Re: [Freeipa-users] error install replication

2015-02-09 Thread alireza baghery
ipasrv# Service SSSD status sssd is runing nevertheless i restart service sssd but problem do not solved On Mon, Feb 9, 2015 at 11:19 AM, Martin Kosek mko...@redhat.com wrote: On 02/09/2015 07:42 AM, alireza baghery wrote: i check on both server ssh each other's name and ssh successful and

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Chris Mohler
On 02/09/2015 09:48 AM, Rich Megginson wrote: On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich! dbmon.sh is a handy tool indeed. I read the instructions and upped my entry cache size to 2gb because I have enough ram. Everything went well until |service

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Rich Megginson
On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich! dbmon.sh is a handy tool indeed. I read the instructions and upped my entry cache size to 2gb because I have enough ram. Everything went well until |service dirsrv restart | |I Got the following errors:

Re: [Freeipa-users] Upgrade from 3x to 4x cant create first replica.

2015-02-09 Thread Chris Mohler
On 02/09/2015 10:18 AM, Martin Kosek wrote: On 02/07/2015 12:27 AM, Chris Mohler wrote: I'm having some troubles. I have an older IPA install Version 3.0.0. on Centos 6.6. It's currently the only master for my domain. I have about 4k user accounts on here and it's a live system called idm I'm

Re: [Freeipa-users] Upgrade from 3x to 4x cant create first replica.

2015-02-09 Thread Martin Kosek
On 02/09/2015 05:16 PM, Chris Mohler wrote: On 02/09/2015 10:18 AM, Martin Kosek wrote: On 02/07/2015 12:27 AM, Chris Mohler wrote: I'm having some troubles. I have an older IPA install Version 3.0.0. on Centos 6.6. It's currently the only master for my domain. I have about 4k user accounts

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Rich Megginson
On 02/09/2015 08:26 AM, Chris Mohler wrote: On 02/09/2015 09:48 AM, Rich Megginson wrote: On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich! dbmon.sh is a handy tool indeed. I read the instructions and upped my entry cache size to 2gb because I have enough

Re: [Freeipa-users] Upgrade from 3x to 4x cant create first replica.

2015-02-09 Thread Martin Kosek
On 02/07/2015 12:27 AM, Chris Mohler wrote: I'm having some troubles. I have an older IPA install Version 3.0.0. on Centos 6.6. It's currently the only master for my domain. I have about 4k user accounts on here and it's a live system called idm I'm trying to upgrade to V4.x as I am hoping

Re: [Freeipa-users] Trust with Active Directory fails

2015-02-09 Thread Guertin, David S.
For Active Directory cross-forest trusts to work, we need following records to be in place: _ldap._tcp.DOMAIN _kerberos._udp.DOMAIN _kerberos._tcp.DOMAIN _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.DOMAIN _kerberos._udp.Default-First-Site-Name._sites.dc._msdcs.DOMAIN

Re: [Freeipa-users] error install replication

2015-02-09 Thread Martin Kosek
On 02/09/2015 03:31 PM, Dmitri Pal wrote: On 02/09/2015 08:34 AM, alireza baghery wrote: yes try ssh admin@hostname but do not work log secure- Feb 9 15:42:20 ipasrv sshd[13414]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.30.160.20

Re: [Freeipa-users] Trust with Active Directory fails

2015-02-09 Thread Alexander Bokovoy
On Mon, 09 Feb 2015, Guertin, David S. wrote: For Active Directory cross-forest trusts to work, we need following records to be in place: _ldap._tcp.DOMAIN _kerberos._udp.DOMAIN _kerberos._tcp.DOMAIN _ldap._tcp.Default-First-Site-Name._sites.dc._msdcs.DOMAIN

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Chris Mohler
On 02/09/2015 11:19 AM, Rich Megginson wrote: On 02/09/2015 08:26 AM, Chris Mohler wrote: On 02/09/2015 09:48 AM, Rich Megginson wrote: On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich! dbmon.sh is a handy tool indeed. I read the instructions and upped my

Re: [Freeipa-users] User certificates with FreeIPA and another question.

2015-02-09 Thread Christopher Young
I actually think I can get this going at this time if I can just figure out how to submit a subca csr to dogtag, sign it, and acquire it. Documentation on that seems to be hard to come by, but I'm digging to avoid eating up this thread (and trying to RTFM where possible). I still stand by my

Re: [Freeipa-users] admin password is always expired

2015-02-09 Thread Dmitri Pal
On 02/09/2015 05:35 PM, Roderick Johnstone wrote: Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a good learning experience. I suspect its some changes that I made to the password policy that caused this.

Re: [Freeipa-users] Upgrade from 3x to 4x cant create first replica.

2015-02-09 Thread Chris Mohler
On 02/09/2015 11:36 AM, Martin Kosek wrote: On 02/09/2015 05:16 PM, Chris Mohler wrote: On 02/09/2015 10:18 AM, Martin Kosek wrote: On 02/07/2015 12:27 AM, Chris Mohler wrote: I'm having some troubles. I have an older IPA install Version 3.0.0. on Centos 6.6. It's currently the only master

Re: [Freeipa-users] User certificates with FreeIPA and another question.

2015-02-09 Thread Christopher Young
Would anyone happen to have any guides on how one could get through this process? I'm a one-man IT shop at the moment, so I'm building up a tremendous amount of infrastructure at once. I'm thinking that the option of creating a subCA with something simple like openssl would be the best option,

[Freeipa-users] Heads up - FC20 softhsm -2.0.0b1-8 rpm from mkosek/freeipa copr appears to be broken

2015-02-09 Thread Michael Lasevich
To save a day of torture to those of you still on FC20 and using mkosek-freeipa copr repo - it appears that the package ( http://copr-be.cloud.fedoraproject.org/results/mkosek/freeipa/fedora-20-x86_64/softhsm-2.0.0b1-8.fc20/softhsm-2.0.0b1-8.fc20.x86_64.rpm) is somehow broken. Once installed, you

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Rob Crittenden
Rich Megginson wrote: On 02/09/2015 12:13 PM, Chris Mohler wrote: On 02/09/2015 11:19 AM, Rich Megginson wrote: On 02/09/2015 08:26 AM, Chris Mohler wrote: On 02/09/2015 09:48 AM, Rich Megginson wrote: On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich!

Re: [Freeipa-users] Real-time replication status (RFE)?

2015-02-09 Thread Innes, Duncan
For sure Rob. It's a dirty hack to get the information that we desperately needed at one point. We had a pretty severe issue with our IPA servers a while back which was eventually solved by reinstalling all but the initial IPA server, deleting the old replication agreements and building the new

Re: [Freeipa-users] error install replication

2015-02-09 Thread Martin Kosek
Did you try the ssh admin@`hostname` command? It should show if ssh to admin via SSSDFreeIPA really works. On 02/09/2015 11:18 AM, alireza baghery wrote: account admin recognize and show uid gid and groups On Feb 9, 2015 1:42 PM, Martin Kosek mko...@redhat.com wrote: Ok. When on the server,

Re: [Freeipa-users] error install replication

2015-02-09 Thread alireza baghery
yes try ssh admin@hostname but do not work log secure- Feb 9 15:42:20 ipasrv sshd[13414]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.30.160.20 user=admin Feb 9 15:42:20 ipasrv sshd[13414]: pam_sss(sshd:auth): authentication success;

Re: [Freeipa-users] error install replication

2015-02-09 Thread alireza baghery
account admin recognize and show uid gid and groups On Feb 9, 2015 1:42 PM, Martin Kosek mko...@redhat.com wrote: Ok. When on the server, does # id admin or ssh admin@`hostname` work? Maybe it does not recognize the admin user. On 02/09/2015 09:29 AM, alireza baghery wrote: ipasrv#

Re: [Freeipa-users] error install replication

2015-02-09 Thread Martin Kosek
Ok. When on the server, does # id admin or ssh admin@`hostname` work? Maybe it does not recognize the admin user. On 02/09/2015 09:29 AM, alireza baghery wrote: ipasrv# Service SSSD status sssd is runing nevertheless i restart service sssd but problem do not solved On Mon, Feb 9, 2015 at

Re: [Freeipa-users] How do I modify the entry cache size?

2015-02-09 Thread Rich Megginson
On 02/09/2015 12:13 PM, Chris Mohler wrote: On 02/09/2015 11:19 AM, Rich Megginson wrote: On 02/09/2015 08:26 AM, Chris Mohler wrote: On 02/09/2015 09:48 AM, Rich Megginson wrote: On 02/08/2015 08:23 PM, Chris Mohler wrote: Thanks for the reply and the link Rich! dbmon.sh is a handy tool

[Freeipa-users] admin password is always expired

2015-02-09 Thread Roderick Johnstone
Hi I seem to have locked myself out of my ipa admin account (on RHEL 6.6). This is an evaluation instance so not too big a deal, but a good learning experience. I suspect its some changes that I made to the password policy that caused this. The admin account has expired and I'm trying to

Re: [Freeipa-users] error install replication

2015-02-09 Thread Dmitri Pal
On 02/09/2015 08:34 AM, alireza baghery wrote: yes try ssh admin@hostname but do not work log secure- Feb 9 15:42:20 ipasrv sshd[13414]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.30.160.20 user=admin Feb 9 15:42:20 ipasrv

Re: [Freeipa-users] error install replication

2015-02-09 Thread alireza baghery
thanks On Mon, Feb 9, 2015 at 6:42 PM, Martin Kosek mko...@redhat.com wrote: On 02/09/2015 03:31 PM, Dmitri Pal wrote: On 02/09/2015 08:34 AM, alireza baghery wrote: yes try ssh admin@hostname but do not work log secure- Feb 9 15:42:20 ipasrv sshd[13414]: pam_unix(sshd:auth):