Re: [Freeipa-users] ipa krbtpolicy-mod --maxlife

2012-07-31 Thread Martin Kosek
On 07/30/2012 05:00 PM, george he wrote: Hello all, I'm trying to change the krb ticket life time for myself, so I used ipa krbtpolicy-mod MYUSERNAME --maxlife 36 but then after I do kinit, my new ticket is still going to expire after 24 hours, which is the default ticket life, even

Re: [Freeipa-users] resetting an admin account.

2012-07-31 Thread Martin Kosek
On 07/27/2012 12:48 AM, Steven Jones wrote: I have tried to reset my admin password (admjonesst1) using the admin account toa temp password, So I run a kinit admjonesst1 to reset it to a perm one and I get, [jonesst1@8kxl72s ~]$ kinit admjonesst1 Password for

Re: [Freeipa-users] Very slow kerberos performance after upgrade to IPA 2.2

2012-07-31 Thread Petr Spacek
On 07/30/2012 10:37 PM, Sigbjorn Lie wrote: Hi, I've been having performance issues after I upgraded to RHEL 6.3 / IPA 2.2. I still have a LDAP server having unusual high cpu usage even after it's been removed from the SRV records and is serving almost no clients anymore, but it would seem as

Re: [Freeipa-users] Very slow kerberos performance after upgrade to IPA 2.2

2012-07-31 Thread Sigbjorn Lie
On Tue, July 31, 2012 10:20, Petr Spacek wrote: On 07/30/2012 10:37 PM, Sigbjorn Lie wrote: Hi, I've been having performance issues after I upgraded to RHEL 6.3 / IPA 2.2. I still have a LDAP server having unusual high cpu usage even after it's been removed from the SRV records and is

Re: [Freeipa-users] Very slow kerberos performance after upgrade to IPA 2.2

2012-07-31 Thread Simo Sorce
On Tue, 2012-07-31 at 10:50 +0200, Sigbjorn Lie wrote: On Tue, July 31, 2012 10:20, Petr Spacek wrote: On 07/30/2012 10:37 PM, Sigbjorn Lie wrote: Hi, I've been having performance issues after I upgraded to RHEL 6.3 / IPA 2.2. I still have a LDAP server having unusual high cpu

Re: [Freeipa-users] ipa krbtpolicy-mod --maxlife

2012-07-31 Thread george he
Thank you, Martin. This helps. George From: Martin Kosek mko...@redhat.com To: george he george_...@yahoo.com Cc: freeipa-users@redhat.com freeipa-users@redhat.com Sent: Tuesday, July 31, 2012 3:04 AM Subject: Re: [Freeipa-users] ipa krbtpolicy-mod --maxlife

Re: [Freeipa-users] Very slow kerberos performance after upgrade to IPA 2.2

2012-07-31 Thread Sigbjorn Lie
On 07/31/2012 01:50 PM, Simo Sorce wrote: On Tue, 2012-07-31 at 10:50 +0200, Sigbjorn Lie wrote: On Tue, July 31, 2012 10:20, Petr Spacek wrote: On 07/30/2012 10:37 PM, Sigbjorn Lie wrote: Hi, I've been having performance issues after I upgraded to RHEL 6.3 / IPA 2.2. I still have a LDAP

Re: [Freeipa-users] resetting an admin account.

2012-07-31 Thread Steven Jones
Hi, Both my replicas had stopped replicating, or the ldap db was corrupt...I need to test to see if this issue has gone away or not, but Im bogged down with essential work this morning. :/ regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4

Re: [Freeipa-users] resetting an admin account.

2012-07-31 Thread Steven Jones
As it turns out I need to use it. :/ === [root@vuwunicoipam001 log]# kinit admjonesst1 Password for admjones...@ods.vuw.ac.nz: Password expired. You must change it now. Enter new password: Enter it again: kinit: Password change failed while getting initial credentials

Re: [Freeipa-users] Very slow kerberos performance after upgrade to IPA 2.2

2012-07-31 Thread Simo Sorce
On Tue, 2012-07-31 at 21:08 +0200, Sigbjorn Lie wrote: On 07/31/2012 01:50 PM, Simo Sorce wrote: On Tue, 2012-07-31 at 10:50 +0200, Sigbjorn Lie wrote: On Tue, July 31, 2012 10:20, Petr Spacek wrote: On 07/30/2012 10:37 PM, Sigbjorn Lie wrote: Hi, I've been having performance

Re: [Freeipa-users] resetting an admin account.

2012-07-31 Thread Steven Jones
This appears to be a failure of the password change mechanism to fail say the password is either too short or not complex enough. regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: Martin

[Freeipa-users] IPA Server

2012-07-31 Thread freeipa
Hi All, NOTE: I posted this on the 389 forum, they rightly suggested this is most likely and IPA issue. Spec: Redhat Enterprise Linux 6.3 x64 - ipa-server-2.2.0-16.el6.x86_64 - 389-ds-base-1.2.10.2-18.el6_3.x86_64 - 389-ds-base-libs-1.2.10.2-18.el6_3.x86_64 We had a simple (but quite