[Freeipa-users] Re: FreeIPA/IdM versions on RHEL8

2019-12-06 Thread Christophe TREFOIS via FreeIPA-users
There is difference between ipa-client and ipa-server. > On 6 Dec 2019, at 18:32, Vinícius Ferrão via FreeIPA-users > wrote: > > Hi Christian > >> On 6 Dec 2019, at 14:04, Christian Heimes via FreeIPA-users >> > > wrote: >> >> On 06/12/2019

[Freeipa-users] Re: FreeIPA/IdM versions on RHEL8

2019-12-06 Thread Vinícius Ferrão via FreeIPA-users
Hi Christian > On 6 Dec 2019, at 14:04, Christian Heimes via FreeIPA-users > wrote: > > On 06/12/2019 17.48, Vinícius Ferrão via FreeIPA-users wrote: >> Hello, this is probably a comercial question and not a technical one, >> but I’m curious about it. >> >> As today RHEL8 ships with FreeIPA

[Freeipa-users] Re: FreeIPA/IdM versions on RHEL8

2019-12-06 Thread Christian Heimes via FreeIPA-users
On 06/12/2019 17.48, Vinícius Ferrão via FreeIPA-users wrote: > Hello, this is probably a comercial question and not a technical one, > but I’m curious about it. > > As today RHEL8 ships with FreeIPA (IdM) 4.7. The latest release is 4.8 > with some interesting features. RHEL 8.0 has 4.7.1. RHEL

[Freeipa-users] FreeIPA/IdM versions on RHEL8

2019-12-06 Thread Vinícius Ferrão via FreeIPA-users
Hello, this is probably a comercial question and not a technical one, but I’m curious about it. As today RHEL8 ships with FreeIPA (IdM) 4.7. The latest release is 4.8 with some interesting features. Since RHEL8 is still fresh, there’s any rebase to a higher version on the map? I see that IdM

[Freeipa-users] Re: No Login on GUI

2019-12-06 Thread Christophe TREFOIS via FreeIPA-users
Have you checked certificates ? https://www.freeipa.org/page/Certmonger#Get_a_list_of_currently_tracked_certificates Have you check Kerberos logs, Dirsv logs, Tomcat logs?

[Freeipa-users] Re: No Login on GUI

2019-12-06 Thread Christian Reiss via FreeIPA-users
Hey Angus, thanks for replying. Allow me to reply inline: On 06/12/2019 16:00, Angus Clarke wrote: Have you checked your times are in sync within 5 minutes? Yes. And it's monitored. Have you checked DNS is working for all node entries between all nodes? Yes. And it's monitored. Even PTR

[Freeipa-users] Re: FreeIPA / SSSD and IPV6

2019-12-06 Thread TomK via FreeIPA-users
On 12/6/2019 10:51 AM, TomK wrote: On 12/4/2019 11:16 AM, Alexander Bokovoy via FreeIPA-users wrote: On ke, 04 joulu 2019, Stephen John Smoogen via FreeIPA-users wrote: On Tue, 3 Dec 2019 at 21:43, TomK via FreeIPA-users wrote: Hey All, Does FreeIPA fully support IPV6 or are there corner

[Freeipa-users] Re: FreeIPA and IPV6

2019-12-06 Thread TomK via FreeIPA-users
On 12/4/2019 11:16 AM, Alexander Bokovoy via FreeIPA-users wrote: On ke, 04 joulu 2019, Stephen John Smoogen via FreeIPA-users wrote: On Tue, 3 Dec 2019 at 21:43, TomK via FreeIPA-users wrote: Hey All, Does FreeIPA fully support IPV6 or are there corner cases and limitations that could make

[Freeipa-users] Re: [EXTERNAL] Re: Anyone using FreeIPA/IdM and MicroFocus Network Automation ?

2019-12-06 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
I agree with your response: user search base="cn=users,cn=accounts,dc=lab,dc=PROJECT,dc=EXAMPLE,dc=ORG" group search base = " cn=nnmi_access,cn=groups,cn=accounts, dc=PROJECT,dc=EXAMPLE,dc=ORG" AND change the roleBase from member to memberOf This is based on the results of tinkering with

[Freeipa-users] Re: [EXTERNAL] Re: Anyone using FreeIPA/IdM and MicroFocus Network Automation ?

2019-12-06 Thread Rob Crittenden via FreeIPA-users
White, Daniel E. (GSFC-770.0)[NICS] wrote: > We set roleContextDN to cn=nnmi-access > >   > > And it still barfs, but I found stuff in the access log file: (redacted > a bit) > >   > > [06/Dec/2019:12:49:18.055641820 +] conn=2805 fd=110 slot=110 > connection from NNMi-Server to IdM-Server

[Freeipa-users] Re: [EXTERNAL] Re: Anyone using FreeIPA/IdM and MicroFocus Network Automation ?

2019-12-06 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
We set roleContextDN to cn=nnmi-access And it still barfs, but I found stuff in the access log file: (redacted a bit) [06/Dec/2019:12:49:18.055641820 +] conn=2805 fd=110 slot=110 connection from NNMi-Server to IdM-Server [06/Dec/2019:12:49:18.055983514 +] conn=2805 op=0 BIND dn=""

[Freeipa-users] Re: In-place upgrade from RHEL 7 to RHEL 8

2019-12-06 Thread Rob Crittenden via FreeIPA-users
Ronald Wimmer via FreeIPA-users wrote: > > https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/installing_identity_management/migrate-7-to-8_migrating > states that the CA-Master should be replaced. > > How would you proceed if there were multiple servers that needed an