Re: [Freeipa-users] DNS logs - named.run

2012-06-01 Thread Jimmy
Our DNS topology is a very simple, out of the box, FreeIPA config. Our systems are configured to run independently at completely disparate locations, so there is very little to the topology besides forward and reverse zones for the networks served at each site. There are no slaves, and this is the

Re: [Freeipa-users] DNS logs - named.run

2012-06-01 Thread Petr Spacek
On 05/31/2012 07:24 PM, Jimmy wrote: This message repeats numerous times per minute: zone myzone.info/IN: zone serial (2012150501) unchanged. zone may fail to transfer to slaves. I even went into the admin page and changed the serial manually to see if I could get past the message but it just c

Re: [Freeipa-users] Authentication Failure from Java - LoginException PREAUTH_FAILED

2012-06-01 Thread Darran Lofthouse
On 06/01/2012 03:49 PM, Rob Crittenden wrote: Darran Lofthouse wrote: On 05/31/2012 03:17 PM, Simo Sorce wrote: Darran, I think you may need to download "Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files 7" See here: http://www.oracle.com/technetwork/java/javase/dow

Re: [Freeipa-users] Authentication Failure from Java - LoginException PREAUTH_FAILED

2012-06-01 Thread Rob Crittenden
Darran Lofthouse wrote: On 05/31/2012 03:17 PM, Simo Sorce wrote: Darran, I think you may need to download "Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files 7" See here: http://www.oracle.com/technetwork/java/javase/downloads/jce-7-download-432124.html Apparently

Re: [Freeipa-users] ipa-client-install hangs on ipa-getkeytab - Fixed!!

2012-06-01 Thread Rob Crittenden
free...@noboost.org wrote: On Wed, May 30, 2012 at 12:01:21PM -0400, Rob Crittenden wrote: free...@noboost.org wrote: On Tue, May 29, 2012 at 09:00:43AM +0200, Martin Kosek wrote: On Mon, 2012-05-28 at 10:21 +0400, free...@noboost.org wrote: Hi All, This one has me stumped! For some reason m

[Freeipa-users] more HBAC service groups?

2012-06-01 Thread Rob Crittenden
We have an open ticket, https://fedorahosted.org/freeipa/ticket/1712, requesting to add more HBAC services groups by default to IPA. We're looking for suggestions on groups of services to add. We currently provide just two groups, ftp and sudo. thanks rob

Re: [Freeipa-users] IPA 2.2 on Fedora 17

2012-06-01 Thread Petr Spacek
On 05/31/2012 03:33 PM, Chris Evich wrote: On 05/30/2012 03:14 PM, Rob Crittenden wrote: The current 389-ds-base package in Fedora 17 is known to not work with IPA. This is any of the 1.2.11.x builds through 1.2.11.4. The only solution we have right now is to downgrade to 1.2.10.4. This is unfo

Re: [Freeipa-users] token/swipe pass deployments with IPA

2012-06-01 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 31/05/12 23:54, Dmitri Pal wrote: > On 05/31/2012 03:03 PM, Dale Macartney wrote: > > >> Evening all >> >> http://www.youtube.com/watch?v=uvfkj8V6ylM >> >> This video was floating around Google plus a few days ago which is >> brilliant to show of