[Freeipa-users] IPA Error 4205 attribute idnsAllowTransfer not allowed

2012-07-26 Thread Robert Bowell
Hi, I'm encountering a strange problem.. upon trying to add a new DNS zone the following message is being displayed attribute idnsAllowTransfer not allowed and the DNS entry is not created. Has any one ever encountered such a problem if so what needs to be done to resolve it ? IPA server version

Re: [Freeipa-users] User can't login via ssh from external

2012-07-26 Thread Jakub Hrozek
On Wed, Jul 25, 2012 at 02:38:36PM -0700, Joe Linoff wrote: As Rob says, I think we should take a look at SSSD and system logs. Can you paste or attach the couple of lines that are appended to /var/log/secure during the login attempt? That should give us a clue on whether the SSSD

Re: [Freeipa-users] User can't login via ssh from external

2012-07-26 Thread Jakub Hrozek
On Thu, Jul 26, 2012 at 01:39:12AM +, Steven Jones wrote: I am now getting this Steven, are you saying you can't login even though hbactest passes for your user? Can you then append or paste the last couple of lines of /var/log/secure and the relevat part of the SSSD domain log?

Re: [Freeipa-users] 'Request is a replay'

2012-07-26 Thread Rob Crittenden
Sigbjorn Lie wrote: On Wed, July 25, 2012 09:54, Sigbjorn Lie wrote: On Tue, July 24, 2012 20:29, Simo Sorce wrote: On Tue, 2012-07-24 at 10:22 +0200, Sigbjorn Lie wrote: Hi, I keep seing this error message in our production environment Request is a replay in variuos services using

[Freeipa-users] 3.0 beta1 install on Fedora 17 - No DNS Zones

2012-07-26 Thread Michael Mercier
Hello, I have installed FreeIPA 3.0 beta 1 on Fedora 17, and added a Fedora 17 client. I do not have anything under the Identity - DNS tab (i.e. no DNS zones) I did the following when installing: On the server: [root@ipaserver ~]#ipa-server-install -- oops forgot to include DNS

Re: [Freeipa-users] 'Request is a replay'

2012-07-26 Thread Sigbjorn Lie
On 07/26/2012 02:53 PM, Rob Crittenden wrote: Sigbjorn Lie wrote: On Wed, July 25, 2012 09:54, Sigbjorn Lie wrote: On Tue, July 24, 2012 20:29, Simo Sorce wrote: On Tue, 2012-07-24 at 10:22 +0200, Sigbjorn Lie wrote: Hi, I keep seing this error message in our production environment

Re: [Freeipa-users] 3.0 beta1 install on Fedora 17 - No DNS Zones

2012-07-26 Thread Petr Vobornik
On 07/26/2012 03:22 PM, Michael Mercier wrote: Hello, I have installed FreeIPA 3.0 beta 1 on Fedora 17, and added a Fedora 17 client. I do not have anything under the Identity - DNS tab (i.e. no DNS zones) I did the following when installing: 8-

[Freeipa-users] dirsrv@PKI-IPA.service disappeared

2012-07-26 Thread Tomasz 'Zen' NapieraƂa
Hi, After upgrade from F16 to F17 FreeIPA 2.2.0.1 on secondary servers dirsrv@PKI-IPA.service disappeared. There is an entry for it in systemd, but no config files, etc. /var/log/messages:Jul 24 19:50:56 ldap-XX systemd[1]: dirsrv@PKI-IPA.service failed to run 'start' task: No such file or

Re: [Freeipa-users] User can't login via ssh from external

2012-07-26 Thread Steven Jones
Yes, So, I reset the password and that failed, so I added the user to my desktop group logged in to my desktop with ssh localhost and set the password, then I could log into the client fine. Other users had no problem logging in via the HBAC rule This sort of behaviour is usually a

Re: [Freeipa-users] User can't login via ssh from external

2012-07-26 Thread Jakub Hrozek
On Thu, Jul 26, 2012 at 09:12:35PM +, Steven Jones wrote: Yes, So, I reset the password and that failed, so I added the user to my desktop group logged in to my desktop with ssh localhost and set the password, then I could log into the client fine. Other users had no problem logging

[Freeipa-users] resetting an admin account.

2012-07-26 Thread Steven Jones
I have tried to reset my admin password (admjonesst1) using the admin account toa temp password, So I run a kinit admjonesst1 to reset it to a perm one and I get, [jonesst1@8kxl72s ~]$ kinit admjonesst1 Password for admjones...@ods.vuw.ac.nz: Password expired. You must change it now.

Re: [Freeipa-users] resetting an admin account.

2012-07-26 Thread Steven Jones
If I put the adm account into a user group and ssh in I can set a password, [jonesst1@8kxl72s ~]$ ssh -l admjonesst1 localhost -p22 admjonesst1@localhost's password: Password expired. Change your password now. Creating home directory for admjonesst1. WARNING: Your password has expired. You

[Freeipa-users] unable to logout of IPA

2012-07-26 Thread Steven Jones
When in IPA, when I click on the logout I expect to logout so I can login as another user, === Logged In As: steven jones | Logout === Clicking on logout, and clearing history in Firefox and even closing all instances of Firefox and restarting see me looged back in as my adm

Re: [Freeipa-users] unable to logout of IPA

2012-07-26 Thread Simo Sorce
On Fri, 2012-07-27 at 03:14 +, Steven Jones wrote: When in IPA, when I click on the logout I expect to logout so I can login as another user, === Logged In As: steven jones | Logout === Clicking on logout, and clearing history in Firefox and even closing all instances of

Re: [Freeipa-users] unable to logout of IPA

2012-07-26 Thread Steven Jones
So if i just click on logout, I should just logout as if i kdestroy'd? If so, when I do that why doesnt that cleanup occur? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: Simo Sorce