to deploy freeipa to an environment running a mix of ubuntu 16.04 and 14.04 servers. on 16.04 the servers join and can pull down users no problem, on 14.04 when joining it'll throw a "Unable to find 'admin' user with 'getent passwd ad...@redacted.net'!:" And sure enough

[Freeipa-users] Re: Forwarders don't work when enabled but do work when disabled

2018-01-04 Thread Martin Basti via FreeIPA-users
Hello, Could you be more specific about your configuration. How did you disabled forwarder, what is your forwarder configuration Martin ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: client fails - requested domain name does not match the server's certificate

2018-01-04 Thread Natxo Asenjo via FreeIPA-users
On Thu, Jan 4, 2018 at 7:01 PM, lejeczek via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: [knip] Joining realm failed: libcurl failed to execute the HTTP POST transaction, > explaining: Unable to communicate securely with peer: requested domain > name does not match the server's

[Freeipa-users] New replica (4.5) issues

2018-01-04 Thread john.bowman--- via FreeIPA-users
After some trial and error I was finally able to get a new replica + CA (RHEL7.4 and ipa-server 4.5) added to our existing mixed (RHEL 6 and ipa server 3.0 - 4.x) and the ipa-replica-install command completed successfully but now when I run the ipa-manage-replica -v list command I see this: #

[Freeipa-users] Re: debian 8 freeipa-client

2018-01-04 Thread Andrew Radygin via FreeIPA-users
Flo, of course it installed. # which python /usr/bin/python # python -V Python 2.7.14+ = It seems Timo is right. Update python-six to 1.11 and dpkg --configure executed successful. BUT, I've next error :) # ipa-client-install .. There was a problem importing one of the required Python

[Freeipa-users] Re: Ubuntu -> Fedora and tomcat SetAllPropertiesRule warnings

2018-01-04 Thread David Harvey via FreeIPA-users
Point No.2 Is now sorted. It was the old missing Subject Alternative Name extension in certificate problem (which I had only seen with https until now!). I would still love to know if I need to live in fear of the other errors though :) On 4 January 2018 at 12:25, David Harvey

[Freeipa-users] Re: debian 8 freeipa-client

2018-01-04 Thread Timo Aaltonen via FreeIPA-users
On 04.01.2018 12:48, Andrew Radygin via FreeIPA-users wrote: > Flo, > I've checked certmonger dbus config - it's okay and identical to another > one working. > But after restart dbus - certmoner configured and installed successful. > > Although I have another problem error now: > >

[Freeipa-users] Re: Centos7.4: users not seeing password expired notifications

2018-01-04 Thread Jakub Hrozek via FreeIPA-users
On Thu, Jan 04, 2018 at 11:30:22AM +0100, Johan Vermeulen via FreeIPA-users wrote: > Hello, > > apologies for the late reply, due to the holidays. > > I had a call from a user this morning, she had to do multiple login > attempts and reboot several times before she could login. > > Trying to

[Freeipa-users] Re: debian 8 freeipa-client

2018-01-04 Thread Florence Blanc-Renaud via FreeIPA-users
On 01/04/2018 11:48 AM, Andrew Radygin via FreeIPA-users wrote: Flo, I've checked certmonger dbus config - it's okay and identical to another one working. But after restart dbus - certmoner configured and installed successful. Although I have another problem error now: # apt-get

[Freeipa-users] Ubuntu -> Fedora and tomcat SetAllPropertiesRule warnings

2018-01-04 Thread David Harvey via FreeIPA-users
Dear list, In trying to escape from the various issues facing the ubuntu freeipa, I attempted to make the switch to Fedora 26 (same freeipa version 4.4.4). This seemed to go well (adding new replica first, and then replacing the ubuntu based installs), but I notice on my fedora boxes several

[Freeipa-users] Re: debian 8 freeipa-client

2018-01-04 Thread Andrew Radygin via FreeIPA-users
Flo, I've checked certmonger dbus config - it's okay and identical to another one working. But after restart dbus - certmoner configured and installed successful. Although I have another problem error now: # apt-get install freeipa-client Reading package lists... Done Building

[Freeipa-users] Re: Centos7.4: users not seeing password expired notifications

2018-01-04 Thread Johan Vermeulen via FreeIPA-users
Hello, apologies for the late reply, due to the holidays. I had a call from a user this morning, she had to do multiple login attempts and reboot several times before she could login. Trying to follow https://docs.pagure.org/SSSD.sssd/users/troubleshooting.html I assume the general setup