Re: [Freeipa-users] Migrate from SunONE DS5.2 - UnicodeDecodeError

2012-09-21 Thread Pieter Baele
On Thu, Sep 20, 2012 at 3:49 PM, Martin Kosek mko...@redhat.com wrote: Since an Internal error was returned, there should at least be a traceback in /var/log/httpd/error_log. This should help us narrow down the root cause of this issue. Martin Oops, I only sent to Rob. So that's

Re: [Freeipa-users] ipa host-add having both an IPv4 and an IPv6 address

2012-09-21 Thread Martin Kosek
On 09/20/2012 10:35 PM, Sigbjorn Lie wrote: Hi, I see that I can add hosts with either an IPv4 or an IPv6 address when using ipa host-add --ip-address=. Is there a way to add a host specifying both an IPv4 and an IPv6 address at the same time? Adding the --ip-address option twice

[Freeipa-users] Do we need ipa-client-update script?

2012-09-21 Thread Petr Spacek
Hello users, we have a question for client machine administrators: On 09/21/2012 10:12 AM, Martin Kosek wrote: snip ..., that it may be useful to implement a script like ipa-client-update which would be capable of updating client information (and could be entered in a cron for example)

Re: [Freeipa-users] Do we need ipa-client-update script?

2012-09-21 Thread Jan Cholasta
Dne 21.9.2012 10:45, Petr Spacek napsal(a): Hello users, we have a question for client machine administrators: On 09/21/2012 10:12 AM, Martin Kosek wrote: snip ..., that it may be useful to implement a script like ipa-client-update which would be capable of updating client information

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-21 Thread Rich Megginson
On 09/21/2012 05:21 AM, Martin Kosek wrote: When using bare ldapsearch, you are hitting 389-ds limits - in your case nsslapd-sizelimit. This can be increased either globally or (this seems as a more secure solution) for a user you bind as:

Re: [Freeipa-users] sudden ipa errors.

2012-09-21 Thread Rob Crittenden
Lager, Nathan T. wrote: Well, after all of this, RedHat support just resolved my issue! It came down the the domain_realm definitions in /etc/krb5.conf. They had me change: [domain_realm] .systems.lafayette.edu = SYSTEMS.LAFAYETTE.EDU systems.lafayette.edu = SYSTEMS.LAFAYETTE.EDU To:

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-21 Thread Rich Megginson
On 09/21/2012 09:04 AM, Dmitri Pal wrote: On 09/21/2012 09:23 AM, Rich Megginson wrote: On 09/21/2012 05:21 AM, Martin Kosek wrote: When using bare ldapsearch, you are hitting 389-ds limits - in your case nsslapd-sizelimit. This can be increased either globally or (this seems as a more secure

Re: [Freeipa-users] sudden ipa errors.

2012-09-21 Thread Rob Crittenden
Nathan Lager wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 09/21/2012 10:18 AM, Rob Crittenden wrote: Lager, Nathan T. wrote: Well, after all of this, RedHat support just resolved my issue! It came down the the domain_realm definitions in /etc/krb5.conf. They had me change:

Re: [Freeipa-users] Migrate from SunONE DS5.2 - UnicodeDecodeError

2012-09-21 Thread Dmitri Pal
On 09/21/2012 04:23 AM, Pieter Baele wrote: On Thu, Sep 20, 2012 at 3:49 PM, Martin Kosek mko...@redhat.com wrote: Since an Internal error was returned, there should at least be a traceback in /var/log/httpd/error_log. This should help us narrow down the root cause of this issue. Martin

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-21 Thread Dmitri Pal
On 09/21/2012 11:07 AM, Rich Megginson wrote: On 09/21/2012 09:04 AM, Dmitri Pal wrote: On 09/21/2012 09:23 AM, Rich Megginson wrote: On 09/21/2012 05:21 AM, Martin Kosek wrote: When using bare ldapsearch, you are hitting 389-ds limits - in your case nsslapd-sizelimit. This can be increased

Re: [Freeipa-users] sudden ipa errors.

2012-09-21 Thread Dmitri Pal
On 09/21/2012 11:13 AM, Nathan Lager wrote: On 09/21/2012 11:07 AM, Nathan Lager wrote: On 09/21/2012 10:18 AM, Rob Crittenden wrote: Lager, Nathan T. wrote: Well, after all of this, RedHat support just resolved my issue! It came down the the domain_realm definitions in

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-21 Thread Rich Megginson
On 09/21/2012 09:18 AM, Dmitri Pal wrote: On 09/21/2012 11:07 AM, Rich Megginson wrote: On 09/21/2012 09:04 AM, Dmitri Pal wrote: On 09/21/2012 09:23 AM, Rich Megginson wrote: On 09/21/2012 05:21 AM, Martin Kosek wrote: When using bare ldapsearch, you are hitting 389-ds limits - in your case

Re: [Freeipa-users] krb5-server-1.9-33.el6_3.3.x86_64 prevents named from starting when selinux is enforcing

2012-09-21 Thread Sigbjorn Lie
On 09/21/2012 02:47 PM, Rob Crittenden wrote: Simo Sorce wrote: - Original Message - Sigbjorn Lie wrote: On 09/20/2012 10:17 PM, Rob Crittenden wrote: bind isn't my strongest suite. My guess is that this file is the ccache for bind. I'm guessing that 25 is the UID of the named user.

Re: [Freeipa-users] ipa host-add having both an IPv4 and an IPv6 address

2012-09-21 Thread Sigbjorn Lie
On 09/21/2012 10:29 AM, Martin Kosek wrote: On 09/20/2012 10:35 PM, Sigbjorn Lie wrote: Hi, I see that I can add hosts with either an IPv4 or an IPv6 address when using ipa host-add --ip-address=. Is there a way to add a host specifying both an IPv4 and an IPv6 address at the same time?

Re: [Freeipa-users] Do we need ipa-client-update script?

2012-09-21 Thread Sigbjorn Lie
On 09/21/2012 10:45 AM, Petr Spacek wrote: Hello users, we have a question for client machine administrators: On 09/21/2012 10:12 AM, Martin Kosek wrote: snip ..., that it may be useful to implement a script like ipa-client-update which would be capable of updating client information (and