[Freeipa-users] Re: Session Recording on RHEL/OL8

2019-07-05 Thread Justin Stephenson via FreeIPA-users
Based on the error: Failed setting locale from environment variables Tlog is attempting to read and set the environment locale settings calling the glibc function setlocale() but not finding a valid locale. This error occurs after checking the LC_ALL and LANG environment variables, is it possible

[Freeipa-users] Re: Session Recording on RHEL/OL8

2019-07-02 Thread Justin Stephenson via FreeIPA-users
Hello, If you do not intend to use the cockpit web interface then you only need to install the 'tlog' package for session recording configuration. RHEL8 documentation for configuring session recording is below: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/recordin

[Freeipa-users] Re: AD accounts unavailable from clients

2018-01-22 Thread Justin Stephenson via FreeIPA-users
If the trust was added successfully and IPA servers were promoted to Trust Controllers or Trust Agents with ipa-adtrust-install then you followed the necessary setup steps. The 's2n' log messages are client-specific requests made to the IPA server for AD trust user and group information. These

[Freeipa-users] Re: cross-forest trust, client system cannot id AD users.

2017-10-19 Thread Justin Stephenson via FreeIPA-users
On 10/19/2017 02:14 PM, Jakub Hrozek via FreeIPA-users wrote: On Tue, Oct 17, 2017 at 02:21:07PM -0700, Steve Dainard via FreeIPA-users wrote: Hello, I've installed a 60 day 'self supported' trial of red hat idm on rhel7. I've created a cross-forest trust with an AD domain (2012R2) which alread

[Freeipa-users] Re: HBAC vs Sudo

2017-08-08 Thread Justin Stephenson via FreeIPA-users
On 08/08/2017 12:02 PM, Steve Weeks via FreeIPA-users wrote: We are running FreeIPA 4.4. Even though sudo is listed as one of the services in the HBAC rule, it seems like only the Sudo rules are what really controls sudo. Sudo ignores what is in the HBAC rules. Is this expected behavior? It

[Freeipa-users] Re: AD trust setup woes

2017-08-02 Thread Justin Stephenson via FreeIPA-users
On 08/02/2017 07:40 AM, Igor Sever via FreeIPA-users wrote: There is no gidNumber attribute on AD group objects. If I want to apply posix attributes directly in AD, then I don't need FreeIPA, do I... https://blogs.technet.microsoft.com/activedirectoryua/2016/02/09/identity-management-for-unix-id