[Freeipa-users] Ansible tasks for certprofiles and ca-acls

2020-04-21 Thread pleusmann--- via FreeIPA-users
Hi, I'd like to issue wildcard-certificates following this guide: https://www.freeipa.org/page/Howto/Wildcard_certificates Is there any way to manage certprofiles and ca-acls using ansible? Cheers, Philipp ___ FreeIPA-users mailing list --

[Freeipa-users] Re: EL7 Upgrades

2020-04-21 Thread Angus Clarke via FreeIPA-users
Other issues have kept me from returning to this topic and I haven't yet made any further progress, so I'll just say thanks now for the advice - thanks a lot! Regards Angus From: Rob Crittenden Sent: Tuesday, April 7, 2020 5:15:41 PM To: FreeIPA users list Cc:

[Freeipa-users] Replication issue with CSN generator

2020-04-21 Thread Morgan Marodin via FreeIPA-users
Hi. Into my environment I have two IPA server, replicating each other. They are both 7.6 OS systems, ipa-server RPM version is 4.6.4-10.0.1.el7_6.2.x86_64. The first server installed was srv01 (many years ago), then I installed the replica into srv02 (like a year later the 1st node). When I had

[Freeipa-users] Re: Sudo command not working

2020-04-21 Thread Faraz Younus via FreeIPA-users
It worked with ALL command given to administrator group On Mon, Apr 20, 2020 at 10:45 PM Elhamsadat Azarian via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi > i had this problem too. i studied all of these pages but it doesnt work > and i had to stop working with IPA > > On

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-21 Thread Simo Sorce via FreeIPA-users
On Tue, 2020-04-21 at 12:25 +, Andreas Bulling via FreeIPA-users wrote: > The admin login problem I just managed to fix - missing trailing slash in a > permanent redirect from http to https in Apache. > > But the ISSUE/NEEDED_PREAUTH messages I'd still like to figure out if these > are not

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-21 Thread Andreas Bulling via FreeIPA-users
The admin login problem I just managed to fix - missing trailing slash in a permanent redirect from http to https in Apache. But the ISSUE/NEEDED_PREAUTH messages I'd still like to figure out if these are not normal. Thanks! ___ FreeIPA-users mailing

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-21 Thread Andreas Bulling via FreeIPA-users
Thanks for your help. I ended up uninstalling and reinstalling all clients and saw the new CA certificates during the process. But the ISSUE/NEEDED_PREAUTH messages remain - is that normal? Any idea how I can fix my other problem, that of not being able to login to the admin interface? In the

[Freeipa-users] Re: SERVFAIL for one hostname

2020-04-21 Thread Tiemen Ruiten via FreeIPA-users
On Tue, Apr 21, 2020 at 1:10 PM Tiemen Ruiten wrote: > Hello, > > On Tue, Apr 21, 2020 at 12:46 PM François Cami wrote: > >> Hi, >> >> On Tue, Apr 21, 2020 at 12:19 PM Tiemen Ruiten via FreeIPA-users >> wrote: >> > >> > Hello, >> > >> > Since a few days ago, we're having issues with resolution

[Freeipa-users] Re: SERVFAIL for one hostname

2020-04-21 Thread Tiemen Ruiten via FreeIPA-users
Hello, On Tue, Apr 21, 2020 at 12:46 PM François Cami wrote: > Hi, > > On Tue, Apr 21, 2020 at 12:19 PM Tiemen Ruiten via FreeIPA-users > wrote: > > > > Hello, > > > > Since a few days ago, we're having issues with resolution of this > hostname: > > > >

[Freeipa-users] Re: SERVFAIL for one hostname

2020-04-21 Thread François Cami via FreeIPA-users
Hi, On Tue, Apr 21, 2020 at 12:19 PM Tiemen Ruiten via FreeIPA-users wrote: > > Hello, > > Since a few days ago, we're having issues with resolution of this hostname: > > download.wisselkoersenvoorjeadministratie.nl > > Our FreeIPA DNS servers return SERVFAIL for that particular hostname. What's

[Freeipa-users] SERVFAIL for one hostname

2020-04-21 Thread Tiemen Ruiten via FreeIPA-users
Hello, Since a few days ago, we're having issues with resolution of this hostname: download.wisselkoersenvoorjeadministratie.nl Our FreeIPA DNS servers return SERVFAIL for that particular hostname. What's funny, after I do a (successful) lookup directly at one of the configured forwarders,

[Freeipa-users] Re: replica install fails

2020-04-21 Thread Alexandru David via FreeIPA-users
correction ipa replica hostname is ipareplica01.linux.example.com. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: Problems after replacing SSL certificates

2020-04-21 Thread Florence Blanc-Renaud via FreeIPA-users
On 4/20/20 8:39 PM, Andreas Bulling via FreeIPA-users wrote: Andreas Bulling via FreeIPA-users wrote: You have a chicken and egg problem. When replacing your certs on an existing infrastructure you first have to add your new CA certs using ipa-cacert-manage, then run ipa-certupdate on all