Re: [Freeipa-users] Fwd: FreeIPA on Fedora 19 won't work

2013-09-30 Thread Glenn Jenkins
Alexander Bokovoy abokovoy@... writes: On Fri, 14 Jun 2013, Steve Dickson wrote: The $subject says it all... Any ideas what is going on here? I did fresh install right now on a up to date F19 VM and experienced no problem whatsoever. There were updates in pki-* and 389-ds-* packages over

[Freeipa-users] krb5kdc Additional pre-authentication required

2013-09-30 Thread Mohan Cheema
Hi, We are trying to authenticate from Windows machine and getting below error. Sep 30 14:07:34 kdc1.domain.com krb5kdc[10105](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 10.43.2.45: NEEDED_PREAUTH: u...@domain.com for krbtgt/domain@domain.com, Additional

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-09-30 Thread Sumit Bose
On Mon, Sep 30, 2013 at 03:20:46PM +0100, Mohan Cheema wrote: Hi, We are trying to authenticate from Windows machine and getting below error. Sep 30 14:07:34 kdc1.domain.com krb5kdc[10105](info): AS_REQ (7 etypes {18 17 23 3 1 24 -135}) 10.43.2.45:

[Freeipa-users] SUDOers config with cleartext password?

2013-09-30 Thread Innes, Duncan
Hi folks, Just wondering if it's really the case that I have to use a cleartext bindpw in my /etc/sudo-ldap.conf file in order to get sudoers looking at my FreeIPA servers? It's the first time I've looked into this side of things in FreeIPA and it just seems a bit more clunky than other areas

Re: [Freeipa-users] SUDOers config with cleartext password?

2013-09-30 Thread Innes, Duncan
Thanks, I'll try and speed up my migration to RHEL 6.4 then :) Duncan -Original Message- From: Alexander Bokovoy [mailto:aboko...@redhat.com] Sent: 30 September 2013 17:26 To: Innes, Duncan Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] SUDOers config with cleartext

Re: [Freeipa-users] SUDOers config with cleartext password?

2013-09-30 Thread Alexander Bokovoy
On Mon, 30 Sep 2013, Innes, Duncan wrote: Hi folks, Just wondering if it's really the case that I have to use a cleartext bindpw in my /etc/sudo-ldap.conf file in order to get sudoers looking at my FreeIPA servers? It's the first time I've looked into this side of things in FreeIPA and it just

[Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Andrew Tranquada
I have 6 servers setup as freeipa replicas. 5 are working great, no problems. They are all running ipa-server-3.0.0-26.el6_4.4.x86_64 However, the same one will randomly stop working. By stop working I mean the following: (domain name and ips have been redacted) I cannot kinit as any user on

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Alexander Bokovoy
On Mon, 30 Sep 2013, Andrew Tranquada wrote: I have 6 servers setup as freeipa replicas. 5 are working great, no problems. They are all running ipa-server-3.0.0-26.el6_4.4.x86_64 However, the same one will randomly stop working. By stop working I mean the following: (domain name and ips have

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Andrew Tranquada
Thanks for the response I did look in /var/log/slapd-PKI* or slapd-DOMAIN (I guess I was not too clear I did that in my email) in those logs the last thing in that log is from Sep 18 From /var/log/dirsrv/slapd-EXAMPLE-COM/errors: [18/Sep/2013:01:09:34 -0400] slapd_ldap_sasl_interactive_bind -

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Rob Crittenden
Andrew Tranquada wrote: Thanks for the response I did look in /var/log/slapd-PKI* or slapd-DOMAIN (I guess I was not too clear I did that in my email) in those logs the last thing in that log is from Sep 18 From /var/log/dirsrv/slapd-EXAMPLE-COM/errors: [18/Sep/2013:01:09:34 -0400]

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Alexander Bokovoy
On Mon, 30 Sep 2013, Andrew Tranquada wrote: Thanks for the response I did look in /var/log/slapd-PKI* or slapd-DOMAIN (I guess I was not too clear I did that in my email) in those logs the last thing in that log is from Sep 18 From /var/log/dirsrv/slapd-EXAMPLE-COM/errors:

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Andrew Tranquada
Well I feel silly for not checking this earlier. You were correct. Sep 18 01:09:35 freeipa1 kernel: : ns-slapd[16553]: segfault at 4 ip 0041227a sp 7fb9d15edc68 error 4 in ns-slapd[40+53000] I am installing the 389-ds-base-debuginfo and accompanying packages now, restarting ipa,

Re: [Freeipa-users] Server randomly will stop accepting krb requests

2013-09-30 Thread Rich Megginson
On 09/30/2013 11:27 AM, Andrew Tranquada wrote: Well I feel silly for not checking this earlier. You were correct. Sep 18 01:09:35 freeipa1 kernel: : ns-slapd[16553]: segfault at 4 ip 0041227a sp 7fb9d15edc68 error 4 in ns-slapd[40+53000] I am installing the

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-09-30 Thread Mohan Cheema
-Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users- boun...@redhat.com] On Behalf Of Sumit Bose Sent: Monday, September 30, 2013 3:47 PM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] krb5kdc Additional pre-authentication required On Mon,