[Freeipa-users] Re: OK_AS_DELEGATE by default

2020-10-01 Thread Rafael Jeffman via FreeIPA-users
On Thu, Oct 1, 2020 at 12:59 PM Ronald Wimmer via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > > On 01.10.20 17:46, Alexander Bokovoy wrote: > > On to, 01 loka 2020, Ronald Wimmer via FreeIPA-users wrote: > >> Is it possible to set this flag by default for all new IPA hosts? > >

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Kees Bakker via FreeIPA-users
On 01-10-2020 20:33, Rob Crittenden wrote: > Kees Bakker via FreeIPA-users wrote: >> Can I safely do the following? >> >> ipa-getcert resubmit -i 20181127141739 >> ipa-getcert resubmit -i 20181127141749 >> ipa-getcert resubmit -i 20181127141750 >> ipa-getcert resubmit -i 20181127141751 > No. Only

[Freeipa-users] Re: SSL/TLS Server Support for TLDv1.0 on port(s) other than 443

2020-10-01 Thread Ian Pilcher via FreeIPA-users
On 10/1/20 12:42 PM, Auerbach, Steven via FreeIPA-users wrote: What is the proper way to change the overall openssl configuration to set the ssl_min toTLSv1.2? https://directory.fedoraproject.org/docs/389ds/howto/howto-ssl.html You can see your current settings with: ldapsearch -x -D

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Kees Bakker via FreeIPA-users
On 01-10-2020 20:33, Rob Crittenden wrote: > Kees Bakker via FreeIPA-users wrote: >> Can I safely do the following? >> >> ipa-getcert resubmit -i 20181127141739 >> ipa-getcert resubmit -i 20181127141749 >> ipa-getcert resubmit -i 20181127141750 >> ipa-getcert resubmit -i 20181127141751 > No. Only

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Rob Crittenden via FreeIPA-users
Kees Bakker via FreeIPA-users wrote: > Can I safely do the following? > > ipa-getcert resubmit -i 20181127141739 > ipa-getcert resubmit -i 20181127141749 > ipa-getcert resubmit -i 20181127141750 > ipa-getcert resubmit -i 20181127141751 No. Only the renewal master should attempt renewing the

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Kees Bakker via FreeIPA-users
Can I safely do the following? ipa-getcert resubmit -i 20181127141739 ipa-getcert resubmit -i 20181127141749 ipa-getcert resubmit -i 20181127141750 ipa-getcert resubmit -i 20181127141751 On 01-10-2020 17:36, Kees Bakker via FreeIPA-users wrote: > EXTERNAL E-MAIL > > On the

[Freeipa-users] SSL/TLS Server Support for TLDv1.0 on port(s) other than 443

2020-10-01 Thread Auerbach, Steven via FreeIPA-users
I have been able to force NSSProtocol to TLSv1.2 on the web service of this IPA server in the nss.conf. But I am receiving a Threat Assessment Hit (SecureWorks) that TLSv1.0 is open on port 636/TCP. I attempted to manually edit the /etc/dirsrv/slapd-/dse.ldif file, but once I made that change

[Freeipa-users] Re: OK_AS_DELEGATE by default

2020-10-01 Thread Alexander Bokovoy via FreeIPA-users
On to, 01 loka 2020, Ronald Wimmer via FreeIPA-users wrote: On 01.10.20 17:46, Alexander Bokovoy wrote: On to, 01 loka 2020, Ronald Wimmer via FreeIPA-users wrote: Is it possible to set this flag by default for all new IPA hosts? I checked the code and there is no way to set it by default.

[Freeipa-users] Re: OK_AS_DELEGATE by default

2020-10-01 Thread Ronald Wimmer via FreeIPA-users
On 01.10.20 17:46, Alexander Bokovoy wrote: On to, 01 loka 2020, Ronald Wimmer via FreeIPA-users wrote: Is it possible to set this flag by default for all new IPA hosts? I checked the code and there is no way to set it by default. You have to explicitly specify --ok-as-delegate=true when

[Freeipa-users] Re: OK_AS_DELEGATE by default

2020-10-01 Thread Alexander Bokovoy via FreeIPA-users
On to, 01 loka 2020, Ronald Wimmer via FreeIPA-users wrote: Is it possible to set this flag by default for all new IPA hosts? I checked the code and there is no way to set it by default. You have to explicitly specify --ok-as-delegate=true when adding hosts and services. -- / Alexander

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Kees Bakker via FreeIPA-users
On the non-renewal masters there are 4 certificates that show "ca-error: Invalid cookie: u''" Request ID '20181127141739':     ca-error: Invalid cookie: u''     subject: CN=IPA RA,O=GHS.NL     expires: 2020-10-26 20:15:48 UTC Request ID '20181127141749':     ca-error: Invalid cookie: u''    

[Freeipa-users] Re: yum update problem

2020-10-01 Thread Kees Bakker via FreeIPA-users
This now happened to me too. The solution in this thread was to copy /var/lib/ipa/ra-agent.* to the failing system. After that I was able to restart (ipactl restart). What remains a mystery is **why** this happened. In my case, we have three CA masters, one is the CA renewal master (of

[Freeipa-users] Re: [offlist] Re: Re: Modify LDAP/HTTP to add alternative names

2020-10-01 Thread Simo Sorce via FreeIPA-users
On Thu, 2020-10-01 at 11:46 +1000, Fraser Tweedale wrote: > On Wed, Sep 30, 2020 at 09:43:29AM -0400, Simo Sorce wrote: > > On Wed, 2020-09-30 at 16:04 +1000, Fraser Tweedale wrote: > > > On Tue, Sep 29, 2020 at 09:44:16AM -0400, Simo Sorce via FreeIPA-users > > > wrote: > > > > On Tue,

[Freeipa-users] OK_AS_DELEGATE by default

2020-10-01 Thread Ronald Wimmer via FreeIPA-users
Is it possible to set this flag by default for all new IPA hosts? Cheers, Ronald ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: