Re: [Freeipa-users] [Freeipa-devel] FreeIPA beta1: SELinux prohibits memcached

2012-03-20 Thread Martin Kosek
On Tue, 2012-03-20 at 12:44 +0100, Marco Pizzoli wrote: Hi guys, I don't know if you already know this, but in my logs I can find this: Mar 20 12:14:47 freeipa01 setroubleshoot: SELinux is preventing /usr/bin/memcached from create access on the sock_file ipa_memcached. For complete

Re: [Freeipa-users] [Freeipa-devel] FreeIPA beta1: SELinux prohibits memcached

2012-03-20 Thread Martin Kosek
On Tue, 2012-03-20 at 13:14 +0100, Marco Pizzoli wrote: Hi Martin, On Tue, Mar 20, 2012 at 1:02 PM, Martin Kosek mko...@redhat.com wrote: On Tue, 2012-03-20 at 12:44 +0100, Marco Pizzoli wrote: Hi guys, I don't know if you already know this, but in my logs I can

Re: [Freeipa-users] Problem in ipa migrate-ds procedure

2012-03-20 Thread Marco Pizzoli
On Tue, Mar 20, 2012 at 1:32 PM, Dmitri Pal d...@redhat.com wrote: ** On 03/20/2012 05:19 AM, Marco Pizzoli wrote: On Tue, Mar 20, 2012 at 12:14 AM, Dmitri Pal d...@redhat.com wrote: On 03/19/2012 06:54 PM, Marco Pizzoli wrote: On Mon, Mar 19, 2012 at 8:31 PM, Rob Crittenden

Re: [Freeipa-users] Problem in ipa migrate-ds procedure

2012-03-20 Thread Dmitri Pal
On 03/20/2012 09:09 AM, Marco Pizzoli wrote: On Tue, Mar 20, 2012 at 1:32 PM, Dmitri Pal d...@redhat.com mailto:d...@redhat.com wrote: On 03/20/2012 05:19 AM, Marco Pizzoli wrote: On Tue, Mar 20, 2012 at 12:14 AM, Dmitri Pal d...@redhat.com mailto:d...@redhat.com wrote:

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Jimmy
When I try to export the db I get this: /var/lib/dirsrv/scripts-ABC-XYZ/db2ldif -n ipaca -a /dbexport/ipaca-output.ldif Exported ldif file: /dbexport/ipaca-output.ldif [03/Mar/2012:17:27:25 +] - ERROR: Could not find backend 'ipaca' When I start IPA as it is now these are the logs I get:

[Freeipa-users] Error during ipa-replica-install

2012-03-20 Thread Marco Pizzoli
Hi guys, I'm running this version of FreeIPA: [root@freeipa03 ~]# rpm -qa|grep freeipa freeipa-server-selinux-2.1.90.rc1-0.fc16.x86_64 freeipa-server-2.1.90.rc1-0.fc16.x86_64 freeipa-admintools-2.1.90.rc1-0.fc16.x86_64 freeipa-client-2.1.90.rc1-0.fc16.x86_64

Re: [Freeipa-users] groups migration problem

2012-03-20 Thread Rob Crittenden
Maciej Sawicki wrote: Hi, I haven't manage to migrate ldap groups (in free ipa panel I see that users are migrated) #ipa migrate-ds ldap://192.168.1.125:389 --bind-dn=cn=admin,dc=polidea,dc=pl --group-container='ou=groups,dc=polidea,dc=pl' #ipa: ERROR: Container for group not found My old ldap

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Jimmy
Here are the http logs: http://fpaste.org/j7kN/ On Tue, Mar 20, 2012 at 3:16 PM, Jimmy g17ji...@gmail.com wrote: I was able to do this: /usr/lib64/dirsrv/slapd-PKI-IPA/db2ldif -n ipaca -a /dbexport/ipaca-output.ldif /usr/lib64/dirsrv/slapd-PKI-IPA/ldif2db -n ipaca -i

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Jimmy
ipa cert-show 1== Certificate: MIIDhTCCAm2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAyMRAwDgYDVQQKEwdQREgu Q1NQMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTEwOTEzMTU0 MTE4WhcNMTkwOTEzMTU0MTE4WjAyMRAwDgYDVQQKEwdQREguQ1NQMR4wHAYDVQQD ExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAw

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Rich Megginson
On 03/20/2012 01:16 PM, Jimmy wrote: I was able to do this: /usr/lib64/dirsrv/slapd-PKI-IPA/db2ldif -n ipaca -a /dbexport/ipaca-output.ldif /usr/lib64/dirsrv/slapd-PKI-IPA/ldif2db -n ipaca -i /dbexport/ipaca-output.ldif ok - let's make sure this step worked - any errors in

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Rob Crittenden
Jimmy wrote: ipa cert-show 1== Certificate: MIIDhTCCAm2gAwIBAgIBATANBgkqhkiG9w0BAQsFADAyMRAwDgYDVQQKEwdQREgu Q1NQMR4wHAYDVQQDExVDZXJ0aWZpY2F0ZSBBdXRob3JpdHkwHhcNMTEwOTEzMTU0 MTE4WhcNMTkwOTEzMTU0MTE4WjAyMRAwDgYDVQQKEwdQREguQ1NQMR4wHAYDVQQD

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Jimmy
I restarted certmonger and it seems to be working. Is there some way to change the renewal interval so we can simulate this in the lab? I'd like to see it go through a number of renewals to make sure we don't keep having this problem. ___ Freeipa-users

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Nalin Dahyabhai
On Tue, Mar 20, 2012 at 04:10:19PM -0400, Jimmy wrote: I restarted certmonger and it seems to be working. Is there some way to change the renewal interval so we can simulate this in the lab? I'd like to see it go through a number of renewals to make sure we don't keep having this problem.

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Rob Crittenden
Jimmy wrote: I restarted certmonger and it seems to be working. Is there some way to change the renewal interval so we can simulate this in the lab? I'd like to see it go through a number of renewals to make sure we don't keep having this problem. Glad you are up and running again. You can

Re: [Freeipa-users] (no subject)

2012-03-20 Thread Jimmy
Cool thanks for the awesome help, y'all. On Tue, Mar 20, 2012 at 5:20 PM, Rob Crittenden rcrit...@redhat.com wrote: Jimmy wrote: I restarted certmonger and it seems to be working. Is there some way to change the renewal interval so we can simulate this in the lab? I'd like to see it go