[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 28, 2023 at 07:23:58AM +0200 schrieb Francis Augusto Medeiros-Logeay: > > > > On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > > wrote: > > > > Am Fri, Jun 23, 2023 at 09:03:55AM +0200 schrieb Francis Augusto > > Medeiros-Logeay via FreeIPA-users: > >> > >> > >>> On 22

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
Am Tue, Jun 27, 2023 at 02:18:22PM +0200 schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > > > > On 27 Jun 2023, at 14:03, Sumit Bose wrote: > > > > Am Tue, Jun 27, 2023 at 01:32:12PM +0200 schrieb Francis Augusto > > Medeiros-Logeay via FreeIPA-users: > >> Hi Sumit, > >> > >>>

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
> On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > wrote: > > Am Fri, Jun 23, 2023 at 09:03:55AM +0200 schrieb Francis Augusto > Medeiros-Logeay via FreeIPA-users: >> >> >>> On 22 Jun 2023, at 14:48, Rob Crittenden via FreeIPA-users >>> wrote: >>> >>> Francis Augusto

[Freeipa-users] Re: 'ipa-ca-install' conncheck failure on freeIPA

2023-06-27 Thread Arne Verheyden via FreeIPA-users
Hello, Thank you for the answer! I don't know how i overlooked that thread, but he seems to have the exact same error messages. Unfortunately I do not seem to have the same issue causing my problems. I tried running the command `pki securitydomain-show` and it had this output: Domain: IPA

[Freeipa-users] Re: ipa-pkinit-manage failure

2023-06-27 Thread Florence Blanc-Renaud via FreeIPA-users
Hi On Thu, Jun 22, 2023 at 5:27 PM Алексей Иванов via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Greetings, > > I'm trying to configure my replica IPA servers to support PKINIT. > > [root@office-ipa-1 ~]# ipa-pkinit-manage enable > Configuring Kerberos KDC (krb5kdc) >

[Freeipa-users] Re: 'ipa-ca-install' conncheck failure on freeIPA

2023-06-27 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, another user recently had the same issue, see https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/VCARE7OOXWBEB5UXF75AQVFQXNOA43XM/#VFPHENT3PPWTY6W5L42FKQJFQ5GBWKOR We are not sure how the situation got solved, but he cleaned the security domain from

[Freeipa-users] 'ipa-ca-install' conncheck failure on freeIPA

2023-06-27 Thread Arne Verheyden via FreeIPA-users
I'm facing a problem while trying to set up a replica of our main FreeIPA server. We're planning to migrate from an old server to a new one. ipa-replica-install and ipa-dns-install runs without issue but the problem arises when I try to use the ipa-ca-install command. The command fails at the

[Freeipa-users] Re: pki-tomcat fails to start after upgrade

2023-06-27 Thread Tania Hagan via FreeIPA-users
Hi flo, Many thanks, that resolved my issue, I can safely upgrade my servers now. Tania ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
> On 27 Jun 2023, at 14:03, Sumit Bose wrote: > > Am Tue, Jun 27, 2023 at 01:32:12PM +0200 schrieb Francis Augusto > Medeiros-Logeay via FreeIPA-users: >> Hi Sumit, >> >>> On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users >>> wrote: >>> No. The users are the same on both -

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Sumit Bose via FreeIPA-users
Am Tue, Jun 27, 2023 at 01:32:12PM +0200 schrieb Francis Augusto Medeiros-Logeay via FreeIPA-users: > Hi Sumit, > > > On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > > wrote: > > > >> > >> No. The users are the same on both - same uid, gid, etc, but no > >> connection, trust, or

[Freeipa-users] Re: AD certificate authentication against FreeIPA - is that possible?

2023-06-27 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
Hi Sumit, > On 23 Jun 2023, at 10:52, Sumit Bose via FreeIPA-users > wrote: > >> >> No. The users are the same on both - same uid, gid, etc, but no connection, >> trust, or anything. >> The mapping on sssd.conf is this one: >> >> [certmap/mydomain.com/truesso]#Add this

[Freeipa-users] Re: pki-tomcat fails to start after upgrade

2023-06-27 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Mon, Jun 26, 2023 at 4:36 PM Tania Hagan via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi FreeIPA, > > I am currently using FreeIPA version 4.9.10 with 6 ipareaplicas. I went > to upgrade the server to 4.9.11 but the ipa-server-upgrade failed where it > attempted to