Re: [Freeipa-users] multi-tenancy status

2015-02-24 Thread Rob Verduijn
Now that sounds like an interesting project :-) besides the following links any other places where I can read up about it ? https://fedorahosted.org/ipsilon/ http://www.freeipa.org/page/Web_App_Authentication http://en.wikipedia.org/wiki/Identity_provider

Re: [Freeipa-users] multi-tenancy status

2015-02-24 Thread Rob Crittenden
Rob Verduijn wrote: Now that sounds like an interesting project :-) besides the following links any other places where I can read up about it ? https://fedorahosted.org/ipsilon/ http://www.freeipa.org/page/Web_App_Authentication http://en.wikipedia.org/wiki/Identity_provider

Re: [Freeipa-users] multi-tenancy status

2015-02-24 Thread Rob Verduijn
Thanx, That all sounds very interesting, I've got some reading up to do. I'm going to point this out to some people :-) Rob 2015-02-24 20:55 GMT+01:00 Rob Crittenden rcrit...@redhat.com: Rob Verduijn wrote: Now that sounds like an interesting project :-) besides the following links any

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Jani West
Re-created replication file and run ipa-replica-install o fresh CentOS 7 server. It is still giving the same error: - 2015-02-24T21:40:54Z DEBUG Process finished, return code=1 2015-02-24T21:40:54Z DEBUG stdout=Loading deployment configuration from /tmp/tmpR56_Ck.

Re: [Freeipa-users] Identifying current CA master

2015-02-24 Thread Thomas Raehalme
Hi! On Mon, Feb 23, 2015 at 10:29 AM, Martin Kosek mko...@redhat.com wrote: Good question. You are most likely hitting bug https://bugzilla.redhat.com/show_bug.cgi?id=1178190 that is planned to be fixed in RHEL-6.7. It should only affect the display of the values, the actual storage and

[Freeipa-users] Root overrides HBAC rules for the command su

2015-02-24 Thread Bloemen , Jurriën
Hi, In FreeIPA you can create users and restrict on which hosts the user can login to. This is all great and works fine. If a user1 is logged in to a system. Knows the password of user2 and issues the command su to be that user2 on that same system. This is not allowed because the user2 does

Re: [Freeipa-users] Centos 7 No permission to /home/..

2015-02-24 Thread Günther J . Niederwimmer
Am Montag, 23. Februar 2015, 20:20:45 schrieb Jakub Hrozek: On Mon, Feb 23, 2015 at 05:29:32PM +0100, Günther J. Niederwimmer wrote: I tested all (?), I have configured a ntp /mount for /home, Create a /home/user directory only on the ipa-server, nothing is working I have allways permission

Re: [Freeipa-users] Root overrides HBAC rules for the command su

2015-02-24 Thread Sumit Bose
On Tue, Feb 24, 2015 at 09:15:11AM +, Bloemen, Jurriën wrote: Hi, In FreeIPA you can create users and restrict on which hosts the user can login to. This is all great and works fine. If a user1 is logged in to a system. Knows the password of user2 and issues the command su to be

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Rob Crittenden
West, Jani wrote: Hi, Validity, status and serials seems to be fine. One interesting pick: While the installation is not too old it might be installed initially with FreeIpa 2.x That's why i have to use ldap port 7389 instead of 398. # getcert list |grep expires expires: 2016-11-21

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread West, Jani
Thank you for the tip, Just created new /root/cacerts.p12. Should I import it to the CA somehow or just restart the ipa server? Will reset the new replicate vm to clean CentOS 7 installation without any leftovers from ipa-replica-install. -- -- Jani West On 24.2.2015 17:06, Rob Crittenden

[Freeipa-users] Reg:FreeIPA Client Configuration

2015-02-24 Thread Veera Veluchamy
Hi, I have configure FreeIPA server in centos and synchronized with windows active directory .If I create any users in AD it will be automatically synchronized with IPAServer . But I'm unable to configure IPA client in my centos machine which is installed on another machine.

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Rob Crittenden
West, Jani wrote: Thank you for the tip, Just created new /root/cacerts.p12. Should I import it to the CA somehow or just restart the ipa server? Will reset the new replicate vm to clean CentOS 7 installation without any leftovers from ipa-replica-install. Re-run ipa-replica-prepare

Re: [Freeipa-users] multi-tenancy status

2015-02-24 Thread Dmitri Pal
On 02/24/2015 12:34 PM, Rob Verduijn wrote: Hello, I'm interested in setting up ipa with multiple tenancies. However I can only find this document about the subject: http://www.freeipa.org/page/V3/Multitenancy What is the status of the implementation of multiple tenancies. Unscheduled. Too

[Freeipa-users] multi-tenancy status

2015-02-24 Thread Rob Verduijn
Hello, I'm interested in setting up ipa with multiple tenancies. However I can only find this document about the subject: http://www.freeipa.org/page/V3/Multitenancy What is the status of the implementation of multiple tenancies. Cheers Rob Verduijn -- Manage your subscription for the

Re: [Freeipa-users] ipa-getcert list fails to report correctly - RESOLVED

2015-02-24 Thread Les Stott
-Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users- boun...@redhat.com] On Behalf Of Les Stott Sent: Monday, 23 February 2015 8:01 PM To: Rob Crittenden; Martin Kosek; freeipa-users@redhat.com; Endi Dewata; Jan Cholasta Subject: Re: [Freeipa-users]

Re: [Freeipa-users] bug in pki during install of CA replica and workaround/solution - RESOLVED

2015-02-24 Thread Les Stott
Have resolved the issues below by completely removing FreeIPA and starting from scratch. Here is the procedure to completely remove FreeIPA so you can start again. ipa-server-install --uninstall certutil -d /etc/httpd/alias -D -n Server-Cert certutil -d /etc/httpd/alias -D -n MYDOMAIN.COM IPA

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Jani West
On old master apache logs looks like this: --- [Tue Feb 24 23:37:40 2015] [error] [client 192.168.177.8] File does not exist: /var/www/html/ca [Tue Feb 24 23:37:41 2015] [error] [client 192.168.177.8] File does not exist: /var/www/html/ca [Tue Feb 24 23:38:22 2015] [error] [client

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Rob Crittenden
Jani West wrote: Re-created replication file and run ipa-replica-install o fresh CentOS 7 server. It is still giving the same error: - 2015-02-24T21:40:54Z DEBUG Process finished, return code=1 2015-02-24T21:40:54Z DEBUG stdout=Loading deployment configuration from

Re: [Freeipa-users] Migration fails from 3.0.0 to 3.3.3 on Centos 6/7

2015-02-24 Thread Rob Crittenden
Jani West wrote: On old master apache logs looks like this: --- [Tue Feb 24 23:37:40 2015] [error] [client 192.168.177.8] File does not exist: /var/www/html/ca [Tue Feb 24 23:37:41 2015] [error] [client 192.168.177.8] File does not exist: /var/www/html/ca [Tue Feb 24 23:38:22