[Freeipa-users] issue with group's objectclass attributes

2022-03-31 Thread Kathy Zhu via FreeIPA-users
Hi List, Here is what happened in a timely order. the group "it" was created a long time ago without "groupOfUniqueNames" objectclass. I did following to add "groupOfUniqueNames" objectclass: [root@ipa0 ~]# ipa group-show it --all | grep object objectclass: top, groupofnames,

[Freeipa-users] Re: certs: SAN without othername / NT Principal name

2022-03-31 Thread Fraser Tweedale via FreeIPA-users
On Thu, Mar 31, 2022 at 09:14:39PM +0300, Alexander Bokovoy via FreeIPA-users wrote: > On to, 31 maalis 2022, David Harvey via FreeIPA-users wrote: > > Hi FreeiPA users, > > > > I'm having great fun with a web app that hates the othername/ NT Principal > > name included with certificates

[Freeipa-users] Re: certs: SAN without othername / NT Principal name

2022-03-31 Thread Alexander Bokovoy via FreeIPA-users
On to, 31 maalis 2022, David Harvey via FreeIPA-users wrote: Hi FreeiPA users, I'm having great fun with a web app that hates the othername/ NT Principal name included with certificates generated with ipa-getcert. I've tried several variations but can't omit this part of the subject

[Freeipa-users] certs: SAN without othername / NT Principal name

2022-03-31 Thread David Harvey via FreeIPA-users
Hi FreeiPA users, I'm having great fun with a web app that hates the othername/ NT Principal name included with certificates generated with ipa-getcert. I've tried several variations but can't omit this part of the subject alternative name. Is there any way to do so? Thanks in advance, David

[Freeipa-users] Re: geo replication - ? - concept of

2022-03-31 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, IPA doesn't support read-only replica (see ticket https://pagure.io/freeipa/issue/5569), but has a notion of hidden replica (

[Freeipa-users] geo replication - ? - concept of

2022-03-31 Thread lejeczek via FreeIPA-users
Hi guys. This must have been asked/covered somewhere I think, as it must be trivial concept/question many must have wondered - can IPA, in supported manner with built-in way or not, do 'geo-repliacation' in some sense? What I wonder specifically is - call it a secondary, backup or a mirror

[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread lejeczek via FreeIPA-users
On 31/03/2022 13:40, Florence Blanc-Renaud wrote: Hi, The command /ipa dns-update-system-records/ can be used to add the missing records. If you'd rather add them manually, the command can be run with the /--dry-run/ option and will display the expected records but will not perform any

[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, The command *ipa dns-update-system-records* can be used to add the missing records. If you'd rather add them manually, the command can be run with the *--dry-run* option and will display the expected records but will not perform any update. flo On Thu, Mar 31, 2022 at 2:26 PM Rob Crittenden

[Freeipa-users] Re: ipa-ca DNS record - ?

2022-03-31 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > Hi guys. > > What is 'ipa-ca' for and what should it point to? > Also, should IPA change that record ever? > > Reason I ask - from the docs as I understand - it should point to all CA > servers in the domain, but it not happening. It is a generic name for the

[Freeipa-users] ipa-ca DNS record - ?

2022-03-31 Thread lejeczek via FreeIPA-users
Hi guys. What is 'ipa-ca' for and what should it point to? Also, should IPA change that record ever? Reason I ask - from the docs as I understand - it should point to all CA servers in the domain, but it not happening. many thanks, L. ___

[Freeipa-users] Re: upgrade to FreeIPA 4.7+ from 4.6

2022-03-31 Thread Ivars Strazdins via FreeIPA-users
Thank you Florence, this link was exactly what I was looking for, but somehow I missed it. With kind regards, Ivars > On 30 Mar 2022, at 23:05, Florence Blanc-Renaud wrote: > > Hi, > > the official Red Hat Enterprise Linux documentation recommends to install a > RHEL8 replica (in place