Re: [Freeipa-users] Freeipa 3.3.3 and --external-ca

2015-01-01 Thread Martin Minkus
Hi Daniel, Oh wow, you might be right! I just checked the CA cert and the signed IPA cert, and openssl shows: Certificate: Data: Version: 3 (0x2) Serial Number: 33 (0x21) Signature Algorithm: sha1WithRSAEncryption Now that we know what the problem most likely is, we'll

[Freeipa-users] firewalld management

2015-01-01 Thread Jorick Astrego
Hi, FreeIPA is great! One thing I'm missing though is management of firewalld services and ports. Is that something that would fit in FreeIPA? Currently we are using puppet scripts through katello/the foreman, but as this is very error prone we'd like to have it centrally managed a different

Re: [Freeipa-users] firewalld management

2015-01-01 Thread Rob Crittenden
Andrew Holway wrote: This would perhaps be a very interesting addition to the HBAC stuff. We're considering deploying freeipa on EC2 and LDAP backed firewalld would be a very powerful tool for a geographically distributed system. There is an existing open ticket for this request,

Re: [Freeipa-users] Client configuration to point to Replica server once master service failed

2015-01-01 Thread Jan Pazdziora
On Thu, Jan 01, 2015 at 11:05:32AM +0530, Sanju A wrote: I have configured Master - Master replication and replication (bi direction) is working fine. Can I get the configuration that has to be added/modified in server/client machine so as to point to the replica server once the master