[Freeipa-users] Re: ipa-replica-install -- cannot get past [26/41]: creating DS keytab

2019-01-30 Thread Jonathon Jenkins via FreeIPA-users
I have found the issue - on the master there was an old krbPrincipalName associated with this host. Clearing it out allowed this process to finish. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] ipa-replica-install -- cannot get past [26/41]: creating DS keytab

2019-01-30 Thread Jonathon Jenkins via FreeIPA-users
Greetings, I cannot get the ipa-replica-install to proceed past step 26/41 - creating DS keytab. I see the command that is to be run, and I can run that just fine before and after the ipa-replica-install command, and it creates the keytab. I am not sure how to proceed from here - the bug

[Freeipa-users] Re: Transitive trust with AD domain that has already a trust with a 3rd domain.

2019-01-30 Thread Alexander Bokovoy via FreeIPA-users
On ke, 30 tammi 2019, SOLER SANGUESA Miguel via FreeIPA-users wrote: Hello, I have 2 AD domains on windows 2016 with a forest trust, two-way, and "Selective authentication": mydomain.com <--trust--> other.company.org Now I have built an IDM instance on RHEL 7.5 and IPA version 4.5.4 on the

[Freeipa-users] Re: [systemd-devel] systemctl condreload - Is it a thing?

2019-01-30 Thread Ian Pilcher via FreeIPA-users
On 1/30/19 10:16 AM, Ian Pilcher wrote: Yes, but I'm asking about condreload (not condrestart). Wrong mailing list. Sorry! -- Ian Pilcher arequip...@gmail.com "I grew up

[Freeipa-users] Re: [systemd-devel] systemctl condreload - Is it a thing?

2019-01-30 Thread Ian Pilcher via FreeIPA-users
On 1/30/19 10:11 AM, Andy Pieters wrote: man page on Centos try-restart PATTERN... Restart one or more units specified on the command line if the units are running. This does nothing if units are not running. Note that, for compatibility with Red Hat init scripts,

[Freeipa-users] Transitive trust with AD domain that has already a trust with a 3rd domain.

2019-01-30 Thread SOLER SANGUESA Miguel via FreeIPA-users
Hello, I have 2 AD domains on windows 2016 with a forest trust, two-way, and "Selective authentication": mydomain.com <--trust--> other.company.org Now I have built an IDM instance on RHEL 7.5 and IPA version 4.5.4 on the subdomain "ipa.mydomain.com". I need to use users from the 2 domains

[Freeipa-users] Re: certmonger with certs/keys not owned by root

2019-01-30 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > I am setting up FreeRADIUS on my "network server" at home, which also > runs FreeIPA.  Naturally, I would like to use certmonger to issue, > track, and renew the certificate(s) used by FreeRADIUS. > > Unfortunately, ipa-getcert only works when run as root,