Re: [Freeipa-users] sudo !requiretty !authenticate

2015-01-06 Thread Pavel Březina
On 01/05/2015 07:32 PM, Craig White wrote: Hi - reply at bottom -Original Message- From: Martin Kosek [mailto:mko...@redhat.com] Sent: Monday, January 05, 2015 4:33 AM To: Craig White; freeipa-users@redhat.com; Pavel Brezina Subject: Re: [Freeipa-users] sudo !requiretty !authenticate

Re: [Freeipa-users] sudo !requiretty !authenticate

2015-01-06 Thread Lukas Slebodnik
On (06/01/15 10:21), Pavel Březina wrote: On 01/05/2015 07:32 PM, Craig White wrote: Hi - reply at bottom -Original Message- From: Martin Kosek [mailto:mko...@redhat.com] Sent: Monday, January 05, 2015 4:33 AM To: Craig White; freeipa-users@redhat.com; Pavel Brezina Subject: Re:

[Freeipa-users] Replica install fails when using --setup-ca

2015-01-06 Thread dbischof
Hi, I have two small FreeIPA installations (for two different realms), both with CentOS 6/FreeIPA 3.0.0-42. After running them both with only one master server each for a while, I attempted to extend both installations with one replica each. Doing a ipa-replica-install --setup-ca

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-06 Thread Dmitri Pal
On 01/05/2015 10:37 PM, Ben .T.George wrote: HI IRC is like totally dead. i have waited one whole day to anyone responding. not even to my replay. i didn't see any messages at all. As I said AB is on PTO till tomorrow. Please ping him when he is back. Regards, Ben On Mon, Jan 5, 2015

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-06 Thread Rob Crittenden
Dmitri Pal wrote: On 01/05/2015 10:37 PM, Ben .T.George wrote: HI IRC is like totally dead. i have waited one whole day to anyone responding. not even to my replay. i didn't see any messages at all. As I said AB is on PTO till tomorrow. Please ping him when he is back. You're on #freeipa

Re: [Freeipa-users] trust non-IPA certificate client

2015-01-06 Thread Rob Crittenden
Stephen Ingram wrote: On Fri, Jan 2, 2015 at 10:02 AM, Rob Crittenden rcrit...@redhat.com mailto:rcrit...@redhat.com wrote: Stephen Ingram wrote: On Mon, Dec 15, 2014 at 6:40 PM, Stephen Ingram sbing...@gmail.com mailto:sbing...@gmail.com mailto:sbing...@gmail.com

Re: [Freeipa-users] ipa host-add and service add command to add solaris 10

2015-01-06 Thread Rob Crittenden
Ben .T.George wrote: HI i was trying to ass solaris 10 client from command line. Host add comand went successfully and service add for /host is giving error. please check below output and help me to solve this [root@kwtpocpbis01 ~]# ipa host-add --force --ip-address=172.16.107.107

Re: [Freeipa-users] ipa host-add and service add command to add solaris 10

2015-01-06 Thread Ben .T.George
HI thanks for the replay. i was trying for keytab and getting below error. [root@kwtpocpbis01 ~]# ipa-getkeytab -s kwtpocpbis01.solipa.local -p host/kwttestsolaris10.solipa.local -k /tmp/krb5.keytab -e des-cbc-crc Operation failed! All enctypes provided are unsupported my krb5.conf looks like

[Freeipa-users] Confused with certificate renewal ipa-server-3.0.0.0-37.el6.x86_64

2015-01-06 Thread John Desantis
Hello all, Looking at the various online documentation regarding certificate renewals: http://www.freeipa.org/page/Howto/CA_Certificate_Renewal#Procedure_in_IPA_.3C_4.0 http://www.freeipa.org/page/Certmonger

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Sumit Bose
On Tue, Jan 06, 2015 at 07:19:15AM -0700, Rich Megginson wrote: On 01/05/2015 08:35 PM, Ben .T.George wrote: Hi LIst, how to check IPA - Active directory trust relationship . i just want to confirm my ipa server is working fine. On an IPA server or client machine: $ kinit

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-06 Thread Endi Sukma Dewata
On 1/6/2015 4:55 AM, Anthony Messina wrote: I'm discussing this with Ade (CC'd). Based on the stack trace it looks like the replica thinks the master returns an incomplete information about the security domain, probably due to the different Dogtag versions used in master and replica. We need

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Ben .T.George
Hi I Tried on IPA server and below is my output: [root@kwtpocpbis01 ~]# kinit adm-ben.geo...@kwttestdc.com Password for adm-ben.geo...@kwttestdc.com: kinit: KDC reply did not match expectations while getting initial credentials how can i troubleshot this issue.? Thanks Regards, Ben On Tue,

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Sumit Bose
On Tue, Jan 06, 2015 at 07:52:20PM +0300, Ben .T.George wrote: Hi I Tried on IPA server and below is my output: [root@kwtpocpbis01 ~]# kinit adm-ben.geo...@kwttestdc.com Password for adm-ben.geo...@kwttestdc.com: kinit: KDC reply did not match expectations while getting initial

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Ben .T.George
HI thanks for the replay. please find below output.it's asking for password and accepting that. but something wrong [root@kwtpocpbis01 ~]# kinit -C adm-ben.geo...@kwttestdc.com Password for adm-ben.geo...@kwttestdc.com: [root@kwtpocpbis01 ~]# getent passwd adm-ben.george [root@kwtpocpbis01

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Sumit Bose
On Tue, Jan 06, 2015 at 08:13:17PM +0300, Ben .T.George wrote: HI thanks for the replay. please find below output.it's asking for password and accepting that. but something wrong [root@kwtpocpbis01 ~]# kinit -C adm-ben.geo...@kwttestdc.com Password for adm-ben.geo...@kwttestdc.com:

Re: [Freeipa-users] How to check IPA -- AD trust from command line

2015-01-06 Thread Ben .T.George
HI thanks now i am getting output: [root@kwtpocpbis01 ~]# getent passwd adm-ben.geo...@kwttestdc.com adm-ben.geo...@kwttestdc.com:*:1198401206:1198401206:ADM Ben George:/home/ kwttestdc.com/adm-ben.george: [root@kwtpocpbis01 ~]# id adm-ben.geo...@kwttestdc.com

Re: [Freeipa-users] trust non-IPA certificate client

2015-01-06 Thread Stephen Ingram
On Fri, Jan 2, 2015 at 10:02 AM, Rob Crittenden rcrit...@redhat.com wrote: Stephen Ingram wrote: On Mon, Dec 15, 2014 at 6:40 PM, Stephen Ingram sbing...@gmail.com mailto:sbing...@gmail.com wrote: I have one client using a certificate issued by a third party provider such that

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-06 Thread Anthony Messina
Quoting Endi Sukma Dewata edew...@redhat.com: On 1/6/2015 4:55 AM, Anthony Messina wrote: I'm discussing this with Ade (CC'd). Based on the stack trace it looks like the replica thinks the master returns an incomplete information about the security domain, probably due to the different Dogtag