[Freeipa-users] Re: different security policy for login(password+otp) and screenlock (password only) for workstation

2019-03-29 Thread Jelle de Jong via FreeIPA-users
cess authsufficientpam_sss.so forward_pass The one that gets messy is x2go, because it uses ssh, and can’t be detected by a service test. On Mar 19, 2019, at 2:16 PM, Jelle de Jong via FreeIPA-users wrote: Hello everybody, Thank you all for replying. On 18/03/2019 20:44, Jakub Hrozek w

[Freeipa-users] Re: different security policy for login(password+otp) and screenlock (password only) for workstation

2019-03-26 Thread Jelle de Jong via FreeIPA-users
, 2019, at 2:16 PM, Jelle de Jong via FreeIPA-users wrote: Hello everybody, Thank you all for replying. On 18/03/2019 20:44, Jakub Hrozek wrote: On Mon, Mar 18, 2019 at 06:14:16PM +0200, Alexander Bokovoy wrote: On ma, 18 maalis 2019, Jelle de Jong via FreeIPA-users wrote: Hello everybody,

[Freeipa-users] change default freeipa settings for password change/expire and otp timeout

2019-03-14 Thread Jelle de Jong via FreeIPA-users
Hello everybody, First thank you for the great software and this support list! I got a few questions: version that I am using: ipa-server-4.6.4-10.el7.centos.2.x86_64 1) I need to be able to set the initial password and not have it changed or expired after I add the user. I need users to be

[Freeipa-users] different security policy for login(password+otp) and screenlock (password only) for workstation

2019-03-18 Thread Jelle de Jong via FreeIPA-users
Hello everybody, I am looking for a way to have different authentication policy for a freeia-client logout and screenlock on linux workstations. When a user logs in I want to use my password+otp (this is working)! When a user locks it screen I want to be able unlock it with only the

[Freeipa-users] Re: different security policy for login(password+otp) and screenlock (password only) for workstation

2019-03-19 Thread Jelle de Jong via FreeIPA-users
Hello everybody, Thank you all for replying. On 18/03/2019 20:44, Jakub Hrozek wrote: On Mon, Mar 18, 2019 at 06:14:16PM +0200, Alexander Bokovoy wrote: On ma, 18 maalis 2019, Jelle de Jong via FreeIPA-users wrote: Hello everybody, I am looking for a way to have different authentication

[Freeipa-users] Re: different security policy for login(password+otp) and screenlock (password only) for workstation

2019-03-21 Thread Jelle de Jong via FreeIPA-users
Community question, as I am trying to think of solutions and can use some advice. On 19/03/2019 19:16, Jelle de Jong wrote: On 18/03/2019 20:44, Jakub Hrozek wrote: On Mon, Mar 18, 2019 at 06:14:16PM +0200, Alexander Bokovoy wrote: On ma, 18 maalis 2019, Jelle de Jong via FreeIPA-users wrote

[Freeipa-users] Re: change default freeipa settings for password change/expire and otp timeout

2019-03-22 Thread Jelle de Jong via FreeIPA-users
Hello everybody, On 14/03/2019 15:08, Jelle de Jong via FreeIPA-users wrote: Hello everybody, First thank you for the great software and this support list! I got a few questions: version that I am using: ipa-server-4.6.4-10.el7.centos.2.x86_64 1) I need to be able to set the initial

[Freeipa-users] Re: change default freeipa settings for password change/expire and otp timeout

2019-03-22 Thread Jelle de Jong via FreeIPA-users
Hi Dmitry, On 15/03/2019 12:42, Dmitry Perets via FreeIPA-users wrote: Hi, I saw another solution for your problem - you can define a user as "passSyncManager". Then that particular user will be able to set passwords for other users without having them immediately expired. This is especially

[Freeipa-users] free-ipa-client with otp (sssd) on linux laptop how to keep working on different networks.

2019-05-02 Thread Jelle de Jong via FreeIPA-users
Hello everybody, What would be the way to configure a linux laptop free-ipa-client (sssd) with freeipa users with otp (2fa) passwords, to keep working on other networks then the local lan of the freeipa server? Is there a sssd config option that can be used or port forwardings on firewalls?

[Freeipa-users] how to create system user account, hide ipa data from users, have a default group list

2020-11-25 Thread Jelle de Jong via FreeIPA-users
Hello everybody, 1. How can I make a system user like the admin account only without admin rights, but still available with id and getent tools. I need machine account for a holds a kerberos ticket. A normal user shows up everywhere through LDAP, the admin user does not but is still available

[Freeipa-users] how to create system user account and have it receive a kerberos ticket on boot

2020-12-30 Thread Jelle de Jong via FreeIPA-users
Hello everybody, 1. How can I get machine that is joined as ipa-client recieve a kerberos ticket for a specific user without storing a password or having to manually login? I want to replace this, manual systemd tricker that I currently run: ExecStart=/usr/bin/bash -c "echo -n "secretpass" |

[Freeipa-users] centos8 freeipa not starting anymore

2021-07-01 Thread Jelle de Jong via FreeIPA-users
Hello everybody, All my centos8 freeipa instances at different sites where down this morning. https://pastebin.com/vVfwrNqL I tried disabling firewalld, selinux, downgrade java version, can not get it to work. Did anyone encountered this issue and found a workaround? Kind regards, Jelle

[Freeipa-users] Re: centos8 freeipa not starting anymore

2021-07-01 Thread Jelle de Jong via FreeIPA-users
On 7/1/21 10:41 AM, Jelle de Jong via FreeIPA-users wrote: Hello everybody, All my centos8 freeipa instances at different sites where down this morning. https://pastebin.com/vVfwrNqL I tried disabling firewalld, selinux, downgrade java version, can not get it to work. Did anyone

[Freeipa-users] /var/log/krb5kdc.log server not found, how to do a kinit or krb5.conf that freeipa likes better

2021-03-06 Thread Jelle de Jong via FreeIPA-users
Hello everybody, Can someone help how to do a kinit or change my krb5.conf so freeipa does not create "Server not found in Kerberos database" warnings flooding the logs? After freeipa crashed because root / was 100% filled due to /var/log/krb5kdc.* total size being more then 30GB I found

[Freeipa-users] Re: ipa user-add-cert and org.freedesktop.sssd.infopipe.Users.FindByCertificate into ps12 and mozilla certificate manager

2023-06-01 Thread Jelle de Jong via FreeIPA-users
On 6/1/23 15:18, Sumit Bose via FreeIPA-users wrote: Am Thu, Jun 01, 2023 at 02:18:40PM +0200 schrieb Jelle de Jong via FreeIPA-users: Hello everybody, I am looking for a way to digitally sign documents by end-users within an organisation. Hi, correct me if I'm wrong, but to my

[Freeipa-users] ipa user-add-cert and org.freedesktop.sssd.infopipe.Users.FindByCertificate into ps12 and mozilla certificate manager

2023-06-01 Thread Jelle de Jong via FreeIPA-users
Hello everybody, I am looking for a way to digitally sign documents by end-users within an organisation. I can add a certificate to every user with our IPA user-add-cert system. I can use SSSD clients to pull up te certificate. org.freedesktop.sssd.infopipe.Users.FindByCertificate Is there