Re: [Freeipa-users] unable to logout of IPA

2012-09-10 Thread Petr Spacek
On 09/08/2012 02:05 AM, Dmitri Pal wrote: On 07/27/2012 10:30 AM, Petr Spacek wrote: On 07/27/2012 03:28 PM, John Dennis wrote: On 07/27/2012 02:06 AM, Dan Scott wrote: Hi, I'm not sure if this is relevant, but Firefox preserves session cookies across browser restarts. This was discussed on

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Petr Spacek
On 09/08/2012 05:03 PM, Dmitri Pal wrote: On 09/07/2012 04:50 PM, Rob Crittenden wrote: Michael Mercier wrote: On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier

Re: [Freeipa-users] openindiana ldap client

2012-09-10 Thread Dmitri Pal
On 09/09/2012 04:25 PM, Sigbjorn Lie wrote: On 09/07/2012 08:38 PM, Dmitri Pal wrote: On 09/02/2012 12:58 PM, Sigbjorn Lie wrote: On 09/02/2012 04:37 PM, Natxo Asenjo wrote: hi, Recently I have been playing with the zfs for its native nfs4 acl capabilities. I have used openindiana for this.

Re: [Freeipa-users] sudden ipa errors.

2012-09-10 Thread Dmitri Pal
On 08/24/2012 04:43 PM, Rob Crittenden wrote: Nathan Lager wrote: This did not seem to help... What else isn't working? Does the UI work? Do clients on other machines work? Does user lookup still work? rob Was this issue ever resolved? On 08/22/2012 06:02 PM, Rob Crittenden wrote:

Re: [Freeipa-users] IBM Tivoli Identity Manager connector to manage IPA

2012-09-10 Thread Dmitri Pal
On 08/24/2012 02:21 AM, Willem Bos wrote: Hi Sylvian, I'm not familiar with Tivoli but maybe it's able to generate HTTP requests? I recently did a proof-of-concept (with help from this mailing list) to provision IPA with usernames/passwords. It's really a re-write of a post from Adam Young

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Rob Crittenden
Dmitri Pal wrote: On 09/07/2012 04:50 PM, Rob Crittenden wrote: Michael Mercier wrote: On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote: On 09/06/2012 10:40 AM, Michael Mercier wrote: Hello, I have

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Jakub Hrozek
On Mon, Sep 10, 2012 at 09:08:07AM -0400, Rob Crittenden wrote: Dmitri Pal wrote: On 09/07/2012 04:50 PM, Rob Crittenden wrote: Michael Mercier wrote: On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM, Michael Mercier wrote: On 2012-09-07, at 12:14 PM, Dmitri Pal wrote:

Re: [Freeipa-users] Prompting for expired passwords on AIX

2012-09-10 Thread Dmitri Pal
On 08/09/2012 05:28 PM, KodaK wrote: I've kerberized a bunch of AIX machines, and I noticed when I was starting out that AIX allows people to connect that have expired passwords, and does not prompt for changes. 1) does anyone know what I need to do on AIX to make this happen (I don't hold

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Simo Sorce
On Mon, 2012-09-10 at 15:20 +0200, Jakub Hrozek wrote: On Mon, Sep 10, 2012 at 09:08:07AM -0400, Rob Crittenden wrote: Dmitri Pal wrote: On 09/07/2012 04:50 PM, Rob Crittenden wrote: Michael Mercier wrote: On 2012-09-07, at 2:47 PM, Dmitri Pal wrote: On 09/07/2012 12:42 PM,

[Freeipa-users] Announcing FreeIPA v3.0.0 beta 3

2012-09-10 Thread Rob Crittenden
The FreeIPA team is proud to announce version FreeIPA v3.0.0 beta 3. It can be downloaded from http://www.freeipa.org/page/Downloads. A build is available only for Fedora 17 via the freeipa-devel repo on www.freeipa.org: http://freeipa.org/downloads/freeipa-devel.repo . To install in Fedora

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Simo Sorce
On Mon, 2012-09-10 at 16:36 +0200, Sumit Bose wrote: What about defining a task in the SSSD krb5 provider instead of pinging it from the locator plugin. The task can run at a configurable interval or never and checks if the current KDC is available. If not it tries the next until it goes

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Rob Crittenden
Simo Sorce wrote: On Mon, 2012-09-10 at 16:36 +0200, Sumit Bose wrote: What about defining a task in the SSSD krb5 provider instead of pinging it from the locator plugin. The task can run at a configurable interval or never and checks if the current KDC is available. If not it tries the next

Re: [Freeipa-users] errors when one ipa server down

2012-09-10 Thread Simo Sorce
On Mon, 2012-09-10 at 11:11 -0400, Rob Crittenden wrote: Simo Sorce wrote: On Mon, 2012-09-10 at 16:36 +0200, Sumit Bose wrote: What about defining a task in the SSSD krb5 provider instead of pinging it from the locator plugin. The task can run at a configurable interval or never and

[Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Sigbjorn Lie
Hi, I added indexes for automountKey, and automountmapname yesterday in my test environment to see if that would speed the automounters up a bit, and now the automounters does not always work. They manage to look up the map, but not the keys in the map. Restarting the automounter sometimes

[Freeipa-users] KRB5 keytab not always created or updated on RHEL 5

2012-09-10 Thread Sigbjorn Lie
Hi, We are using pam_ldap + pam_krb5 on our RHEL 5 workstations. Sometimes when the user logs in, or unlocks his workstation the users kerberos keytab is not created or updated. Often, just locking the screen with the screensaver and unlocking again creates or updates the keytab file.

Re: [Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Rich Megginson
On 09/10/2012 01:59 PM, Sigbjorn Lie wrote: Hi, I added indexes for automountKey, and automountmapname yesterday in my test environment to see if that would speed the automounters up a bit, and now the automounters does not always work. They manage to look up the map, but not the keys in

Re: [Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Sigbjorn Lie
On 09/10/2012 10:36 PM, Rich Megginson wrote: On 09/10/2012 01:59 PM, Sigbjorn Lie wrote: Hi, I added indexes for automountKey, and automountmapname yesterday in my test environment to see if that would speed the automounters up a bit, and now the automounters does not always work. They

[Freeipa-users] slow ssh

2012-09-10 Thread Steven Jones
Hi, Not sure if this is an IPA issue but Im finding ssh takes long time to login. It looks like ssh is querying IPA for authentication mechanisms?...if so can I simply turn this off? and if so how? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ

Re: [Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Rich Megginson
On 09/10/2012 03:01 PM, Sigbjorn Lie wrote: On 09/10/2012 10:36 PM, Rich Megginson wrote: On 09/10/2012 01:59 PM, Sigbjorn Lie wrote: Hi, I added indexes for automountKey, and automountmapname yesterday in my test environment to see if that would speed the automounters up a bit, and now the

[Freeipa-users] Do you use logrotate?

2012-09-10 Thread Dmitri Pal
Hello, Does anyone use logrotate? If so can you share you configuration and recommendations with us? Is there anything that one should make sure while using logrotate with IPA? For example if the ownership of the log files changes due to wrong logrotate configuration the dis srv might not start.

Re: [Freeipa-users] slow ssh

2012-09-10 Thread Rob Crittenden
Steven Jones wrote: Hi, Not sure if this is an IPA issue but Im finding ssh takes long time to login. It looks like ssh is querying IPA for authentication mechanisms?...if so can I simply turn this off? and if so how? Run in verbose mode to see what it's doing, ssh -vv. It may be trying

Re: [Freeipa-users] Question about migration and scripts variables

2012-09-10 Thread James James
Back from hollidays... I have just trying --user-ignore-attribute=uidnumber,gidnumber, the server says that the posixAccount attribute requires uid and gid number. I will find another solution to solve my problem. James 2012/8/20 Rob Crittenden rcrit...@redhat.com James James wrote: Hi,

Re: [Freeipa-users] slow ssh

2012-09-10 Thread Dmitri Pal
On 09/10/2012 05:16 PM, Steven Jones wrote: Hi, Not sure if this is an IPA issue but Im finding ssh takes long time to login. It looks like ssh is querying IPA for authentication mechanisms?...if so can I simply turn this off? and if so how? Is it the problem on the SSH client or on the

Re: [Freeipa-users] slow ssh

2012-09-10 Thread KodaK
On Mon, Sep 10, 2012 at 4:16 PM, Steven Jones steven.jo...@vuw.ac.nz wrote: Hi, Not sure if this is an IPA issue but Im finding ssh takes long time to login. It looks like ssh is querying IPA for authentication mechanisms?...if so can I simply turn this off? and if so how? Slow SSH is (in

Re: [Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Dmitri Pal
On 09/10/2012 05:27 PM, Rich Megginson wrote: On 09/10/2012 03:01 PM, Sigbjorn Lie wrote: On 09/10/2012 10:36 PM, Rich Megginson wrote: On 09/10/2012 01:59 PM, Sigbjorn Lie wrote: Hi, I added indexes for automountKey, and automountmapname yesterday in my test environment to see if that

Re: [Freeipa-users] slow ssh

2012-09-10 Thread David Björkevik
[email re-sent to list] Hi Steven, Try ssh -o GSSAPIAuthentication=no your.host.name If that doesn't change anything, try adding -v to the command line and see where the delay is happening. /David On 2012-09-10 23:16, Steven Jones wrote: Hi, Not sure if this is an IPA issue but Im

[Freeipa-users] Subject for certificate request in ipa-server-install

2012-09-10 Thread James James
Hi Everybody, I want to change the defaut Certifcate Authority automatically added want you want to make a certificate request. There were a thread about something like ( https://www.redhat.com/archives/freeipa-users/2012-April/msg00021.html) that but I don't know if there is the quick and nice

Re: [Freeipa-users] Adding indexes for the automounter - odd results

2012-09-10 Thread Rich Megginson
On 09/10/2012 04:16 PM, Dmitri Pal wrote: On 09/10/2012 05:27 PM, Rich Megginson wrote: On 09/10/2012 03:01 PM, Sigbjorn Lie wrote: On 09/10/2012 10:36 PM, Rich Megginson wrote: On 09/10/2012 01:59 PM, Sigbjorn Lie wrote: Hi, I added indexes for automountKey, and automountmapname yesterday

Re: [Freeipa-users] slow ssh

2012-09-10 Thread Steven Jones
Hi, It seems to be in my test environment so its probably not a full DNS setup is some of the problem. I didnt select the preview but Ive seen ssh logins that happen without a password so I assume that's at least partially why. regards Steven Jones Technical Specialist - Linux RHCE

Re: [Freeipa-users] Subject for certificate request in ipa-server-install

2012-09-10 Thread Dmitri Pal
On 09/10/2012 06:18 PM, James James wrote: Hi Everybody, I want to change the defaut Certifcate Authority automatically added want you want to make a certificate request. There were a thread about something like (https://www.redhat.com/archives/freeipa-users/2012-April/msg00021.html) that