[Freeipa-users] Re: using SSH with password authentication when NIS is still running with FreeIPA

2021-02-08 Thread Sumit Bose via FreeIPA-users
On Mon, Feb 08, 2021 at 04:42:31PM -0500, Robert Kudyba via FreeIPA-users wrote: > We have freeipa-server-4.8.10-6.fc33 running on top of NIS and I'm trying > to determine why ssh -k from any client is hanging and not even connecting. > Does sssd need to be configured as in this 2013 training

[Freeipa-users] using SSH with password authentication when NIS is still running with FreeIPA

2021-02-08 Thread Robert Kudyba via FreeIPA-users
We have freeipa-server-4.8.10-6.fc33 running on top of NIS and I'm trying to determine why ssh -k from any client is hanging and not even connecting. Does sssd need to be configured as in this 2013 training document? https://www.freeipa.org/images/1/10/Freeipa30_SSSD_OpenSSH_integration.pdf The

[Freeipa-users] Re: Help: Renew Expired IPA Certificates & Fix Broken pki-tomcatd

2021-02-08 Thread SRM via FreeIPA-users
Ignore this thread, double posted thread. Execuse my ignorance, first time user of mailing list. The original thread is here https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/Y5ROHIC56BLVPCHQLSWC4WRMMSM2I2H5/ ___

[Freeipa-users] Re: Help: Renew Expired IPA Certificates & Fix Broken pki-tomcatd

2021-02-08 Thread SRM via FreeIPA-users
Not Sure why the body text is attached as html file. Here is what I wanted to post. I see some one else opened another thread with similar issue, but the error messages are different so I'm going ahead & seeking help on a new thread. I've inherited a FreeIPA installation from somebody used

[Freeipa-users] How To Renew Expired Certificates & pki-tomcatd not starting

2021-02-08 Thread SRM via FreeIPA-users
I see some one else opened another thread with similar issue, but the error messages are different so I'm going ahead & seeking help on a new thread. I've inherited a FreeIPA installation from somebody used among 5 physical servers with one FreeIPA server (everything CA etc on it) while other 4

[Freeipa-users] Re: IPA certs expired, pki-tomcatd fails to start

2021-02-08 Thread Manuel Gujo via FreeIPA-users
Hi, I re-sync the date to today and ran ipa-cert-fix but it returns an error [root@ipa1 ~]# ipa-cert-fix WARNING ipa-cert-fix is intended for recovery when expired certificates prevent the normal operation of IPA. It should ONLY be used in such scenarios, and backup

[Freeipa-users] Re: IPA certs expired, pki-tomcatd fails to start

2021-02-08 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/8/21 2:03 PM, Manuel Gujo via FreeIPA-users wrote: Hi Florence, thanks for the answer it's a single IPA server, VERSION: 4.6.8, API_VERSION: 2.237 Hi, The CA is self-signed and still valid, and you are lucky because this ipa version already provides a new tool called ipa-cert-fix that

[Freeipa-users] Re: IPA certs expired, pki-tomcatd fails to start

2021-02-08 Thread Manuel Gujo via FreeIPA-users
Hi Florence, thanks for the answer it's a single IPA server, VERSION: 4.6.8, API_VERSION: 2.237 I kinit as admin without problems, then: [root@ipa1 ~]# ipa server-role-find ipa: ERROR: cannot connect to 'https://ipa1.itec.lab/ipa/json': Internal Server Error [root@ipa1 ~]# rpm -qa *ipa-server

[Freeipa-users] Re: IPA certs expired, pki-tomcatd fails to start

2021-02-08 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/8/21 11:59 AM, Manuel Gugliucci via FreeIPA-users wrote: Hello, I'm running a freeipa server over a cloudera cluster, on 2020-12-31 all the certs expired and did not renew by itself. After I set the system date before the expiration date, I tried ipa-cacert-renew but returns an error

[Freeipa-users] IPA certs expired, pki-tomcatd fails to start

2021-02-08 Thread Manuel Gugliucci via FreeIPA-users
Hello, I'm running a freeipa server over a cloudera cluster, on 2020-12-31 all the certs expired and did not renew by itself. After I set the system date before the expiration date, I tried ipa-cacert-renew but returns an error saying that ca cert are not managed by certmonger so I did a