Re: [Freeipa-users] Don't know what To do with this (error?? )

2014-11-25 Thread Rolf Nufable
ohh sorry I didn't said that I was using the freeipa server on this problem, anyway thanks for the replies :) and before  Thanks, really appreciate it :D On Monday, November 24, 2014 11:55 PM, Martin Kosek mko...@redhat.com wrote: On 11/25/2014 08:12 AM, Rolf Nufable wrote: Well I

Re: [Freeipa-users] Is it possible to set up SUDO with redudancy?

2014-11-25 Thread Lukas Slebodnik
On Mon, Nov 24, 2014 at 8:38 PM, William Muriithi william.murii...@gmail.com wrote: Evening, After looking at almost all the SUDO documentation I could find, it looks one has to hardcode FreeIPA hostname on sssd.conf file. Below is what red hat advice to add in sssd config file. services

Re: [Freeipa-users] Setting up a Kerberized IMAP Server.

2014-11-25 Thread Petr Spacek
On 24.11.2014 17:45, Maria Jose Yañez Dacosta wrote: Thank you for your prompt reply :). I still don't discover what caused the problem, but now I could get more information about the problem. I run the command that you commented me, I did as follows: - kinit usuipa - kvno

Re: [Freeipa-users] Freeipa-users Digest, Vol 76, Issue 111

2014-11-25 Thread Maria Jose Yañez Dacosta
Sorry for delay in answering, I've been testing a few things before going back to ask. Thanks for the advice, I'll be careful with security :). I also tried as is explained in the url you shared with me and as you suspected that isn't the problem either. I installed Wireshark, packet capture

[Freeipa-users] backup procedure : procedure for a lost of primary master

2014-11-25 Thread Nicolas Zin
Hi, I read the backup procedure on http://www.freeipa.org/page/Backup_and_Restore. If I lose my first master, it is stated than: - Clean deployment from the lost server by removing all replication agreements with it. - Choose another FreeIPA Server with CA installed to become the first master

Re: [Freeipa-users] 3.0.0-42 Replication issue after Centos6.5-6.6 upgrade

2014-11-25 Thread dbischof
Hi, with the help of Thierry and Rich I managed to debug the running ns-slapd on Server1 (see below). The failing attempt of decoding the SASL data returns a not very fruitful -1 (SASL_FAIL, generic failure). Any ideas? Short summary: Server1 = running IPA server Server2 = intended IPA

Re: [Freeipa-users] Services and Keytabs for load-balanced hostnames

2014-11-25 Thread Dimitar Georgievski
My case for HTTP load balancing is little different. Ideally I would like to use a real load balancer (A10 in this case) for balancing HTTP and HTTPS services. Would that be possible? Based on the info in this thread, and Apache configuration for IPA (ipa.conf) the following steps were performed

Re: [Freeipa-users] Services and Keytabs for load-balanced hostnames

2014-11-25 Thread Alexander Bokovoy
On Tue, 25 Nov 2014, Dimitar Georgievski wrote: My case for HTTP load balancing is little different. Ideally I would like to use a real load balancer (A10 in this case) for balancing HTTP and HTTPS services. Would that be possible? Based on the info in this thread, and Apache configuration for

Re: [Freeipa-users] backup procedure : procedure for a lost of primary master

2014-11-25 Thread Rob Crittenden
Nicolas Zin wrote: Hi, I read the backup procedure on http://www.freeipa.org/page/Backup_and_Restore. If I lose my first master, it is stated than: - Clean deployment from the lost server by removing all replication agreements with it. - Choose another FreeIPA Server with CA

[Freeipa-users] Centos5 - freeipa - AD trust

2014-11-25 Thread Nicolas Zin
Hi, I successfully create a trust relationship between a freeipa 3.3 realm (on Centos 7) and a windows 2008 AD. Now I add some machine clients to my IPA realm, and try to connect to them with my AD credential: - connecting to the 2 freeipa server: no problem - connecting to a Centos6 machine:

Re: [Freeipa-users] 3.0.0-42 Replication issue after Centos6.5-6.6 upgrade

2014-11-25 Thread Rich Megginson
On 11/25/2014 12:32 PM, dbisc...@hrz.uni-kassel.de wrote: Hi, with the help of Thierry and Rich I managed to debug the running ns-slapd on Server1 (see below). The failing attempt of decoding the SASL data returns a not very fruitful -1 (SASL_FAIL, generic failure). Any ideas? Short

Re: [Freeipa-users] Is it possible to set up SUDO with redudancy

2014-11-25 Thread William Muriithi
Implications of adding above is that SUDO would break if the hardcoded ipa is not available even if there is another replica somewhere in the network. Is that correct assumption? Is there a better way of doing it that I have missed? Which version of sssd do you have? sssd = 1.10 has native

Re: [Freeipa-users] Is it possible to set up SUDO with redudancy

2014-11-25 Thread William Muriithi
client machine. AFAIK, this is default behavior. Martin -- next part -- An HTML attachment was scrubbed... URL: https://www.redhat.com/archives/freeipa-users/attachments/20141125/bdd3495e/attachment.html

[Freeipa-users] Freeipa Blocking Sites?

2014-11-25 Thread Rolf Nufable
Goodmorning Is there a function in freeipa that blocks websites? -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project

Re: [Freeipa-users] Freeipa Blocking Sites?

2014-11-25 Thread Fraser Tweedale
On Wed, Nov 26, 2014 at 04:31:38AM +, Rolf Nufable wrote: Goodmorning Is there a function in freeipa that blocks websites?  Hi Rolf, FreeIPA does not have this feature. It is a centralised identity management system providing authentication and access control for hosts and services

Re: [Freeipa-users] Freeipa Blocking Sites?

2014-11-25 Thread Rolf Nufable
yea I figured this would be the answer , I was just making sure of the features in free ipa because I didn't read the whole documentation, thanks for the reply Sir Fraser :)  On Tuesday, November 25, 2014 9:51 PM, Fraser Tweedale ftwee...@redhat.com wrote: On Wed, Nov 26, 2014 at

Re: [Freeipa-users] Freeipa Blocking Sites?

2014-11-25 Thread Outback Dingo
You probably want like a squid or oops proxy filter if you mean for filtering web traffic. On Wed, Nov 26, 2014 at 4:51 PM, Fraser Tweedale ftwee...@redhat.com wrote: On Wed, Nov 26, 2014 at 04:31:38AM +, Rolf Nufable wrote: Goodmorning Is there a function in freeipa that blocks

Re: [Freeipa-users] Freeipa Blocking Sites?

2014-11-25 Thread Rolf Nufable
Actually the problem was that I was accessing our site from outside our network now, our domain in the  network locally is named example.com, and the outside website is also at the domain example.com so I guess what freeipa does is it looks for the website inside our local network..  On

[Freeipa-users] Failed to remove host

2014-11-25 Thread Vaclav Adamec
Hi, I'm encounter strange behavior, I run host removing from web UI and it failed with error Some entries were not deleted : host not found but it's still showing in list. Via cmd: ipa host-find -- 1 host matched -- Host name: Principal name: