[Freeipa-users] Any command can change the direcoty manager password

2014-03-17 Thread barrykfl
hi: I accidently changed uid admin 's password ...and then change back orginal. BUT it seem that it also modify CN+directory manager also can now conflcit.s soem user cann not access using if cn= direcory manager. any idea ? i tried the follwig command it says ssl conenection already

Re: [Freeipa-users] Any command can change the direcoty manager password

2014-03-17 Thread Rich Megginson
On 03/17/2014 07:50 AM, barry...@gmail.com wrote: hi: I accidently changed uid admin 's password ...and then change back orginal. BUT it seem that it also modify CN+directory manager also can now conflcit.s The below command changed the password for cn=directory manager? What do you

Re: [Freeipa-users] Any command can change the direcoty manager password

2014-03-17 Thread Rob Crittenden
barry...@gmail.com wrote: hi: I accidently changed uid admin 's password ...and then change back orginal. BUT it seem that it also modify CN+directory manager also can now conflcit.s soem user cann not access using if cn= direcory manager. any idea ? i tried the follwig command it says ssl

[Freeipa-users] Change admin password will change directory manager also ???

2014-03-17 Thread barrykfl
Dear all: As title ? I changed admin (uid) and then change back orginal passwd . It seem it also syn to directoy manager. I wonder Now all applications integrated wih using CN=directory manger all fail to connect authroization fail. Any idea ? should i also change the directory manager password

Re: [Freeipa-users] Change admin password will change directory manager also ???

2014-03-17 Thread Rich Megginson
On 03/17/2014 08:34 AM, barry...@gmail.com wrote: Dear all: As title ? I changed admin (uid) and then change back orginal passwd . It seem it also syn to directoy manager. I wonder Now all applications integrated wih using CN=directory manger all fail to connect authroization fail. Any

Re: [Freeipa-users] Change admin password will change directory manager also ???

2014-03-17 Thread Rich Megginson
On 03/17/2014 08:34 AM, barry...@gmail.com wrote: Dear all: As title ? I changed admin (uid) and then change back orginal passwd . It seem it also syn to directoy manager. I wonder Using ldappasswd changed both the uid=admin password, and directory manager password? Can you confirm that

[Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Todd Maugh
I'm trying to sync all of my AD to IPA, I don't need to retain any of the original windows directory structure once in IPA. I cannot find where to set ipaWinSyncUserFlatten to true (so I'm assuming it's on true by default) I really need to be able to sync more than just the cn=users subtree

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Rich Megginson
On 03/17/2014 03:33 PM, Todd Maugh wrote: I'm trying to sync all of my AD to IPA, I don't need to retain any of the original windows directory structure once in IPA. I cannot find where to set ipaWinSyncUserFlatten to true (so I'm assuming it's on true by default) Yes, it is true by

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Todd Maugh
Thanks Rich, I am able to create a successful winsync agreement from the top level. Unfortunately, when I do this. I do not see any of the accounts from the sub trees populate my ipa server. Is it possible to have all the subtrees (ous) live under cn=users. If I make this change to AD would

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Rich Megginson
On 03/17/2014 03:52 PM, Todd Maugh wrote: Thanks Rich, I am able to create a successful winsync agreement from the top level. Unfortunately, when I do this. I do not see any of the accounts from the sub trees populate my ipa server. Ok, so it doesn't work. Is it possible to have all the

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Todd Maugh
Thanks again Rich is there some good Documentation on setting up the trust? From: Rich Megginson [mailto:rmegg...@redhat.com] Sent: Monday, March 17, 2014 3:03 PM To: Todd Maugh; freeipa-users@redhat.com Subject: Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Dmitri Pal
On 03/17/2014 06:04 PM, Todd Maugh wrote: Thanks again Rich is there some good Documentation on setting up the trust? http://www.freeipa.org/page/IPAv3_testing_AD_trust *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Monday, March 17, 2014 3:03 PM *To:* Todd Maugh;

Re: [Freeipa-users] Has one successfully synched the entirety of their AD to IPA (multiple OUs and or Subtrees)

2014-03-17 Thread Rich Megginson
On 03/17/2014 04:04 PM, Todd Maugh wrote: Thanks again Rich is there some good Documentation on setting up the trust? I'm not familiar with trust. There are other folks in the IPA community who are. *From:*Rich Megginson [mailto:rmegg...@redhat.com] *Sent:* Monday, March 17, 2014 3:03