Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Jakub Hrozek
On Mon, Jul 23, 2012 at 06:22:55PM -0400, Rob Crittenden wrote: > Joe Linoff wrote: > >Hi Steve: > > > >Thank you for your suggestions. > > > > > In the gui you can do a hbac test of the rule. > > > >I ran the hbactest rule testing from the command line using “ipa > >hbactest …”. It showed that the

Re: [Freeipa-users] winsync msi

2012-07-23 Thread Steven Jones
Hi, No not specific developers but some sort of statement of ownership from RedHat I suppose. So they are I assume looking for some sort of confidence that it wont trash AD and if I install it and it does trash our AD some liability. regards Steven Jones Technical Specialist - Linux RHCE Vic

Re: [Freeipa-users] winsync msi

2012-07-23 Thread Rich Megginson
On 07/23/2012 05:38 PM, Steven Jones wrote: Hi, For the winsync agreement my Windows and security teams want to know its details, eg who wrote it, Red Hat - do you need to know the names of the developers? it is Microsoft certified etc. Not that I know of - how would one go about doing th

[Freeipa-users] winsync msi

2012-07-23 Thread Steven Jones
Hi, For the winsync agreement my Windows and security teams want to know its details, eg who wrote it, it is Microsoft certified etc. Where will I find such info? All I have is http://port389.org/wiki/Download Which doesn't tell me much. regards Steven Jones Technical Specialist - Linux

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Joe Linoff
Hi Rob: > The issue is if the UIDS are < 1000 they are treated as local in sssd. Ahh, of course, thanks. I never assigned any UIDs < 1000 (or less than 1 for that matter). > It could be that sssd cached something and wouldn't let it go, too. If you can reproduce > this it is probably worthw

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Joe Linoff
Hi Rob: Thank you for helping. > Are you performing a login between steps 3 and 5? Otherwise all that does is add > a member/memberof and then remove it. I don't see how this would affect anything. Hmmm, good point. I think that I was probably doing a "kinit" between steps 3 and 5 which would

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Rob Crittenden
Joe Linoff wrote: Hi Steve: Thank you for your suggestions. > In the gui you can do a hbac test of the rule. I ran the hbactest rule testing from the command line using “ipa hbactest …”. It showed that the rules were correct. Do you think that the GUI might provide a different result? No, t

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Steven Jones
as below. regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: Joe Linoff [jlin...@tabula.com] Sent: Tuesday, 24 July 2012 10:04 a.m. To: Steven Jones Cc: freeipa-users@redhat.com; Joe Linoff Subject

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Rob Crittenden
Joe Linoff wrote: Hi Folks: I managed to get the user working doing the following (all from the CLI): 1.Deleted the user (ipa user-del new-user) 2.Re-added the user 3.Add the user to administrator groups. 4.Changed/set the password. 5.Removed the administrator privileges. 6.Attempt report

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Joe Linoff
Hi Steve: Thank you for your suggestions. > In the gui you can do a hbac test of the rule. I ran the hbactest rule testing from the command line using "ipa hbactest ...". It showed that the rules were correct. Do you think that the GUI might provide a different result? > Also wh

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Joe Linoff
Hi Folks: I managed to get the user working doing the following (all from the CLI): 1. Deleted the user (ipa user-del new-user) 2. Re-added the user 3. Add the user to administrator groups. 4. Changed/set the password. 5. Removed the administrator privilege

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Steven Jones
Hi, In the gui you can do a hbac test of the rule. Also what are the UIDS? IPA provided 32bit ones? or your own? I'd suggest re-setting that user's password and get them to login and reset the password, that works for me, it was a sign of bad/failed replication in my system I think (now fixe

Re: [Freeipa-users] User can't login via ssh from external

2012-07-23 Thread Joe Linoff
Hi Stephen and Dmitri: Thank you for the sshd GSSAPI configuration suggestion. I tried it this morning but it didn't work. That particular user is still not able to login. What is even more interesting is that I created a user with the identical setup and the new user worked (i.e., they were ab

Re: [Freeipa-users] Openldap to IPA migration confusion

2012-07-23 Thread Rob Crittenden
Qing Chang wrote: On 20/07/2012 5:14 PM, Rob Crittenden wrote: Qing Chang wrote: Greetings, Migration from OpedLDAP to IPA creates a pair of subtrees for both users and groups: compat and accounts, use groups as an example: dn: cn=acdp,cn=groups,cn=compat,dc=sri,dc=utoronto,dc=ca dn: cn=acdp

Re: [Freeipa-users] Openldap to IPA migration confusion

2012-07-23 Thread Qing Chang
On 20/07/2012 5:14 PM, Rob Crittenden wrote: Qing Chang wrote: Greetings, Migration from OpedLDAP to IPA creates a pair of subtrees for both users and groups: compat and accounts, use groups as an example: dn: cn=acdp,cn=groups,cn=compat,dc=sri,dc=utoronto,dc=ca dn: cn=acdp,cn=groups,cn=accou

Re: [Freeipa-users] servers going out of sync

2012-07-23 Thread Petr Spacek
On 07/23/2012 04:49 PM, KodaK wrote: On Mon, Jul 23, 2012 at 9:42 AM, KodaK wrote: Alright, this is pretty bad. My servers keep going out of sync. I have four replicas, slpidml01 through 04. I only figure it out when weird things start happening. Is there a log somewhere that I can parse tha

Re: [Freeipa-users] servers going out of sync

2012-07-23 Thread KodaK
On Mon, Jul 23, 2012 at 9:42 AM, KodaK wrote: > Alright, this is pretty bad. > > My servers keep going out of sync. I have four replicas, slpidml01 > through 04. I only figure it out when weird things start happening. > Is there a log somewhere that I can parse that says that updates > aren't ge

[Freeipa-users] servers going out of sync

2012-07-23 Thread KodaK
Alright, this is pretty bad. My servers keep going out of sync. I have four replicas, slpidml01 through 04. I only figure it out when weird things start happening. Is there a log somewhere that I can parse that says that updates aren't getting sent out? What are the types of things that can cau

[Freeipa-users] FreeIPA, rkhunter & "unknown rootkit"

2012-07-23 Thread Anthony Messina
I have installed freeipa-server-2.2.0-1.fc17.x86_64 and it's running well. I have also installed rkhunter-1.4.0-1.fc17.noarch on the IPA server and each morning I receive the following report from rkhunter. I imagine/hope that these are not actual rootkits and was wondering if anyone knew of a wa