[Freeipa-users] Re: Certificates for embeded devices and old equipment.

2020-02-19 Thread Fraser Tweedale via FreeIPA-users
Hi Kendrick, Please give more detail about exactly what you did and what the errors were. FWIW the warning below does not seem relevant to your issue. Thanks, Fraser On Thu, Feb 20, 2020 at 02:01:22AM -, Kendrick . via FreeIPA-users wrote: > I have a older kvm that is requiring an

[Freeipa-users] ipa reverse dns best practices.

2020-02-19 Thread Kendrick . via FreeIPA-users
Should i create a single reverse zone or should there be zones for each subnet? 10.1.1/24 10.1.2/24 10.1.3/26 10.1.3.192/26 etc? 10.1.1-50/ is the likely used ip range with a few /25-26's Thanks Kendrick ___ FreeIPA-users mailing list --

[Freeipa-users] Certificates for embeded devices and old equipment.

2020-02-19 Thread Kendrick . via FreeIPA-users
I have a older kvm that is requiring an unencrypted pem for its cert from freeipa. I have also tried signing a csr from an older ilo product and the cert manager started giving a 404 check your services after trying to import it. any suggestions on how best to aproch these issues. I did

[Freeipa-users] Re: Reissue IPA LDAP cert with SAN

2020-02-19 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > I am trying to get OpenShift to use my FreeIPA installation > (ipa-server-4.6.5-11.el7.centos.4.x86_64) as an identity provider. > OpenShift is refusing to talk to the LDAP server, because its > certificate doesn't contain a subjectAltName. > > So I need to

[Freeipa-users] Reissue IPA LDAP cert with SAN

2020-02-19 Thread Ian Pilcher via FreeIPA-users
I am trying to get OpenShift to use my FreeIPA installation (ipa-server-4.6.5-11.el7.centos.4.x86_64) as an identity provider. OpenShift is refusing to talk to the LDAP server, because its certificate doesn't contain a subjectAltName. So I need to re-request/re-issue the certificate with the

[Freeipa-users] Trust with Azure AD possible in the near future?

2020-02-19 Thread Kimmo Rantala via FreeIPA-users
Hi, I discovered this: https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-create-forest-trust Does this, in theory, mean that in the near future, a trust with Azure AD Domain Services would be possible without much effort from the developers? I thought I would

[Freeipa-users] Re: Can't login AD users on FreeIPA client

2020-02-19 Thread Sumit Bose via FreeIPA-users
On Wed, Feb 19, 2020 at 07:26:51AM -, Michael Solodovnikov via FreeIPA-users wrote: > I have a fresh installed FreeIPA 4.6.5, sssd 1.16.4, krb5 1.15.1-37, samba > 4.9.1-10, on CentOS 7.7.1908, can’t login as AD user. > FreeIPA configured one-way trust AD(win.gtf.kz),AD user have UPN >