[Freeipa-users] Re: dogtag-ipa-renew-agent-submit thundering herd

2021-03-26 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > SHORT VERSION: > > I run IPA (4.8) on a low powered CentOS 7 system, and the thundering > herd of dogtag-ipa-renew-agent-submit processes that certmonger > spawns at startup appears to be causing issues. > > I'm looking for some way to limit the number of

[Freeipa-users] dogtag-ipa-renew-agent-submit thundering herd

2021-03-26 Thread Ian Pilcher via FreeIPA-users
SHORT VERSION: I run IPA (4.8) on a low powered CentOS 7 system, and the thundering herd of dogtag-ipa-renew-agent-submit processes that certmonger spawns at startup appears to be causing issues. I'm looking for some way to limit the number of concurrent requests that certmonger spawns at

[Freeipa-users] Re: ipa-server-install w/o password on command line?

2021-03-26 Thread Russell Jones via FreeIPA-users
Use a bash script to do so. ipa-server-install . -p ${PASSWD} On Thu, Mar 25, 2021 at 4:49 AM Dominik Vogt via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > We want to generate the initial passwords at random. Is there a > non-interactive method of telling

[Freeipa-users] Re: Password expirations

2021-03-26 Thread Alexander Bokovoy via FreeIPA-users
On pe, 26 maalis 2021, Stephen Berg, Code 7309 via FreeIPA-users wrote: Is there a way to use an ldapsearch to get the current value in the password expiration field?  I can quickly get a list of users but haven't been able to find how to list password expiration for a particular user using

[Freeipa-users] Password expirations

2021-03-26 Thread Stephen Berg, Code 7309 via FreeIPA-users
Is there a way to use an ldapsearch to get the current value in the password expiration field?  I can quickly get a list of users but haven't been able to find how to list password expiration for a particular user using ldapsearch.  It shows up from "ipa user-show --all" so I thought I'd be

[Freeipa-users] Re: Dogtag certificates somehow got expired

2021-03-26 Thread Florence Blanc-Renaud via FreeIPA-users
On 3/25/21 2:20 PM, Rogge, Henning via FreeIPA-users wrote: Hi, we are running a FreeIPA server instance (with an externally supplied and still valid CA certificate) in our company network (on Fedora): # rpm -qa *ipa-server freeipa-server-4.8.3-1.fc31.x86_64 ​ Somewhen in the last months