Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Rich Megginson
Please keep replies on list Shan Kumaraswamy wrote: Rich, Does a reverse DNS lookup on the IP address return that hostname? -Yes Is Active Directory configured to use/listen to SSL? -Yes, Active Directory Cert Auth installed and exported the and verifityed. Does the cert db

Re: [Freeipa-users] Unable to connect to IPA server: File Not Found

2010-03-09 Thread root
Turned out to be webservice getting reconfigured out from under me. We didn't know that the management interface website was necessary for the command-line management tools. This raises a couple more questions: 1) Is the free-ipa website needed only for management (i.e.: changes) to the IPA

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Rich Megginson
Shan Kumaraswamy wrote: When I try to run this command I am getting this error: [r...@sbttipa001 ~]# /usr/lib64/mozldap/ldapsearch -h sbtaddc001.bmitest.com http://sbtaddc001.bmitest.com -D CN=administrator,CN=users,DC=bmitest,DC=com -w secretpw -s base -b objectclass=* ldap_simple_bind:

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Shan Kumaraswamy
Rich, Your mean the AD Administrator password or IPA admin password? On Tue, Mar 9, 2010 at 6:32 PM, Rich Megginson rmegg...@redhat.com wrote: Shan Kumaraswamy wrote: When I try to run this command I am getting this error: [r...@sbttipa001 ~]# /usr/lib64/mozldap/ldapsearch -h

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Rich Megginson
Shan Kumaraswamy wrote: Rich, Your mean the AD Administrator password or IPA admin password? AD I'm trying to find out why IPA cannot make a connection to AD. So the hostname should be the AD hostname, and the -D (binddn) should be the DN of the user that IPA uses to bind to AD, and the

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Shan Kumaraswamy
Rich again some errors: [r...@sbttipa001 ~]# /usr/lib64/mozldap/ldapsearch -h sbtaddc001.bmitest.com-D CN=administrator,CN=users,DC=bmitest,DC=com -w Str1ve2XL -s base -b objectclass=* ldap_simple_bind: Strong authentication required ldap_simple_bind: additional info: 2028: LdapErr:

Re: [Freeipa-users] Needed_Preauth Issue

2010-03-09 Thread Simo Sorce
On Mon, 08 Mar 2010 18:15:05 -0600 David Christensen da...@adurotec.com wrote: I have two servers that I have installed the ipa-client on, both of these servers are configured the same way however one is providing single sign on, the other is not and instead prompts for a password when a

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Rich Megginson
Shan Kumaraswamy wrote: Yes I can get the output when I ran this step: Command: /usr/lib64/mozldap/ldapsearch -ZZ -P /etc/dirsrv/slapd-BMITEST-COM/cert8.db -h sbtaddc001.bmitest.com http://sbtaddc001.bmitest.com -D CN=administrator,CN=users,DC=bmitest,DC=com -s base -b objectclass=*

Re: [Freeipa-users] AD Sync Error

2010-03-09 Thread Rich Megginson
Shan Kumaraswamy wrote: Yes I can able to get the output using the port, but without password. /usr/lib64/mozldap/ldapsearch -Z -P /etc/dirsrv/slapd-BMITEST-COM/cert8.db -h sbtaddc001.bmitest.com http://sbtaddc001.bmitest.com -p 636 -D CN=administrator,CN=users,DC=bmitest,DC=com -s base -b