[Freeipa-users] Re: debian 8 freeipa-client

2018-01-03 Thread Lee Wiscovitch via FreeIPA-users
Doesn't really address the core issue, but wanted to chime in that we ended up having to manually configure our Debian 8 instances to work with our RHEL IPA servers. We use ansible to automate the entire process, the playbook contents below should be descriptive enough to know what is being

[Freeipa-users] Re: openvpn authenticating to freeipa

2017-12-06 Thread Lee Wiscovitch via FreeIPA-users
We use openvpn's "auth-user-pass-verify" option to call a perl script that queries PAM. I can't provide all of it since it has sensitive/corporate information but essentially OpenVPN will provide the password used during client negotiation as an environment variable, and the perl script sends

[Freeipa-users] Re: Can Load balanced HTTP service use kerberos authentication?

2017-08-11 Thread Lee Wiscovitch via FreeIPA-users
Yup, we do it on several of our web servers...It's actually really cut and dry, that last section of that page you referenced is accurate and it's dead simple. On 08/11/2017 03:01 PM, William Muriithi via FreeIPA-users wrote: Afternoon, I am attempting to add redundancy to a system that we

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-06-14 Thread Lee Wiscovitch via FreeIPA-users
We run almost the exact same setup...Which is sufficient, but not as great as it could be (Basically the password changing issues you've noted). We've also noticed that a single bad login attempt gets counted multiple times on the IPA server, so you can get locked accounts quicker than