Re: [Freeipa-users] sssd receives another uid/gid after disabled HBAC rule

2014-09-11 Thread Sumit Bose
On Wed, Sep 10, 2014 at 08:19:15AM +0200, Gregor Bregenzer wrote: Hello Sumit, i think maybe there is a different problem i just discovered by accident. As stated in the first email, i have an AD trust with FreeIPA that receives all POSIX attributes from AD, but i get different values: On

Re: [Freeipa-users] FreeIPA Web UI error: Service Unavailable

2014-09-11 Thread Petr Vobornik
Hello Tevfik, comments inline On 11.9.2014 12:24, Tevfik Ceydeliler wrote: Hi all, I tried to do single sign on for FreeIPa Web UI according to 4.3.3. Configuring the Browser I did browser side and then turn back to server side. And run those command: # scp /etc/krb5.conf

Re: [Freeipa-users] FreeIPA Web UI error: Service Unavailable

2014-09-11 Thread Tevfik Ceydeliler
hi, thnx for comment. I really dont care sibgle sign on or something like that now :) All I want I try to get back my ipa server :) I check IPA status and : [root@srv httpd]# ipactl status Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING MEMCACHE

Re: [Freeipa-users] Branding

2014-09-11 Thread Kodiak Firesmith
Sounds like a job for Puppet. On Wed, Sep 10, 2014 at 7:58 PM, Dmitri Pal d...@redhat.com wrote: On 09/10/2014 07:49 PM, William Graboyes wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Dimitri, Yeah just the logo should do, I believe I found it at

Re: [Freeipa-users] FreeIPA Active directory Integration: ipa unknown command trustdomain-fetch

2014-09-11 Thread Alexander Bokovoy
On Thu, 11 Sep 2014, Traiano Welcome wrote: Hi List I'm currently working through the IPAv3 AD integration document at: http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup I've managed to establish a trust between the IdM and the AD server. However, when I run the command: ---

Re: [Freeipa-users] FreeIPA, SSSD, sudo and Local Users

2014-09-11 Thread Jakub Hrozek
On Wed, Sep 10, 2014 at 09:58:27PM +, Trevor T Kates (Services - 6) wrote: Hi all: I'm using FreeIPA 3.0 under CentOS 6.5 and I'm trying to solve a bit of a quirky problem. From what I've read thus far, sudo under SSSD can't provide sudo rules for local users that are not part of

Re: [Freeipa-users] FreeIPA Active directory Integration: ipa unknown command trustdomain-fetch

2014-09-11 Thread Traiano Welcome
On Thu, Sep 11, 2014 at 6:06 PM, Traiano Welcome trai...@gmail.com wrote: Hi Alexander On Thu, Sep 11, 2014 at 4:38 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Thu, 11 Sep 2014, Traiano Welcome wrote: Hi List I'm currently working through the IPAv3 AD integration document at:

Re: [Freeipa-users] BIND not starting after IPA install

2014-09-11 Thread Petr Spacek
On 11.9.2014 14:20, Renier Gertzen wrote: Hi, My bind server refuses to start. I get the following: Sep 11 14:14:40 orpst named-sdb[4343]: generating session key for dynamic DNS Sep 11 14:14:40 orpst named-sdb[4343]: sizing zone task pool based on 6 zones Sep 11 14:14:40 orpst named-sdb[4343]:

Re: [Freeipa-users] FreeIPA Active directory Integration: ipa unknown command trustdomain-fetch

2014-09-11 Thread Alexander Bokovoy
On Thu, 11 Sep 2014, Traiano Welcome wrote: This one is not usable. You need to enable debugging on the server side. See http://www.freeipa.org/page/Howto/IPAv3_AD_trust_setup# Debugging_trust in the part where it talks about /usr/share/ipa/smb.conf.empty. I've attached the debug logs, I'd

Re: [Freeipa-users] FreeIPA Web UI error: Service Unavailable

2014-09-11 Thread Petr Vobornik
On 11.9.2014 13:36, Tevfik Ceydeliler wrote: hi, thnx for comment. I really dont care sibgle sign on or something like that now :) All I want I try to get back my ipa server :) I check IPA status and : [root@srv httpd]# ipactl status Directory Service: RUNNING KDC Service: RUNNING KPASSWD

[Freeipa-users] Use of SAN's with automatic certificates in FreeIPA 4

2014-09-11 Thread Michael Lasevich
If I remember correctly, you could not use SAN (Subject Alternate Names) for certificates in FreeIPA 3.0 - is this still the case with 4? I have hosts that automatically receive two hostnames, a long proper name (like service-i-12345678) and a simpler cname based on an index for ease of access

[Freeipa-users] Max life set 0 already but still promot admin rese tpassword every 3 months

2014-09-11 Thread barrykfl
Hi: i set max life no expiry already but still pomt reset password every 3 month any idea to disable it ??? what happening Regards -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the

Re: [Freeipa-users] FreeIPA Web UI error: Service Unavailable

2014-09-11 Thread Tevfik Ceydeliler
Yes I can use ipa on cli On 11-09-2014 20:17, Petr Vobornik wrote: On 11.9.2014 13:36, Tevfik Ceydeliler wrote: hi, thnx for comment. I really dont care sibgle sign on or something like that now :) All I want I try to get back my ipa server :) I check IPA status and : [root@srv httpd]# ipactl