Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Johan Petersson
I have now managed to use a Solaris 11 system as a client to IPA Server. su - testuser works ssh works and console login works. I get a delay before getting the prompt through ssh though and maybe from console too, probably something about autofs. Going to see if i can increase loginformation

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Sigbjorn Lie
Hi, This is interesting. When I tested Solaris 11 ssh worked, and su - testuser worked. However console login did not work giving some PAM errors. Could you please share your entire pam.conf file? Is this Solaris 11 or Solaris 11.1? Regards, Siggi On Thu, December 20, 2012 09:40, Johan

[Freeipa-users] ipa-replica-manage error

2012-12-20 Thread Nate Marks
I'm struggling with this output from ipa-replica-manage against an AD machine. Can anyone tell me what the'-11 -System Error means? Thanks! Added CA certificate /etc/openldap/cacerts/testdc.testdomain.corp_testdomain-TESTDC-CA.crt to certificate database for ipa01.inframax.ncare ipa:

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Johan Petersson
Hi, Here is my pam.conf cleaned up a bit. login auth requisite pam_authtok_get.so.1 login auth required pam_dhkeys.so.1 login auth sufficient pam_krb5.so.1 try_first_pass login auth required pam_unix_cred.so.1 login auth required

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Sigbjorn Lie
Thanks. I'm guessing it's taking such a long time because it's looking trough the entire LDAP server for your automount maps. The automountmap rules in the DUA profile will help with that. You'll also run into issues if you attempt to have several automount locations without having specified

Re: [Freeipa-users] ipa-replica-manage error

2012-12-20 Thread Rich Megginson
On 12/20/2012 04:04 AM, Nate Marks wrote: I'm struggling with this output from ipa-replica-manage against an AD machine. Can anyone tell me what the'-11 -System Error means? Thanks! Added CA certificate /etc/openldap/cacerts/testdc.testdomain.corp_testdomain-TESTDC-CA.crt to

Re: [Freeipa-users] login with kerberos on a webserver, just like with the ipa interface.

2012-12-20 Thread Simo Sorce
On Thu, 2012-12-20 at 16:38 +0100, Han Boetes wrote: Hi, I followed http://freeipa.org/page/Apache_SNI_With_Kerberos to enable login in to a webserver with kerberos tickets. I followed everything to the letter and all looks well. I can log in with a username and password, but when I

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Johan Petersson
Hi, Thank you for the tip about NFSMAPID_DOMAIN It was not set properly. sharectl get nfs nfsmapid_domain= And by using: sharectl set -p nfsmapid_domain=servername nfs It was properly set. I must add that i prefer editing files instead of sharectl,svccfg and so on. :) I also made a

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-20 Thread Johan Petersson
Hi, Was your example of a new DUAProfile ever added to Fedora or RHEL? If so i can't find any reference to it or a fix of the documentation. If not, is there a way to add it myself for my configuration? There is always the manual way otherwise i guess. Are Red Hat going to support RHEL clients

[Freeipa-users] freeIPA 3.1.0 for Redhat Enterprise 6.3?

2012-12-20 Thread David Copperfield
Hi Rob and all, Can FreeIPA be compiled and installed on Redhat Enterprise 6.3?  Or I have to upgrade/install some underlying packages first? Thanks. --David From: Johan Petersson johan.peters...@sscspace.com To: Sigbjorn Lie sigbj...@nixtra.com Cc: