Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Jakub Hrozek
On 16 Jul 2014, at 03:29, Parsons, Aron parso...@bit-sys.com wrote: I ran into this issue last fall and have been running with a patched libnfsidmap since November while our support case with Red Hat waits on a resolution (pretty much have given up hope at this point). It's a trivial

[Freeipa-users] User auth for Samba 3 file server against IPA 3.0.0

2014-07-16 Thread dbischof
Hi, this has been discussed on this list and elsewhere [1], but I'm still a little puzzled: I have IPA running on a CentOS 6 server. This server also acts as NFS- and Samba server. My Linux clients (openSUSE 13.1) work fine (NFS, automount, user auth for ssh and display manager). Since I

[Freeipa-users] Difference between Masters and Replicas?

2014-07-16 Thread Choudhury, Suhail
Hi, I'd like some clarification on what a master and replica is please. This doc suggests you start with 1 master and a replica can be promoted to a master by changing /var/lib/pki-ca/conf/CS.cfg: http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/promoting-replica.html However

Re: [Freeipa-users] Difference between Masters and Replicas?

2014-07-16 Thread Petr Viktorin
On 07/16/2014 02:34 PM, Choudhury, Suhail wrote: Hi, I'd like some clarification on what a master and replica is please. Once installed, all masters are identical (except some might have a CA and some not). The distinction is useful when installing a replica, where master and replica

Re: [Freeipa-users] Difference between Masters and Replicas?

2014-07-16 Thread Bill Peck
On Wed, Jul 16, 2014 at 9:03 AM, Petr Viktorin pvikt...@redhat.com wrote: On 07/16/2014 02:34 PM, Choudhury, Suhail wrote: Hi, I'd like some clarification on what a master and replica is please. Once installed, all masters are identical (except some might have a CA and some not). The

Re: [Freeipa-users] Difference between Masters and Replicas?

2014-07-16 Thread Rob Crittenden
Bill Peck wrote: On Wed, Jul 16, 2014 at 9:03 AM, Petr Viktorin pvikt...@redhat.com mailto:pvikt...@redhat.com wrote: On 07/16/2014 02:34 PM, Choudhury, Suhail wrote: Hi, I'd like some clarification on what a master and replica is please. Once

Re: [Freeipa-users] Difference between Masters and Replicas?

2014-07-16 Thread Petr Spacek
On 16.7.2014 15:03, Petr Viktorin wrote: On 07/16/2014 02:34 PM, Choudhury, Suhail wrote: Hi, I'd like some clarification on what a master and replica is please. Once installed, all masters are identical (except some might have a CA and some not). The distinction is useful when installing a

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Nordgren, Bryce L -FS
Hi Aron, the support case you referenced is linked to bugzilla https://bugzilla.redhat.com/show_bug.cgi?id=1066153 which is fully acked for RHEL-6.6, the state of the bugzilla is ON_QA, so currently it looks the patch will be released in 6.6.. username@domain is coded in the NFS spec as an

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Alexander Bokovoy
On Wed, 16 Jul 2014, Nordgren, Bryce L -FS wrote: Hi Aron, the support case you referenced is linked to bugzilla https://bugzilla.redhat.com/show_bug.cgi?id=1066153 which is fully acked for RHEL-6.6, the state of the bugzilla is ON_QA, so currently it looks the patch will be released in 6.6..

Re: [Freeipa-users] Problem with IPAv2 certificate renewal

2014-07-16 Thread Rob Crittenden
Michal Nawrocki wrote: Hello, I¹m trying to renew IPA server certificates according to this howto: http://www.freeipa.org/page/IPA_2x_Certificate_Renewal and have problem with one of them. After starting tracking and resubmitting all 4 PKI certificates (auditSigningCert cert-pki-ca²,

[Freeipa-users] OC and FreeIPA

2014-07-16 Thread Jonathan J. Ramirez C.
Hi. Does anybody here know how to properly set up ownCloud 6.0.4 to work with FreeIPA 3.3.5? I keep getting these messages when trying to logon to OC with a created account in FreeIPA. Here's a sample: ownCloud[2182]: {user_ldap} initializing paged search for FilterobjectClass=* base Array ([0]

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Nordgren, Bryce L -FS
Thing is, nfsidmap always adds and then substracts '@' plus domain, assuming that the part prior to '@' is what going to be mapped by the domain-specific idmap mapper. That's the crux of the problem right there. Sssd is not a domain-specific idmap mapper. Sssd is a domain-aware,

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Parsons, Aron
Hi Jakub, Good to know about the patch. It's unfortunate I can get a faster and more detailed answer via the mailing list than GSS. Since I can't access the bugzilla, any idea if it's targeted at RHEL7 as well? /aron From: Jakub Hrozek

Re: [Freeipa-users] OC and FreeIPA

2014-07-16 Thread Rob Crittenden
Jonathan J. Ramirez C. wrote: Hi. Does anybody here know how to properly set up ownCloud 6.0.4 to work with FreeIPA 3.3.5? I keep getting these messages when trying to logon to OC with a created account in FreeIPA. Here's a sample: ownCloud[2182]: {user_ldap} initializing paged search

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-07-16 Thread Alexander Bokovoy
On Wed, 16 Jul 2014, Nordgren, Bryce L -FS wrote: Thing is, nfsidmap always adds and then substracts '@' plus domain, assuming that the part prior to '@' is what going to be mapped by the domain-specific idmap mapper. That's the crux of the problem right there. Sssd is not a

[Freeipa-users] FreeIPA 4.0.0 Peer's certificate issuer has been marked as not trusted by the user.

2014-07-16 Thread Nordgren, Bryce L -FS
On a clean Fedora 20, minimal install, system using the netinstall iso, I'm getting an error all the way at the end of the ipa-server-install process (when it tries to run ipa-client-install). I put the fqdn of the hostname in /etc/hostname and ipaddr ipa.usfs-i2.umt.edu ipa in /etc/hosts and

Re: [Freeipa-users] FreeIPA 4.0.0 Peer's certificate issuer has been marked as not trusted by the user.

2014-07-16 Thread Alexander Bokovoy
On Wed, 16 Jul 2014, Nordgren, Bryce L -FS wrote: On a clean Fedora 20, minimal install, system using the netinstall iso, I'm getting an error all the way at the end of the ipa-server-install process (when it tries to run ipa-client-install). I put the fqdn of the hostname in /etc/hostname and

Re: [Freeipa-users] FreeIPA 4.0.0 Peer's certificate issuer has been marked as not trusted by the user.

2014-07-16 Thread Nordgren, Bryce L -FS
On Wed, 16 Jul 2014, Nordgren, Bryce L -FS wrote: DNS A, SRV, and TXT entries are in place. Reverse DNS works. My text DNS entry is possibly hosed, as it's in lowercase. I put in a request to capitalize it. [root@ipa yum.repos.d]# host -t TXT _kerberos.usfs-i2.umt.edu