[Freeipa-users] Re: Directory manager password best practices

2019-04-17 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher wrote: > On 4/17/19 9:45 AM, Rob Crittenden wrote: >> https://www.freeipa.org/page/Howto/Change_Directory_Manager_Password > > That page says: > >  The following procedure is only applicable to FreeIPA 3.2.1 or older. >  Since FreeIPA 3.2.2 (and ticket #3594), the procedure is

[Freeipa-users] Re: Directory manager password best practices

2019-04-17 Thread Ian Pilcher via FreeIPA-users
On 4/17/19 9:45 AM, Rob Crittenden wrote: https://www.freeipa.org/page/Howto/Change_Directory_Manager_Password That page says: The following procedure is only applicable to FreeIPA 3.2.1 or older. Since FreeIPA 3.2.2 (and ticket #3594), the procedure is automated as a part of preparing a

[Freeipa-users] Re: Directory manager password best practices

2019-04-17 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > On 4/16/19 10:14 PM, Rob Crittenden wrote: >> It isn't a huge deal to change the DM password but in practice you'd >> want to do it on all masters (not replicated) so while not the end of >> the world it can be at best annoying. > > We'll only have a single

[Freeipa-users] Re: Directory manager password best practices

2019-04-17 Thread Ian Pilcher via FreeIPA-users
On 4/16/19 10:14 PM, Rob Crittenden wrote: It isn't a huge deal to change the DM password but in practice you'd want to do it on all masters (not replicated) so while not the end of the world it can be at best annoying. We'll only have a single master, so that doesn't sound too bad. Though

[Freeipa-users] Re: Directory manager password best practices

2019-04-16 Thread Rob Crittenden via FreeIPA-users
Ian Pilcher via FreeIPA-users wrote: > I am setting up a new IPA instance to provide DNS and CA services in a > team lab. I have to decide what to use for the Directory Manager > password — our standard, not very secure root password or something > else, which no one will ever remember. > > Any