Re: [Freeipa-users] Easy deployment

2012-09-25 Thread Christian Horn
Hi, On Tue, Sep 25, 2012 at 12:17:47AM +0200, James James wrote: we are planning to install 150 freeipa clients and I was wondering if there is a way to easily install (from kickstart) nfsv4 client. I can add host with # ipa host-add --password=secret But to get the keytab (host and

Re: [Freeipa-users] Easy deployment

2012-09-25 Thread Rob Crittenden
Dmitri Pal wrote: On 09/24/2012 06:17 PM, James James wrote: Hi guys, we are planning to install 150 freeipa clients and I was wondering if there is a way to easily install (from kickstart) nfsv4 client. I can add host with # ipa host-add --password=secret This was exactly intended for the

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Rich Megginson
On 09/24/2012 09:49 PM, Steven Jones wrote: Hi, Im confused here, has no one tried to winsync 2000+ users before? You are the first one to run into this problem. Are there any docs on working around this limit? In AD? Ive up'd the user to 2 How? What exactly did you do? but

Re: [Freeipa-users] NSMMReplicationPlugin - changelog program - cl5DBData2Entry: invalid data version

2012-09-25 Thread Dan Scott
Hi, We've tried starting the service properly - the dirsrv process still won't start properly: [25/Sep/2012:13:28:10 -0400] - 389-Directory/1.2.10.14 B2012.201.358 starting up [25/Sep/2012:13:28:10 -0400] - Detected Disorderly Shutdown last time Directory Server was running, recovering database.

Re: [Freeipa-users] Easy deployment

2012-09-25 Thread Sigbjorn Lie
On 09/25/2012 12:17 AM, James James wrote: Hi guys, we are planning to install 150 freeipa clients and I was wondering if there is a way to easily install (from kickstart) nfsv4 client. I can add host with # ipa host-add --password=secret But to get the keytab (host and service), I have to

Re: [Freeipa-users] NSMMReplicationPlugin - changelog program - cl5DBData2Entry: invalid data version

2012-09-25 Thread Rich Megginson
On 09/25/2012 11:39 AM, Dan Scott wrote: Hi, We've tried starting the service properly - the dirsrv process still won't start properly: [25/Sep/2012:13:28:10 -0400] - 389-Directory/1.2.10.14 B2012.201.358 starting up [25/Sep/2012:13:28:10 -0400] - Detected Disorderly Shutdown last time

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Steven Jones
Hi, I have set the filter size as 2 for the user and it makes no difference. So unless its somewhere else configurable it cant be easily done. via adsi edit? and if so what is the value called? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Rich Megginson
On 09/25/2012 03:34 PM, Steven Jones wrote: Hi, I have set the filter size as 2 for the user and it makes no difference. Where did you set this? In IPA? In AD? If so, where? How? What does filter size mean? To me, it means the size of an LDAP search filter in an LDAP search request

[Freeipa-users] Apache, autofs and userdir

2012-09-25 Thread James James
Hi, I don't know if this is the right place to ask this question but I will try. I have : - a freeipa server + autofs maps - a nfsv4 server - a web server from the webserver I can mount my nfs4 exported home dir. Everything works well. I want to acces to my public_html directory from the web

Re: [Freeipa-users] Apache, autofs and userdir

2012-09-25 Thread Sigbjorn Lie
On 09/26/2012 12:21 AM, James James wrote: Hi, I don't know if this is the right place to ask this question but I will try. I have : - a freeipa server + autofs maps - a nfsv4 server - a web server from the webserver I can mount my nfs4 exported home dir. Everything works well. I want to

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Rob Crittenden
Rich Megginson wrote: On 09/25/2012 03:34 PM, Steven Jones wrote: Hi, I have set the filter size as 2 for the user and it makes no difference. Where did you set this? In IPA? In AD? If so, where? How? What does filter size mean? To me, it means the size of an LDAP search filter in an

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Steven Jones
Hi, I dont have a ldapmodify command for changing something in AD. I have increased the only scope I/we know about which is the return of objects from a search inside the AD gui but that might be specific to that view tool. That is 2000 by default, Ive set 4, I am testing it now, if that

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-25 Thread Rob Crittenden
Steven Jones wrote: Hi, I dont have a ldapmodify command for changing something in AD. I have increased the only scope I/we know about which is the return of objects from a search inside the AD gui but that might be specific to that view tool. That is 2000 by default, Ive set 4, I am