[Freeipa-users] OTP and Laptops

2015-07-27 Thread John Johnson
Hello, I'm wondering where/how I could get some more information about the underpinnings of the OTP token mechanisms? Ultimately, I'd like to understand the reason why OTP in FreeIPA doesn't work at the moment with laptops, specifically. -- Manage your subscription for the Freeipa-users mailing

Re: [Freeipa-users] OTP and Laptops

2015-07-27 Thread Janelle
Depending on the laptop -- assuming you are trying to kinit from a terminal window, check the version of Kerberos. It needs to be at least 1.6. ~J On 7/27/15 7:48 AM, John Johnson wrote: Hello, I'm wondering where/how I could get some more information about the underpinnings of the OTP

[Freeipa-users] AD trust deployment without IPA authority over reverse lookup zone

2015-07-27 Thread John Stein
Hi, I consider deploying IPA in my organization.The environment is disconnected from the internet.I have some concerns I'm not sure how to resolve. The environment consists mostly of windows servers (thousands) and workstations (ten thousand) managed by AD (CORP.COM). There is also a small linux

Re: [Freeipa-users] AD trust deployment without IPA authority over reverse lookup zone

2015-07-27 Thread Alexander Bokovoy
On Mon, 27 Jul 2015, John Stein wrote: Hi, I consider deploying IPA in my organization.The environment is disconnected from the internet.I have some concerns I'm not sure how to resolve. The environment consists mostly of windows servers (thousands) and workstations (ten thousand) managed by

Re: [Freeipa-users] OTP and Laptops

2015-07-27 Thread John Johnson
Kerberos version is 1.12.2 on RHEL7.1. I guess I'm wondering if the issue is hardware-related, somehow specific to laptops; or if it's related to the way laptops are assumed to be used, i.e. portable, etc. On Mon, Jul 27, 2015 at 10:14 AM, Janelle janellenicol...@gmail.com wrote: Depending on

Re: [Freeipa-users] OTP and Laptops

2015-07-27 Thread Rob Crittenden
John Johnson wrote: Kerberos version is 1.12.2 on RHEL7.1. I guess I'm wondering if the issue is hardware-related, somehow specific to laptops; or if it's related to the way laptops are assumed to be used, i.e. portable, etc. It would be helpful if you described what isn't working. rob On

Re: [Freeipa-users] OTP and Laptops

2015-07-27 Thread John Johnson
I'm not saying that something isn't working for me; I'm going off the information available on https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System-Level_Authentication_Guide/authconfig-addl-auth.html#otp-laptop-users and a thread in this mailing list referencing

Re: [Freeipa-users] Failed to start pki-tomcatd Service

2015-07-27 Thread Alexander Bokovoy
On Sun, 26 Jul 2015, Alexandre Ellert wrote: 2015-07-23 8:41 GMT+02:00 Alexander Bokovoy aboko...@redhat.com: On Thu, 23 Jul 2015, Ludwig Krispenz wrote: - Directory server starts just fine but serves only port 389 - krb5kdc starts just fine and works fine with LDAP server - Dogtag tries to

Re: [Freeipa-users] OTP and Laptops

2015-07-27 Thread Alexander Bokovoy
On Mon, 27 Jul 2015, John Johnson wrote: I'm not saying that something isn't working for me; I'm going off the information available on https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/System-Level_Authentication_Guide/authconfig-addl-auth.html#otp-laptop-users and a