[Freeipa-users] Re: Remove ntpd from IPA managed services

2018-11-01 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > I am having trouble with ntpd on my IPA server.  For whatever reason, > chrony seems to work when I manually stop ntpd. > > I would like to remove ntpd as an IPA-managed service.  I found an old > thread on this list that says I need to remove: > >  

[Freeipa-users] Remove ntpd from IPA managed services

2018-11-01 Thread Ian Pilcher via FreeIPA-users
I am having trouble with ntpd on my IPA server. For whatever reason, chrony seems to work when I manually stop ntpd. I would like to remove ntpd as an IPA-managed service. I found an old thread on this list that says I need to remove:

[Freeipa-users] Re: Cannot start FreeIPA master - procedure for cleaning up?

2018-11-01 Thread Callum Smith via FreeIPA-users
Dear Rob, Thanks for the fast reply, I think there's something really wrong with the hostname that's configured for the box (that'll teach me for using Ansible), and it's trying to auth locally when it's not running yet. krb5kdc.log Nov 01 18:18:59 ipa-a.in.bmrc.ox.ac.uk krb5kdc[11212](info):

[Freeipa-users] Re: Cannot start FreeIPA master - procedure for cleaning up?

2018-11-01 Thread Rob Crittenden via FreeIPA-users
Callum Smith via FreeIPA-users wrote: > Dear All, > > Running a FreeIPA cluster, the master has fallen over and refuses to get > back up: > > Failed to read data from service file: Unknown error when retrieving > list of services from LDAP: Insufficient access: SASL(-4): no mechanism >

[Freeipa-users] Cannot start FreeIPA master - procedure for cleaning up?

2018-11-01 Thread Callum Smith via FreeIPA-users
Dear All, Running a FreeIPA cluster, the master has fallen over and refuses to get back up: Failed to read data from service file: Unknown error when retrieving list of services from LDAP: Insufficient access: SASL(-4): no mechanism available: (Unknown authentication method) I was wondering

[Freeipa-users] Re: Insufficient access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Ticket expired)

2018-11-01 Thread Robbie Harwood via FreeIPA-users
lune voo via FreeIPA-users writes: > Hello ! > > I contact you because I have a random problem with my 3.0.0.47 FreeIPA > server. > > Sometimes, suddenly, I cannot use anymore the REST API and I got the > following errors when I try things like ipa user-show : > Insufficient access: SASL(-1):

[Freeipa-users] Re: Deployment without CA

2018-11-01 Thread Henrik Johansson via FreeIPA-users
> On 1 Nov 2018, at 10:39, Alexander Bokovoy wrote: > >> Thanks, you mean the UPN: kbtgt/domain@domainn.net part? >> >> We have an intetrnal CA, i guess i’ll try to generate a CSR with >> certutil and submit it. It will be quite a few UPN/SAN if I want one >> certificate for all servers

[Freeipa-users] Re: Cannot issue new certificate

2018-11-01 Thread Peter Tselios via FreeIPA-users
Forget it. I had a tiny typo in the managed by host ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Cannot issue new certificate

2018-11-01 Thread Peter Tselios via FreeIPA-users
Hello, I have issued a certificate for an AWS ELB. The certificate is attached to a psedo-host and service named lb.example.com. There is a certificate and the certificate ID is 21. The certificate was created on the FreeIPA server. (as indicated here

[Freeipa-users] Re: certmonger Error 77 Problem with the SSL CA cert

2018-11-01 Thread Kees Bakker via FreeIPA-users
On 31-10-18 14:27, Kees Bakker via FreeIPA-users wrote: > On 30-10-18 19:41, Rob Crittenden wrote: >> Kees Bakker wrote: >>> On 29-10-18 19:30, Rob Crittenden wrote: Kees Bakker via FreeIPA-users wrote: > On 29-10-18 11:56, Kees Bakker via FreeIPA-users wrote: >> On 26-10-18 18:20,

[Freeipa-users] Re: Deployment without CA

2018-11-01 Thread Alexander Bokovoy via FreeIPA-users
On to, 01 marras 2018, Henrik Stigendal via FreeIPA-users wrote: On 1 Nov 2018, at 00:51, Fraser Tweedale wrote: Note that you'll have a hard time getting a certificate signed by a public CA with the approriate Extended Key Usage and Subject Alternative Name values for a KDC certificate.

[Freeipa-users] Re: Deployment without CA

2018-11-01 Thread Henrik Stigendal via FreeIPA-users
> On 1 Nov 2018, at 00:51, Fraser Tweedale wrote: > Note that you'll have a hard time getting a certificate signed by a > public CA with the approriate Extended Key Usage and Subject > Alternative Name values for a KDC certificate. If you are getting > certificates from some other internal CA

[Freeipa-users] Re: Abstracted NTP server configuration

2018-11-01 Thread Tibor Dudlák via FreeIPA-users
Hey Andrey, I like it! Will jump on review ASAP. On Mon, Oct 29, 2018 at 9:10 AM Andrey Bychkov via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > I offer two packages for configuring ntp service. One for IPA server and > next for IPA client. Each package contains all supported