[Freeipa-users] Re: Is IPA's DNS working as a recursive DNS server for internal + external requests

2019-01-24 Thread 74cmonty via FreeIPA-users
Hm... I think my question was not clear, therefore I'll try to repeat it with a better description. Therefore I simply take an example from Pi-hole directly: "Pi-hole as All-Around DNS Solution" (https://docs.pi-hole.net/guides/unbound/) This means that basically this procedure should work with

[Freeipa-users] Re: Login WebUI fails

2019-01-23 Thread 74cmonty via FreeIPA-users
Do you recommend to file a bug? Can you share some instructions how to do this? I'm not familiar with the process on Fedora. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Is IPA's DNS working as a recursive DNS server for internal + external requests

2019-01-22 Thread 74cmonty via FreeIPA-users
Hi, to my knowledge IPA's DNS server is Bind. And this server is working as recursive DNS for internal domains. Question: Can I use this DNS server for recursive DNS request of external domains, too? If yes, how? My intention is to send client request to Pi-hole first for DNS filtering; Pi-hole

[Freeipa-users] Re: Login WebUI fails

2019-01-14 Thread 74cmonty via FreeIPA-users
Hi Robbie, let me share some additional information on this issue before filing a bug. I checked the log files for errors but didn't detect anything. Then I verified if any service was failing, but everything was running. After this I tried to restart ipa.service and this failed with an error

[Freeipa-users] Re: Login WebUI fails

2019-01-11 Thread 74cmonty via FreeIPA-users
Solved. /var/log was 100% full. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List

[Freeipa-users] Login WebUI fails

2019-01-11 Thread 74cmonty via FreeIPA-users
Hi, starting today I cannot login to WebUI anymore. This is not a password authentication issue because I can switch to user "admin" in console. When I enter 'kinit list' as root I get this response: kinit: general error (see e-text) for Initial credentials will be fetched. The same error is

[Freeipa-users] Re: Recommendation for adding client with 2 NICs (laptop with LAN & WLAN)

2019-01-09 Thread 74cmonty via FreeIPA-users
Well, could you please share your recommendation for this request, means how would you add / maintain a laptop with 2 NICs? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: How to restrict access for users to specific hosts

2019-01-07 Thread 74cmonty via FreeIPA-users
THX I have found this howto guide: https://www.freeipa.org/page/Howto/HBAC_and_allow_all ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of

[Freeipa-users] How to restrict access for users to specific hosts

2019-01-05 Thread 74cmonty via FreeIPA-users
Hi, how can I restrict access for users to specific hosts? Please advise. THX ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Recommendation for adding client with 2 NICs (laptop with LAN & WLAN)

2019-01-05 Thread 74cmonty via FreeIPA-users
Hi, adding a client in WebUI is simple. However, what do you recommend when adding a client with 2 NICs, e.g. laptop? These devices have typically different NICs for LAN and WLAN. And consequently there are 2 MAC addresses and 2 IPs. But there's only 1 hostname (FQHN). Any advise is appreciated.

[Freeipa-users] Re: Service named-pkcs11.service on replica reports error: Failed to get initial credentials (TGT) using principal 'DNS/ipa-replica.example.com' and keytab 'FILE:/etc/named.keytab' (Ge

2019-01-04 Thread 74cmonty via FreeIPA-users
I started setup from scratch. There are no issues observed as of now. I cannot reproduce the issue since the re-installation. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Adding Linux client in WebUI reports error: The host was added but the DNS update failed with: DNS reverse zone 168.192.in-addr.arpa. for IP address 192.168.1.47 is not managed by

2019-01-02 Thread 74cmonty via FreeIPA-users
OK. I created 2 reverse zones: 1.168.192.in-addr.arpa 100.168.192.in-addr.arpa Then I continued and created a host via WebUI. The host is displayed with correct hostname, however there's an error displayed: The host was added but the DNS update failed with: All nameservers failed to answer the

[Freeipa-users] Re: Adding Linux client in WebUI reports error: The host was added but the DNS update failed with: DNS reverse zone 168.192.in-addr.arpa. for IP address 192.168.1.47 is not managed by

2019-01-02 Thread 74cmonty via FreeIPA-users
No, I didn't create a reverse zone. I'm not sure if the definition of DNS forwarding in FreeIPA makes sense. Actually I consider to use Pi-hole as single DNS for specific network 192.168.1.0/24 only and forward any requests to FreeIPA. Would this make sense? And how could I create this reverse

[Freeipa-users] Service named-pkcs11.service on replica reports error: Failed to get initial credentials (TGT) using principal 'DNS/ipa-replica.example.com' and keytab 'FILE:/etc/named.keytab' (Generi

2018-12-29 Thread 74cmonty via FreeIPA-users
Hi, when I start service `named-pkcs11.service` on replica server I get these error messages: ``` Dez 29 17:33:28 ipa-replica.example.com named-pkcs11[3936]: Failed to get initial credentials (TGT) using principal 'DNS/ipa-replica.example.com' and keytab 'FILE:/etc/named.keytab' (Generic error

[Freeipa-users] Service named-pkcs11.service on master fails: Process 3946 (named-pkcs11) of user 25 dumped core

2018-12-29 Thread 74cmonty via FreeIPA-users
Hi, starting service `named-pkcs11.service` fails with a core dump: ``` Dez 29 17:32:25 ipa-master.example.com systemd-coredump[2901]: Process 2895 (named-pkcs11) of user 25 dumped core. Stack trace of thread 2897:

[Freeipa-users] Re: FreeIPA UID vs. Linux UID - what's the difference

2018-12-28 Thread 74cmonty via FreeIPA-users
OK. I have a follow-up question. This is related to system group id. On Debian, users belonging to group sudo get root permission. On Arch Linux, users belonging to group wheel get root permission. Should I maintain the same groups sudo and wheel in FreeIPA with the relevant GUI? THX

[Freeipa-users] FreeIPA UID vs. Linux UID - what's the difference

2018-12-28 Thread 74cmonty via FreeIPA-users
Hi, could you please explain the difference of FreeIPA UID vs. Linux UID? When I create a user in FreeIPA the UID is this: 122721 But in any Linux the first user created has UID: 1000 Should I align UIDs in FreeIPA to the Linux UID? If yes, does the same apply to GID? Or should I keep the

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hi Flo, I have defined the IP of my router as DNS: [root@ipa-master ~]# ipa dnsserver-show Servername: ipa-master.biszumbitterenen.de Servername: ipa-master.biszumbitterenen.de SOA mname override: ipa-master.biszumbitterenen.de. Forwarders: 192.168.100.1 Forward policy: only The same IP

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hi Flo, thanks for your reply. I decided to start replica setup from scratch. This means I executed this command on master: ipa-replica-manage del ipa-replica.biszumbitterenen.de Then I restored the replica server to a previous state, installed freeipa-packages 4.7.2 (and its dependencies).

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hello Flo, I successfully installed FreeIPA 4.7.2 packages on replica server: ``` [root@ipa-replica ~]# rpm -q freeipa-server freeipa-client ipa-server ipa-client 3 89-ds-base pki-ca krb5-server

[Freeipa-users] Re: Announcing FreeIPA v4.7.2

2018-12-07 Thread 74cmonty via FreeIPA-users
Hi, can you please advise how to upgrade to 4.7.2? I'm running version 4.7.0 [root@ipa-replica ~]# rpm -q freeipa-server freeipa-client ipa-server ipa-client 389-ds-base pki-ca krb5-server freeipa-server-4.7.0-3.fc29.x86_64 freeipa-client-4.7.0-3.fc29.x86_64 Das Paket ipa-server ist nicht

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-07 Thread 74cmonty via FreeIPA-users
Hello Flo, I've decided to follow your advise. This means I will install another CA instance on the replica server. However I would prefer to upgrade FreeIPA to version 4.7.2 before. Unfortunately I failed on this task. I've executed ipa-server-upgrade and this process finished successfully

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-06 Thread 74cmonty via FreeIPA-users
Hi Florence, thank you for this detailed analysis. I fully support your conclusion. Before you replied to this ticket I have already opened a bug report: https://pagure.io/freeipa/issue/7795 Question: Is there any workaround to temporarily fix this issue and complete the setup of replica

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-06 Thread 74cmonty via FreeIPA-users
Well, then I will repeat the context... After completing FreeIPA master (vm200; 192.168.100.200) installation I started setup of replica (vm201; 192.168.100.201). This means I first enrolled the replica server as a client successfully and then executed this command: ipa-replica-install The

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-05 Thread 74cmonty via FreeIPA-users
I was instructed to delete the existing cert before executing ipa-pkinit-manage enable. And I have provided the output of getcert in an earlier response. I was told that this cert is incomplete/incorrect. ___ FreeIPA-users mailing list --

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-05 Thread 74cmonty via FreeIPA-users
I have installed freeipa-server-common=4.7.0, so I don't understand the relation to an issue that should be fixed with 4.6.0. I have no restarted command ipa-pkinit-manage enable after opening port 8443 on both, master and replica server. In my opinion the root cause is different. According to

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-03 Thread 74cmonty via FreeIPA-users
This is true, the connect error is clear. However, I don't understand why there's a connection error to the replica-server? Please note that command ipa-pkinit-manage enable is executed on the replica-server, means the connection fails to itself. And there's no instruction to open port 8443 on

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-02 Thread 74cmonty via FreeIPA-users
Hi, this is the output that looks good to me... but I'm not the expert. [root@ipa-replica ~]# getcert list -f /var/kerberos/krb5kdc/kdc.crt Number of certificates and requests being tracked: 4. Request ID '20181202164246': status: MONITORING stuck: no key pair storage:

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-02 Thread 74cmonty via FreeIPA-users
Actually I executed these commands before you replied on the replica server: [root@ipa-replica ~]# ipa-pkinit-manage status PKINIT is disabled The ipa-pkinit-manage command was successful [root@ipa-replica ~]# ipa-pkinit-manage enable Configuring Kerberos KDC (krb5kdc) [1/1]: installing X509

[Freeipa-users] Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-02 Thread 74cmonty via FreeIPA-users
Hi, after completing master installation I started setup of replica. This means I first enrolled the replica server as a client and then executed this command: ipa-replica-install The installation log reports this error: Full PKINIT configuration did not succeed The setup will only install bits

[Freeipa-users] Re: How to add host with subdomain local..de

2018-11-27 Thread 74cmonty via FreeIPA-users
Hi Florence, I intend to define a subdomain for each network, e.g. DMZ = dmz..de (10.0.0.0/24) -> VLAN LAN = local..de (192.168.1.0/24) SHZ = smz..de (Smart Home Network) (10.0.10.0/28) -> VLAN Does this make sense to you? Or is this an overkill? THX Thomas

[Freeipa-users] How to add host with subdomain local..de

2018-11-18 Thread 74cmonty via FreeIPA-users
Hi, I completed installation using the recommended FQHN ipa..de of FreeIPA server. How can I add a client host configured with sub-domain local..de? THX ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an

[Freeipa-users] Connect to WebUI fails: ERR_CONNECTION_TIMED_OUT

2018-11-18 Thread 74cmonty via FreeIPA-users
Hi, I have completed installation on Fedora Server 29 w/o issues. Before I tried WebUI I ensured that administrative ticket is valid. [root@ipa ~]# ipa user-show admin Anmeldename: admin Nachname: Administrator Home-Verzeichnis: /home/admin Anmeldeshell: /bin/bash Principal alias:

[Freeipa-users] Error installation "freeipa-letsencrypt": certutil: could not authenticate to token NSS Certificate DB.: SEC_ERROR_IO: An I/O error occurred during security authorization.

2018-11-03 Thread 74cmonty via FreeIPA-users
Hi, I have executed script setup.sh from package "freeipa-letsencrypt". The installation finished with this error message: ipaplatform.redhat.tasks: INFO: Systemwide CA database updated. ipalib.backend: DEBUG: Destroyed connection context.rpcclient_140228802354200 ipapython.admintool: INFO: The

[Freeipa-users] Re: No httpd service listening on TCP4

2018-11-03 Thread 74cmonty via FreeIPA-users
Solved ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines:

[Freeipa-users] No httpd service listening on TCP4

2018-11-02 Thread 74cmonty via FreeIPA-users
Hi, I just completed installation with Fedora 29 in KVM. The installation finished w/o errors. Setup complete Next steps: 1. You must make sure these network ports are open: TCP Ports: * 80, 443: HTTP/HTTPS * 389, 636: LDAP/LDAPS

[Freeipa-users] FreeIPA - it it the right solution for me?

2018-11-02 Thread 74cmonty via FreeIPA-users
Hi, I consider to deploy FreeIPA in my home network. In this network I run several servers and workstations with both Linux and Windows. In addition I have setup some Webservices running in containers (LXC). I have only one public IP and manage the (privately hosted) Webservices with a reverse