Re: [Freeipa-users] winsync and new users

2014-03-07 Thread Martin Kosek
On 02/27/2014 11:11 PM, Alexander Bokovoy wrote: On Thu, 27 Feb 2014, Michal Zacek wrote: Hi, I have successfully completed agreement between Windows and IPA and it works. When I create user in Windows, it's synchronized to IPA and when I change something on IPA for this user, it's

Re: [Freeipa-users] Patch for ipa-sam: ipa-server-trust-ad samba server valid users =@groupname

2014-03-07 Thread Petr Spacek
On 6.3.2014 23:06, Alexander Bokovoy wrote: On Thu, 06 Mar 2014, Jason Woods wrote: Hi all, I am quite aware that installing ipa-server-trust-ad and using the samba as a file server is as unsupported as one can get... but I really needed a Samba server integrated with IPA (damn Mac OS and

Re: [Freeipa-users] HTTP Service: STOPPED

2014-03-07 Thread Martin Kosek
On 03/04/2014 07:41 PM, Dmitri Pal wrote: On 03/04/2014 01:28 PM, Shree wrote: Not sure what is going on? I get the following error. --- Starting httpd: (98)Address already in use: make_sock: could not bind to address [::]:443 --- I have a feeling our puppet is

Re: [Freeipa-users] F19 - F20 yum upgrade success report (WAS: Re: WARNING: Do not upgrade FreeIPA deployments to Fedora 20 final (yet))

2014-03-07 Thread Martin Kosek
On 03/03/2014 09:54 PM, Anthony Messina wrote: On Saturday, March 01, 2014 04:18:11 AM Anthony Messina wrote: I've been waiting patiently for F20 to settle before upgrading my two VM installations of FreeIPA: ipa1 (original master) ipa2 (clone) I'm considering doing a yum upgrade this

Re: [Freeipa-users] incompatibility Operative systems

2014-03-07 Thread Martin Kosek
On 03/06/2014 05:09 PM, Juan Antonio wrote: I have a conflict with a configuration of free-ipa. The problem is an incompatibility between the client operating system with fedora 19 and the ipa server with Red hat 6.4 operating system. When executing the command: ipa add-service

Re: [Freeipa-users] Patch for ipa-sam: ipa-server-trust-ad samba server valid users =@groupname

2014-03-07 Thread Jason Woods
Hi, On 6.3.2014 23:06, Alexander Bokovoy wrote: For the record, it is ipa-adtrust-install --add-sids and the task is called sidgen task. Absolutely. Sorry for the confusion - too late and swimming in the code had me mix up the terminology :-) All sorted for the bugzilla ticket. On 6.3.2014

[Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread artjazz
Hi, I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are completely separated, 2 subnets and not routed. I'am wondering if this kind of

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Petr Spacek
On 7.3.2014 14:16, artj...@free.fr wrote: I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are completely separated, 2 subnets and not routed. I'm

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Martin Kosek
On 03/07/2014 03:45 PM, Petr Spacek wrote: On 7.3.2014 14:16, artj...@free.fr wrote: I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Dmitri Pal
On 03/06/2014 10:55 AM, Petr Spacek wrote: On 6.3.2014 14:32, Petr Spacek wrote: now it is the right time to propose topics for theses in the next university year. I propose [RFE] IPA should support and manage DNS sites https://fedorahosted.org/freeipa/ticket/2008 It is rotting in the

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread artjazz
Selon Petr Spacek pspa...@redhat.com: On 7.3.2014 14:16, artj...@free.fr wrote: I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are connected on the second interface. The two networks are

[Freeipa-users] IPA DNS command line tools and JSON interface

2014-03-07 Thread Rich Megginson
tl;dr - A lot of detail about working with the IPA DNS command line interfaces and JSON interfaces. I'm working on integrating IPA with OpenStack Designate (DNSaaS), using the /ipa/json interface. I've had some QA with the IPA DNS developer (Thanks Petr Spacek!) that I thought would be

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Jakub Hrozek
On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: We need to check if those are still relevant * https://thesis-managementsystem.rhcloud.com/topic/show/179/java-loginmodule-using-gssapi - I heard JBoss guys are fixing it * We are talking to Mongo about this:

Re: [Freeipa-users] install IPA replica multi-hosts (ipa packages version 3.3.3-18)

2014-03-07 Thread Dmitri Pal
On 03/07/2014 10:29 AM, artj...@free.fr wrote: Selon Petr Spacekpspa...@redhat.com: On 7.3.2014 14:16,artj...@free.fr wrote: I want to install ipa server with a replica. The replica has 2 NICs : the ipa server is connected on the first interface and all the clients are

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Dmitri Pal
On 03/07/2014 10:59 AM, Jakub Hrozek wrote: On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: We need to check if those are still relevant * https://thesis-managementsystem.rhcloud.com/topic/show/179/java-loginmodule-using-gssapi - I heard JBoss guys are fixing it * We are talking to

Re: [Freeipa-users] JSON interface (Was: IPA DNS command line tools and ~)

2014-03-07 Thread Petr Viktorin
On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] The ipa command line tools use RPC, but they use XML. If you run ipa -vv dnsrecord-add ... you can see the XML sent and received. There is a bit of work converting from XML to JSON. e.g.

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Alexander Bokovoy
On Fri, 07 Mar 2014, Dmitri Pal wrote: On 03/06/2014 10:55 AM, Petr Spacek wrote: On 6.3.2014 14:32, Petr Spacek wrote: now it is the right time to propose topics for theses in the next university year. I propose [RFE] IPA should support and manage DNS sites

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Jakub Hrozek
On Fri, Mar 07, 2014 at 11:04:45AM -0500, Dmitri Pal wrote: On 03/07/2014 10:59 AM, Jakub Hrozek wrote: On Fri, Mar 07, 2014 at 10:12:43AM -0500, Dmitri Pal wrote: We need to check if those are still relevant *

Re: [Freeipa-users] JSON interface (Was: IPA DNS command line tools and ~)

2014-03-07 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/07/2014 08:57 AM, Petr Viktorin wrote: On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] The ipa command line tools use RPC, but they use XML. If you run ipa -vv dnsrecord-add ... you can see the XML sent and received. There is a bit of

Re: [Freeipa-users] JSON interface

2014-03-07 Thread Petr Viktorin
On 03/07/2014 05:31 PM, Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/07/2014 08:57 AM, Petr Viktorin wrote: On 03/07/2014 04:34 PM, Rich Megginson wrote: [...] The ipa command line tools use RPC, but they use XML. If you run ipa -vv dnsrecord-add ... you can

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Nordgren, Bryce L -FS
UID/GID solution https://fedorahosted.org/sssd/ticket/1715 Chaining access providers: https://fedorahosted.org/sssd/ticket/1326 I'm not sure these two are enough for a thesis.. I think at least the first one is. You change UID and/or GID on the server. And then you need a

Re: [Freeipa-users] Using external KDC

2014-03-07 Thread Trey Dockendorf
On Thu, Mar 6, 2014 at 7:20 PM, Dmitri Pal d...@redhat.com wrote: On 03/05/2014 06:24 PM, Trey Dockendorf wrote: Correction from my email, the condition that sets if a 389DS user is proxied to pam_krb5 is the pamFilter, sorry. On Wed, Mar 5, 2014 at 5:22 PM, Trey Dockendorftreyd...@gmail.com

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Simo Sorce
On Fri, 2014-03-07 at 20:38 +, Nordgren, Bryce L -FS wrote: UID/GID solution https://fedorahosted.org/sssd/ticket/1715 Chaining access providers: https://fedorahosted.org/sssd/ticket/1326 I'm not sure these two are enough for a thesis.. I think at least the first one

Re: [Freeipa-users] Change user login name? (uid in LDAP)

2014-03-07 Thread Rob Crittenden
Will Sheldon wrote: Hello all :) We have an internal process that requires the renaming of users from time to time (user gets married, changes name). This requires changing the login name” as it’s called in the GUI, (or uid in LDAP). There doesn’t currently appear to be any method for doing

Re: [Freeipa-users] Using external KDC

2014-03-07 Thread Dmitri Pal
On 03/07/2014 05:26 PM, Trey Dockendorf wrote: On Thu, Mar 6, 2014 at 7:20 PM, Dmitri Pald...@redhat.com wrote: On 03/05/2014 06:24 PM, Trey Dockendorf wrote: Correction from my email, the condition that sets if a 389DS user is proxied to pam_krb5 is the pamFilter, sorry. On Wed, Mar 5, 2014

Re: [Freeipa-users] Propose FreeIPA theses: IPA support for sites

2014-03-07 Thread Nordgren, Bryce L -FS
You *could* build a system that can work w/o synchronization, if you carefully restrict what protocols and applications you use (think about distributed filesystems) although you'd still need a local persistent map at least. Backups and restore to other machines would need to be done

[Freeipa-users] Joining realm failed: SASL Bind failed Local error (-2)

2014-03-07 Thread Rashard . Kelly
Hello all!! I cannot get a RHEL5.10 client to install! [root@hostname ~]# ipa-client-install --hostname=hostname.domain.com --no-ntp --ca-cert-file=/etc/ipa/ca.crt DNS domain 'doman.com' is not configured for automatic KDC address lookup. KDC address will be set to fixed value. Discovery was

[Freeipa-users] Joining realm failed: SASL Bind failed Local error (-2)

2014-03-07 Thread Rashard . Kelly
Hello all!! I cannot get a RHEL5.10 client to install! [root@hostname ~]# ipa-client-install --hostname=hostname.domain.com --no-ntp --ca-cert-file=/etc/ipa/ca.crt DNS domain 'doman.com' is not configured for automatic KDC address lookup. KDC address will be set to fixed value. Discovery was