[Freeipa-users] Re: Ad user password authentication doesn't work

2019-03-01 Thread Patrick Irish via FreeIPA-users
Is there any more logs you guys would need? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: ipa service vault - cannot find

2019-03-01 Thread Dmitry Perets via FreeIPA-users
Any ideas...? Thanks. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] Re: Set up ipa-client via Ansible

2019-03-01 Thread Ronald Wimmer via FreeIPA-users
On 01.03.19 16:49, Thomas Woerner wrote: Hello Ronald, [...] How old is your clone of the ansible-freeipa repository? ipaclient_extraargs was only used in the beginning. ipaclient_principal is the wrong name. Please update your ansible-freeipa clone. Oh my god. You were completely right.

[Freeipa-users] Re: Set up ipa-client via Ansible

2019-03-01 Thread Thomas Woerner via FreeIPA-users
Hello Ronald, On 3/1/19 11:19 AM, Ronald Wimmer via FreeIPA-users wrote: Hi, I set up relevant ansible files exaclty like described in: https://www.freeipa.org/page/V4/ClientInstallationWithAnsible#Ansible_ipaclient_module The ipaclient role was fetched from here:

[Freeipa-users] Re: FreeIPA web session timeout

2019-03-01 Thread Rob Crittenden via FreeIPA-users
Yuri Krysko via FreeIPA-users wrote: > Hello, > >   > > Could you please advise how to configure FreeIPA web UI user session > timeout? It depends on your version of IPA. For versions < 4.6.0 use session_auth_duration and session_duration_type For versions >= 4.6.0 use kinit_lifetime See

[Freeipa-users] Re: Unable to login via ssh with AD credentials after upgrade FreeIPA

2019-03-01 Thread Morgan Marodin via FreeIPA-users
It's one of our local Domain Controller, in this site there is 2 DC. Could I try to delete and recreate the trust? Or do you have other suggestions? Thanks Il giorno ven 1 mar 2019 alle ore 11:13 Sumit Bose ha scritto: > On Fri, Mar 01, 2019 at 09:07:26AM +0100, Morgan Marodin wrote: > >

[Freeipa-users] Set up ipa-client via Ansible

2019-03-01 Thread Ronald Wimmer via FreeIPA-users
Hi, I set up relevant ansible files exaclty like described in: https://www.freeipa.org/page/V4/ClientInstallationWithAnsible#Ansible_ipaclient_module The ipaclient role was fetched from here: https://github.com/freeipa/ansible-freeipa/tree/master/roles Uninstalling an ipaclient works.

[Freeipa-users] Re: Unable to login via ssh with AD credentials after upgrade FreeIPA

2019-03-01 Thread Sumit Bose via FreeIPA-users
On Fri, Mar 01, 2019 at 09:07:26AM +0100, Morgan Marodin wrote: > Sorry, any news from my logs? sorry for the delay. What kind of server is 192.168.0.15? It looks like the client assumes it is a KDC for IPA.MYDOMAIN.COM but it returns 'Realm not local to KDC' when getting a request for this

[Freeipa-users] Re: Unable to login via ssh with AD credentials after upgrade FreeIPA

2019-03-01 Thread Morgan Marodin via FreeIPA-users
Sorry, any news from my logs? Please let me know, thanks. Morgan Il giorno mar 26 feb 2019 alle ore 11:56 Morgan Marodin ha scritto: > You can find attached a tar.gz file with the logs of the server and the > testing client, captured after done a restart of the *sssd* daemon and a >