Re: [Freeipa-users] Migration fails with custom objectClasses

2014-10-16 Thread Ludwig Krispenz
On 10/15/2014 10:05 PM, Rob Crittenden wrote: Clint Savage wrote: $ rpm -q ipa-server ipa-server-3.3.3-28.el7.centos.1.x86_64 I was thinking that this might be an issue with the rhel7 version. I'm going to be trying the same migration tonight on rhel6. I know the IPA version is older, and

Re: [Freeipa-users] No result when trying to integrate a FreeBSD client with the FreeIPA server

2014-10-16 Thread Orkhan Gasimov
OK, back to FreeIPA - FreeBSD setup. I changed my setup: instead of 2 VMs now I have 4 VMs: 1: DNS server - set up as shown by Rajnesh Kumar Siwal in http://www.youtube.com/watch?v=0SmiwFoHVeIindex=4list=PLdKXnZQzEG-KmtKq-LelPn5RTKfJig0Wc 2 and 3: IPA server IPA linux client - set up as

Re: [Freeipa-users] No result when trying to integrate a FreeBSD client with the FreeIPA server

2014-10-16 Thread Lukas Slebodnik
On (16/10/14 13:04), Orkhan Gasimov wrote: OK, back to FreeIPA - FreeBSD setup. I changed my setup: instead of 2 VMs now I have 4 VMs: 1: DNS server - set up as shown by Rajnesh Kumar Siwal in http://www.youtube.com/watch?v=0SmiwFoHVeIindex=4list=PLdKXnZQzEG-KmtKq-LelPn5RTKfJig0Wc 2 and 3: IPA

Re: [Freeipa-users] No result when trying to integrate a FreeBSD client with the FreeIPA server

2014-10-16 Thread Orkhan Gasimov
Please excuse me for that silly typo in the letter. The typo doesn`t exist either in /etc/pam.d/system or /etc/pam.d/sshd - in those files I typed ignore_unknown_user. I'll try ignore_authinfo_unavail to see if it prevents me from being locked out of the machine. Here are the log files:

[Freeipa-users] A Specific Problem freeipa user rights

2014-10-16 Thread Tevfik Ceydeliler
Hi, I have user that have sudo su right. And we have to use checkpoint ssl VPN connection. Becouse of SSL VPN connection, VPN want ot create virtual interface for tunneling and needs root right. My clients work on ubuntu desktop. How can I give a permission to my user to create this tunnel

[Freeipa-users] ipa-client-install (Invalid Request) - no Host-Certificate

2014-10-16 Thread Christof Schulze
Hello all, i am running a FreeIPA server on CentOS for 2 years now with mostly Ubuntu 12.04 and some Fedora 20 clients. Since one week (or more) it is not possible any more to install new clients (whether ubuntu nor fedora). The Host gets created on the IPA-server but it can not create/exchange

Re: [Freeipa-users] No result when trying to integrate a FreeBSD client with the FreeIPA server

2014-10-16 Thread Orkhan Gasimov
Here`s what I have at the end of the day after various checks. SSH-ing as existing IPA user rsiwal to my FreeBSD client fails. The same user can SSH or locally login to my Linux client. If I create a new user in IPA, he can`t initially SSH into FreeBSD client. BSD says: password expired, but

Re: [Freeipa-users] ipa-client-install (Invalid Request) - no Host-Certificate

2014-10-16 Thread Rob Crittenden
Christof Schulze wrote: Hello all, i am running a FreeIPA server on CentOS for 2 years now with mostly Ubuntu 12.04 and some Fedora 20 clients. Since one week (or more) it is not possible any more to install new clients (whether ubuntu nor fedora). The Host gets created on the IPA-server

Re: [Freeipa-users] ipa-client-install (Invalid Request) - no Host-Certificate

2014-10-16 Thread Christof . Schulze
The FreeIPA is 3.0.0 server is running on CentOS 6.5. The CA subsystem certificates have all been renewed and will expire not until 2016. In the I think the problems come from modifications a colleague did to /etc/httpd/ipa-pki-proxy.conf , /etc/httpd/nss.conf and /var/lib/pki-ca/conf/server.xml

Re: [Freeipa-users] Migration fails with custom objectClasses

2014-10-16 Thread Clint Savage
On Thu, Oct 16, 2014 at 12:59 PM, Rich Megginson rmegg...@redhat.com wrote: On 10/16/2014 11:42 AM, Clint Savage wrote: The access log had that information. And this error log: https://www.dropbox.com/s/ak6za0dkr0cn7ay/errors.20141010-132318 There unfortunately doesn't seem to be a debug

[Freeipa-users] Valid documentation for sudo setup for version 4.0.3

2014-10-16 Thread Vaclav Adamec
Hi, is there any valid documentation/setup to get sudo working? http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/example-configuring-sudo.html is not usable, modification of another files are needed to get at least attempts to ldap (for example on CentOS /etc/sudo-ldap.conf).

Re: [Freeipa-users] Valid documentation for sudo setup for version 4.0.3

2014-10-16 Thread Dmitri Pal
On 10/16/2014 09:04 PM, Vaclav Adamec wrote: Hi, is there any valid documentation/setup to get sudo working? http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/example-configuring-sudo.html is not usable, modification of another files are needed to get at least attempts to ldap