[Freeipa-users] LDAP Server stop to response after a period of time

2020-03-07 Thread Lays Dragon via FreeIPA-users
I deployed a two replica FreeIPA Servers,it woks well until this month,it start at the service report the LDAP is Timeout,I try to restart the server,even reinstall two IPA server and maintain the data via replica from another server. And it still happen after several days. The 389ds server

[Freeipa-users] Re: ansible ipa_group failure

2020-03-07 Thread Rafael Jeffman via FreeIPA-users
A flag is simply a boolean (True/False, Yes/No) value. In this case, it marks the group as external, which would accept users from trusted domains, or not. The error message you were receiving means that you try to modify a group with the same configuration the group already has. This case, IMHO,

[Freeipa-users] Re: Ubuntu client: Kerberos works, authenticationdoes not

2020-03-07 Thread Alexander Bokovoy via FreeIPA-users
Do not drop the mailing list, please. On la, 07 maalis 2020, Nick DeMarco wrote: root@drupal:~# getent passwd ndemarco So, SSSD does not see the user. root@drupal:~# sssctl domain-status pchem.pro Unable to get online status [3]: Communication error org.freedesktop.systemd1.NoSuchUnit:

[Freeipa-users] Re: Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Alexander Bokovoy via FreeIPA-users
On la, 07 maalis 2020, Nicholas DeMarco via FreeIPA-users wrote: Hello, I've worked through many issues learning and implementing FreeIPA in my realm. Thanks to many for the helpful direction. One Ubuntu client is not behaving. It joined successfully, but will not authenticate. Kerberos works:

[Freeipa-users] Re: Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Nicholas DeMarco via FreeIPA-users
The clocks are synchronized. Chrony is working. I believe kinit would not succeed if the clocks were off, no? On Sat, Mar 7, 2020, 3:00 PM Kevin Vasko wrote: > Is the clock off? NTP working correctly? > > -Kevin > > On Mar 7, 2020, at 12:55 PM, Nicholas DeMarco > wrote: > >  > Good question.

[Freeipa-users] Re: Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Kevin Vasko via FreeIPA-users
Is the clock off? NTP working correctly? -Kevin > On Mar 7, 2020, at 12:55 PM, Nicholas DeMarco wrote: > >  > Good question. Yes. The user is in the admin group and has access to other > newly joined machines. > >> On Sat, Mar 7, 2020, 1:39 PM Kevin Vasko wrote: >> Does the user have

[Freeipa-users] Re: Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Nicholas DeMarco via FreeIPA-users
Good question. Yes. The user is in the admin group and has access to other newly joined machines. On Sat, Mar 7, 2020, 1:39 PM Kevin Vasko wrote: > Does the user have access to the machine? > > -Kevin > > > On Mar 7, 2020, at 11:33 AM, Nicholas DeMarco via FreeIPA-users < >

[Freeipa-users] Re: Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Kevin Vasko via FreeIPA-users
Does the user have access to the machine? -Kevin > On Mar 7, 2020, at 11:33 AM, Nicholas DeMarco via FreeIPA-users > wrote: > ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Ubuntu client: Kerberos works, authentication does not

2020-03-07 Thread Nicholas DeMarco via FreeIPA-users
Hello, I've worked through many issues learning and implementing FreeIPA in my realm. Thanks to many for the helpful direction. One Ubuntu client is not behaving. It joined successfully, but will not authenticate. Kerberos works: # kinit ndemarco # klist Ticket cache: KEYRING:persistent:0:0

[Freeipa-users] Re: ansible ipa_group failure

2020-03-07 Thread Monkey Bizness via FreeIPA-users
Solved it.So it appears that external: False generates the error.If I omit this parameter, the role works as expected."external" is of type flag in the documentation. What is the specificity of flag type? RegardsMonkey On Fri, 2020-03-06 at 14:45 -0300, Rafael Jeffman via FreeIPA-users wrote: >