[Freeipa-users] Re: FreeIPA AD Trust with Samba4 ... is it possible?

2018-08-13 Thread Lachlan Musicman via FreeIPA-users
On 14 August 2018 at 01:38, Hacker Sword via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi Alex, > > >The documentation is only conflicting if you are using it in a > conflicting way. > > > > The choice of Kerberos library is important. Samba AD DC with MIT > Kerberos still is

[Freeipa-users] Re: FreeIPA AD Trust with Samba4 ... is it possible?

2018-08-13 Thread Alexander Bokovoy via FreeIPA-users
On Mon, 13 Aug 2018, Hacker Sword via FreeIPA-users wrote: Hi Alex, The documentation is only conflicting if you are using it in a conflicting way. The choice of Kerberos library is important. Samba AD DC with MIT Kerberos still is broken regarding trust to FreeIPA. Pardon my ignorance,

[Freeipa-users] FreeIPA behind Traefik Reverse Proxy, with wildcard certs

2018-08-13 Thread Ethan Lambert via FreeIPA-users
I have FreeIPA running in a VM with a static IP assigned via dnsmasq with Traefik acting as a reverse proxy. I have traefik grabbing wildcard certs for the domain. However, it seems that FreeIPA does not like that as it has this error in the error log: `SSL Library Error: - 12271 SSL client

[Freeipa-users] Apache OTP Basic Auth

2018-08-13 Thread Robert Gabriel via FreeIPA-users
Hi, Forgive me if this is a dumb question... Is it possible to do password+OTP through Apache basic auth? I have 2FA working for a user via Linux console/SSH login. I have Apache working with Kerberos auth through FreeIPA: AuthType Kerberos AuthName "Web Server Login"

[Freeipa-users] Re: IPA-Server-Upgrade crashes - Certificate has expired

2018-08-13 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/13/2018 05:43 PM, Tobi Berninger via FreeIPA-users wrote: Hello Flo, thanks for ur fast answer. First of all we are an small student organization so we dont have the luck to have the money for an red hat support contract and cant access the link u provided. I started the other

[Freeipa-users] Re: IPA-Server-Upgrade crashes - Certificate has expired

2018-08-13 Thread Tobi Berninger via FreeIPA-users
Hello Flo, thanks for ur fast answer. First of all we are an small student organization so we dont have the luck to have the money for an red hat support contract and cant access the link u provided. I started the other services with ipactl, as u described, allready but not working fully. I also

[Freeipa-users] Re: IPA-Server-Upgrade crashes - Certificate has expired

2018-08-13 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/13/2018 04:13 PM, Tobi Berninger via FreeIPA-users wrote: Hello, i upgrade my centos 7.5 ipaserver to an new version and runned into a few problems. It seems like 'subsystemCert cert-pki-ca' is expired nearly a month ago (jul 22) and i am not sure how to renew it. When i run the

[Freeipa-users] Re: Documented monitoring best practices

2018-08-13 Thread Andrew Meyer via FreeIPA-users
I know this is an old thread, but there are no changes to FreeIPA that cnmonitor might conflict with are there? On Thursday, February 1, 2018 1:34 PM, Rob Crittenden via FreeIPA-users wrote: Alex Corcoles via FreeIPA-users wrote: > On Thu, Feb 1, 2018 at 5:25 PM, Jochen Hein

[Freeipa-users] Re: Changing domain name

2018-08-13 Thread Alfredo De Luca via FreeIPA-users
Hi Florence. I created an new IPA server and tried to migrate but I got the following ... *Passwords have been migrated in pre-hashed format.* *IPA is unable to generate Kerberos keys unless provided* *with clear text passwords. All migrated users need to* *login at

[Freeipa-users] Re: FreeIPA AD Trust with Samba4 ... is it possible?

2018-08-13 Thread Alexander Bokovoy via FreeIPA-users
On ma, 13 elo 2018, Alexander Bokovoy via FreeIPA-users wrote: On pe, 10 elo 2018, D Anderson via FreeIPA-users wrote: Hello all, I am confused by some of the conflicting documentation about whether this is possible or not. Almost all of the documentation/working examples seem to use an

[Freeipa-users] Re: FreeIPA AD Trust with Samba4 ... is it possible?

2018-08-13 Thread Alexander Bokovoy via FreeIPA-users
On pe, 10 elo 2018, D Anderson via FreeIPA-users wrote: Hello all, I am confused by some of the conflicting documentation about whether this is possible or not. Almost all of the documentation/working examples seem to use an actual Windows Domain Controller. Specifically the part on DNS , as

[Freeipa-users] Re: Changing domain name

2018-08-13 Thread Alfredo De Luca via FreeIPA-users
Thanks heaps Florence. Appreciated Alfredo On Mon, Aug 13, 2018 at 11:42 AM Florence Blanc-Renaud wrote: > On 08/13/2018 11:17 AM, Alfredo De Luca via FreeIPA-users wrote: > > Hi Florence. yes this clarify my question. So or I will build an new > > FreeIPA then manually add all the

[Freeipa-users] Stop samba sevice and winbind

2018-08-13 Thread barrykfl--- via FreeIPA-users
Hi all : Any idea how to skip boot of smb.server and win bind ...or uninstall them without affect ..thx Directory Service: RUNNING krb5kdc Service: RUNNING kadmin Service: RUNNING httpd Service: RUNNING ipa-custodia Service: RUNNING ntpd Service: RUNNING pki-tomcatd Service: RUNNING smb

[Freeipa-users] Re: Changing domain name

2018-08-13 Thread Alfredo De Luca via FreeIPA-users
Hi Florence. yes this clarify my question. So or I will build an new FreeIPA then manually add all the users/groups etc ... or maybe import at least some users with some sort of ldap command? Cheers On Mon, Aug 13, 2018 at 8:38 AM Florence Blanc-Renaud wrote: > On 08/11/2018 06:11 PM, Alfredo

[Freeipa-users] Re: Changing domain name

2018-08-13 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/11/2018 06:11 PM, Alfredo De Luca via FreeIPA-users wrote: Hi all. We'd like to change the domain name on our freeipa (4.5.4 on centos 7.5). Not the realm but only the domain is it doable? If so... how? Hi, unfortunately, no. Please have a look at IdM documentation, section Host