Re: [Freeipa-users] ipa-replica-prepare error

2015-07-20 Thread Jan Cholasta
Dne 15.7.2015 v 20:57 Orion Poplawski napsal(a): On 07/14/2015 11:53 PM, Jan Cholasta wrote: Hi, Dne 10.7.2015 v 22:33 Orion Poplawski napsal(a): On 07/08/2015 11:31 AM, Orion Poplawski wrote: But then when I go to make a replica: # ipa-replica-prepare ipa1.nwra.com

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-07-20 Thread Rich Megginson
On 07/20/2015 07:56 AM, Christopher Lamb wrote: Hi Rob The users do have the sambaSamAccount ObjectClass. Or to be more precise, some have sambasamaccount (all lower case), and some have sambaSAMAccount (mixed case) Are objectclasses case sensitive? No, unless there is a bug in the

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-07-20 Thread Christopher Lamb
Hi Alexander This issue got overtaken by others, and slipped off my radar for a bit... While the solution suggested earlier in this thread at http://www.freeipa.org/page/Howto/Integrating_a_Samba_File_Server_With_IPA sounds interesting (and we are running the correct versions of OEL 7.1 and

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-07-20 Thread Alexander Bokovoy
On Mon, 20 Jul 2015, Rob Crittenden wrote: Christopher Lamb wrote: Hi Alexander This issue got overtaken by others, and slipped off my radar for a bit... While the solution suggested earlier in this thread at http://www.freeipa.org/page/Howto/Integrating_a_Samba_File_Server_With_IPA sounds

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-07-20 Thread Christopher Lamb
Hi Rob The users do have the sambaSamAccount ObjectClass. Or to be more precise, some have sambasamaccount (all lower case), and some have sambaSAMAccount (mixed case) Are objectclasses case sensitive? Chris From: Rob Crittenden rcrit...@redhat.com To: Christopher

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-07-20 Thread Christopher Lamb
ldapsearch -x -h localhost -p 389 -b dc=my,dc=silly,dc=example,dc=com ((objectClass=sambaSamAccount)(uid=bilbo)) and ldapsearch -x -h localhost -p 389 -b dc=my,dc=silly,dc=example,dc=com ((objectClass=sambaSAMAccount)(uid=bilbo)) and ldapsearch -x -h localhost -p 389 -b

Re: [Freeipa-users] Failed to start pki-tomcatd Service

2015-07-20 Thread Alexandre Ellert
Can you please show output from fgrep -r 'dc' /etc/dirsrv/slapd-INSTANCE/schema # fgrep -r 'dc' /etc/dirsrv/slapd-NUMEEZY-FR/schema /etc/dirsrv/slapd-NUMEEZY-FR/schema/00core.ldif:attributeTypes: ( 0.9.2342.19200300.100.1.25 NAME ( 'dc' 'domaincomponent' )

Re: [Freeipa-users] ipa-replica-prepare error

2015-07-20 Thread Orion Poplawski
On 07/20/2015 12:57 AM, Jan Cholasta wrote: Dne 15.7.2015 v 20:57 Orion Poplawski napsal(a): On 07/14/2015 11:53 PM, Jan Cholasta wrote: # ipa-replica-prepare -v ipa1.nwra.com --dirsrv_pkcs12=nwra.com.p12 --dirsrv_pin=XX --http_pkcs12=nwra.com.p12 --http_pin=XX Directory

Re: [Freeipa-users] Failed to start pki-tomcatd Service

2015-07-20 Thread Alexander Bokovoy
On Mon, 20 Jul 2015, Alexandre Ellert wrote: Can you please show output from fgrep -r 'dc' /etc/dirsrv/slapd-INSTANCE/schema # fgrep -r 'dc' /etc/dirsrv/slapd-NUMEEZY-FR/schema This is original 'dc' definition: /etc/dirsrv/slapd-NUMEEZY-FR/schema/00core.ldif:attributeTypes: (

Re: [Freeipa-users] Failed to start pki-tomcatd Service

2015-07-20 Thread Alexandre Ellert
Le 20 juil. 2015 à 17:58, Petr Vobornik pvobo...@redhat.com a écrit : On 07/20/2015 05:17 PM, Alexander Bokovoy wrote: On Mon, 20 Jul 2015, Alexandre Ellert wrote: Can you please show output from fgrep -r 'dc' /etc/dirsrv/slapd-INSTANCE/schema # fgrep -r 'dc'

Re: [Freeipa-users] Failed to start pki-tomcatd Service

2015-07-20 Thread Petr Vobornik
On 07/20/2015 05:17 PM, Alexander Bokovoy wrote: On Mon, 20 Jul 2015, Alexandre Ellert wrote: Can you please show output from fgrep -r 'dc' /etc/dirsrv/slapd-INSTANCE/schema # fgrep -r 'dc' /etc/dirsrv/slapd-NUMEEZY-FR/schema This is original 'dc' definition:

[Freeipa-users] Client Certificates not in backlog

2015-07-20 Thread Brian Topping
Hi I was just looking at http://www.freeipa.org/page/User_certificate_use_cases and was trying to do some self-service to see when it might get scheduled. Unless I am mistaken, it doesn't even seem to exist in the backlog. Is that intentional? The reason I started to look at this again is I

Re: [Freeipa-users] Sync useradd from IPA to AD

2015-07-20 Thread Rich Megginson
On 07/20/2015 07:02 AM, Email wrote: Hi Rich, thanks for the reply. Here is the link I working with https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/active-directory-trust.html I'm looking at both options, the cross forest trust and winsync. For my project FreeIPA needs

[Freeipa-users] FreeRadius Authentications (mschapv2)

2015-07-20 Thread William Graboyes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi List, I have run into a snag, I figured I would start here and move forward. I have been searching around for the past 3 or 4 hours looking for some solution to this the issue that I am having. We are doing 802.1x against our freeipa servers.

Re: [Freeipa-users] Client Certificates not in backlog

2015-07-20 Thread Rob Crittenden
Brian Topping wrote: Hi I was just looking at http://www.freeipa.org/page/User_certificate_use_cases and was trying to do some self-service to see when it might get scheduled. Unless I am mistaken, it doesn't even seem to exist in the backlog. Is that intentional? The reason I started to

Re: [Freeipa-users] Client Certificates not in backlog

2015-07-20 Thread Brian Topping
Oh wow, thanks guys! Will watch for it to show up in the CentOS repos! best, Brian On Jul 20, 2015, at 16:44, Rob Crittenden rcrit...@redhat.com wrote: Brian Topping wrote: Hi I was just looking at http://www.freeipa.org/page/User_certificate_use_cases and was trying to do some