[Freeipa-users] Re: CentOS 7 ipa upgrade causes pki-tomcatd not to start CA

2019-01-28 Thread Patrice Gamache via FreeIPA-users
do you have any news on this issue... i havea similar trouble...after yum update from centos 7.4 to 7.6 the pki-tomcatd services failed to start...it worked for a while then failed and now it won't start anymore... looked at the certificate and all seems ok... after a quick look at the

[Freeipa-users] LDAP account for service

2019-01-28 Thread Ian Pilcher via FreeIPA-users
Continuing my adventures with FreeRADIUS ... It seems that there's no escaping the need to create a dedicated LDAP user for FreeRADIUS, so that it can see group membership information. I've already created a FreeIPA service - radius/ipa.example@example.com - so that I could issue a

[Freeipa-users] Re: Unable to migrate IPA3 to IPA4

2019-01-28 Thread Robert Alba via FreeIPA-users
Hostname is the same, just gave it a different IP and update the /etc/hosts file lax4ipa01.mia.bill1st.local r...@lax4ipa01.mia.bill1st:~$ tail /var/log/pki-ca/catalina.out Oct 01, 2018 12:13:33 AM org.apache.coyote.http11.Http11Protocol start INFO: Starting Coyote HTTP/1.1 on http-9444 Oct 01,

[Freeipa-users] Re: Unable to migrate IPA3 to IPA4

2019-01-28 Thread Robert Alba via FreeIPA-users
I kept the hostname the same and just changed the IP. 10.26.26.102 lax4ipa01.mia.bill1st.local I disable IPA and NTP from starting after i cloned it from /var/log/pki-ca/catalina.out pasted some errris CMS Warning: FAILURE: Cannot build CA chain. Error java.security.cert.CertificateException:

[Freeipa-users] [SOLVED] FreeIPA server has no UID range

2019-01-28 Thread Ian Pilcher via FreeIPA-users
On 1/28/19 11:02 AM, Ian Pilcher wrote: Many moons ago I migrated my home FreeIPA server from CentOS 6 to CentOS 7 via replication.  I've just tried to create a new user for the first time since, and I hit:   Operations error: Allocation of a new value for range cn=posix   ids,cn=distributed

[Freeipa-users] Re: "floating IP" / HA IPA <= and Win AD one-way trust

2019-01-28 Thread lejeczek via FreeIPA-users
On 26/01/2019 15:02, François Cami wrote: > On Sat, Jan 26, 2019 at 11:21 AM François Cami wrote: >> Hi, >> >> On Fri, Jan 25, 2019 at 2:06 PM lejeczek via FreeIPA-users >> wrote: >>> hi gents, >>> >>> I wonder if IPA when setup up on an "isolated" network segment, having >>> one single point of

[Freeipa-users] FreeIPA server has no UID range

2019-01-28 Thread Ian Pilcher via FreeIPA-users
Many moons ago I migrated my home FreeIPA server from CentOS 6 to CentOS 7 via replication. I've just tried to create a new user for the first time since, and I hit: Operations error: Allocation of a new value for range cn=posix ids,cn=distributed numeric assignment

[Freeipa-users] Re: CentOS 7 ipa upgrade causes pki-tomcatd not to start CA

2019-01-28 Thread Jason Wood via FreeIPA-users
> Jason, > > Yes, bad search filter there - apologies. > > This one is better: > > # ldapsearch -xLLL -D "cn=Directory Manager" -W -b > ou=certificateprofiles,ou=ca,o=ipaca > '(&(nsds5ReplConflict=*)(objectclass=ldapsubentry))' > > The base DN you want to specify is

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread Alexander Bokovoy via FreeIPA-users
On ma, 28 tammi 2019, François Cami wrote: On Mon, Jan 28, 2019 at 1:02 PM Ronald Wimmer via FreeIPA-users wrote: On 28.01.19 12:42, Alexander Bokovoy wrote: > On ma, 28 tammi 2019, Ronald Wimmer via FreeIPA-users wrote: > [...] >> Is there any experience on how to deal with such a situation?

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread François Cami via FreeIPA-users
On Mon, Jan 28, 2019 at 1:02 PM Ronald Wimmer via FreeIPA-users wrote: > > On 28.01.19 12:42, Alexander Bokovoy wrote: > > On ma, 28 tammi 2019, Ronald Wimmer via FreeIPA-users wrote: > > [...] > >> Is there any experience on how to deal with such a situation? > > Really depends on where these

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread François Cami via FreeIPA-users
On Mon, Jan 28, 2019 at 12:52 PM Ronald Wimmer wrote: > On 28.01.19 12:36, François Cami wrote: > > On Mon, Jan 28, 2019 at 12:20 PM Ronald Wimmer via FreeIPA-users > > wrote: > >> > >> What would be a good solution to add systems where the FQDN cannot be > >> changed? > > > > It's a pretty

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread Ronald Wimmer via FreeIPA-users
On 28.01.19 12:42, Alexander Bokovoy wrote: On ma, 28 tammi 2019, Ronald Wimmer via FreeIPA-users wrote: [...] Is there any experience on how to deal with such a situation? Really depends on where these existing clients are located and what is their function. Do they belong to some other

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread Ronald Wimmer via FreeIPA-users
On 28.01.19 12:36, François Cami wrote: On Mon, Jan 28, 2019 at 12:20 PM Ronald Wimmer via FreeIPA-users wrote: What would be a good solution to add systems where the FQDN cannot be changed? It's a pretty generic question, could you be more specific? Legacy systems are in an AD domain.

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread Alexander Bokovoy via FreeIPA-users
On ma, 28 tammi 2019, Ronald Wimmer via FreeIPA-users wrote: What would be a good solution to add systems where the FQDN cannot be changed? Would it make sense to add a second DNS A Record in the IPA domain for each of these systems? Is there any experience on how to deal with such a

[Freeipa-users] Re: IPA and legacy systems

2019-01-28 Thread François Cami via FreeIPA-users
On Mon, Jan 28, 2019 at 12:20 PM Ronald Wimmer via FreeIPA-users wrote: > > What would be a good solution to add systems where the FQDN cannot be > changed? It's a pretty generic question, could you be more specific? For instance, does that legacy system live in a zone controlled by AD? >

[Freeipa-users] IPA and legacy systems

2019-01-28 Thread Ronald Wimmer via FreeIPA-users
What would be a good solution to add systems where the FQDN cannot be changed? Would it make sense to add a second DNS A Record in the IPA domain for each of these systems? Is there any experience on how to deal with such a situation? Thanks a lot in advance! Cheers, Ronald