Re: [Freeipa-users] FreeIPA certificate for Outlook

2015-08-18 Thread Martin Basti
On 08/18/2015 01:02 PM, Günther J. Niederwimmer wrote: Hello, is it possible to export a CA / certificate for a windows client outlook when yes, can any tell me the correct file? Thanks for a answer -- mit freundlichen Grüssen / best regards, Günther J. Niederwimmer Hi, IPA CA

Re: [Freeipa-users] FreeIPA certificate for Outlook

2015-08-18 Thread Simo Sorce
On Tue, 2015-08-18 at 13:51 +0200, Martin Basti wrote: On 08/18/2015 01:02 PM, Günther J. Niederwimmer wrote: Hello, is it possible to export a CA / certificate for a windows client outlook when yes, can any tell me the correct file? Thanks for a answer -- mit

[Freeipa-users] FreeIPA certificate for Outlook

2015-08-18 Thread Günther J . Niederwimmer
Hello, is it possible to export a CA / certificate for a windows client outlook when yes, can any tell me the correct file? Thanks for a answer -- mit freundlichen Grüssen / best regards, Günther J. Niederwimmer -- Manage your subscription for the Freeipa-users mailing list:

Re: [Freeipa-users] HBAC rules not applying to Solaris clients

2015-08-18 Thread Martin Kosek
On 08/15/2015 07:05 PM, Natxo Asenjo wrote: On Sat, Aug 15, 2015 at 5:24 PM, Rob Crittenden rcrit...@redhat.com mailto:rcrit...@redhat.com wrote: sipazzo wrote: and my users are able to authenticate to the directory but the hbac rules are not being applied. Any user

Re: [Freeipa-users] migrating openldap 2

2015-08-18 Thread Martin Kosek
On 08/07/2015 03:25 PM, Marcelo Roccasalva wrote: Hi, I need to migrate an ldap tree from openldap 2 (including qmail schema). Which would be the shortest path? I see there was no reply to the mail. I would suggest including more details about what you are trying to achieve. FreeIPA does not

Re: [Freeipa-users] time restricted access

2015-08-18 Thread Martin Kosek
On 08/13/2015 05:11 PM, David Kupka wrote: On 13/08/15 17:01, Marcelo Roccasalva wrote: Hello, I've installed freeIPA 4.1.0 under CentOS 7 and I need to restric authentication to one or more time ranges but I failed to find such a configuration... TIA Hello, you're probably looking for

Re: [Freeipa-users] Different shell for different systems

2015-08-18 Thread David Kupka
On 18/08/15 20:47, Wood Peter wrote: Is it possible to setup different user shell for different systems? I want users to have /bin/bash on all systems but I'd like them to get /usr/bin/git-shell on some systems that serve git repositories. Any idea how to achieve that? Thank you, -- Peter

Re: [Freeipa-users] Sudden replication failure

2015-08-18 Thread Martin Kosek
On 08/10/2015 10:05 PM, Burke Rosen wrote: Hello, I'm running two replicated freeIPA servers. One of them spontaneously failed. After taking the misbehaving server down, the remaining replicant handled everything fine. I restored the system to its original working state by uninstalling

[Freeipa-users] Different shell for different systems

2015-08-18 Thread Wood Peter
Is it possible to setup different user shell for different systems? I want users to have /bin/bash on all systems but I'd like them to get /usr/bin/git-shell on some systems that serve git repositories. Any idea how to achieve that? Thank you, -- Peter -- Manage your subscription for the

Re: [Freeipa-users] ipa v4 on CentOS6

2015-08-18 Thread Martin Kosek
On 08/17/2015 01:15 PM, Ramy Allam wrote: Hello, I'm running ipa-server-4.1.0-18.el7.centos.4.x86_64 on a CentoOS 7 machine. And need to setup ipa-4.1.0 on a CentOS *6* machine. CentOS 6 repo has ipa-client-3 available. Where can i find v4 for CentOS 6 please ? The reason i need to setup

[Freeipa-users] freeipa on http?

2015-08-18 Thread Janelle
Hi, Is there a way to force freeipa web server to accept http requests and not redirect to https? Reason is simple - offloading SSL to a load balancer on the front end. (this is for web only, not the LDAP or Kerberos) Thank you ~J -- Manage your subscription for the Freeipa-users mailing

[Freeipa-users] Public Key Authentication Failing

2015-08-18 Thread Yogesh Sharma
Team. We are using public key authentication instead of password. It was working fine but a day latter it has stopped working. The same key is working for if change the username. For eg: Initially we created a user - ipa1 with ssh public key, but after sometime it has stopped working, now the

Re: [Freeipa-users] Public Key Authentication Failing

2015-08-18 Thread Yogesh Sharma
Majority of sssd logs are filled with below error: (Wed Aug 19 01:22:24 2015) [sssd[be[klikpay.int]]] [sdap_idmap_domain_has_algorithmic_mapping] (0x0080): Could not parse domain SID from [(null)] (Wed Aug 19 01:22:24 2015) [sssd[be[klikpay.int]]] [sdap_idmap_domain_has_algorithmic_mapping]

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Simo Sorce
On Tue, 2015-08-18 at 18:01 -0400, Simo Sorce wrote: The load balancer would have to have the exact same name (for the clients) as the IPA server, which may be challenging depending on the network configuration you have. More on that issue here: http://ssimo.org/blog/id_019.html On Tue,

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Simo Sorce
On Tue, 2015-08-18 at 17:44 -0700, Janelle wrote: Simo, I read your blog sometime ago and do like it. However in this case, this is only for HTTPS, not kerberos, so the names do not have to match. It is for users managing accounts across any number of hosts. But thank you. There is still

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Rob Crittenden
Janelle wrote: Hi, Is there a way to force freeipa web server to accept http requests and not redirect to https? Reason is simple - offloading SSL to a load balancer on the front end. (this is for web only, not the LDAP or Kerberos) Thank you ~J You could try disabling the rewrite rules to

Re: [Freeipa-users] Different shell for different systems

2015-08-18 Thread Peter Wood
Exactly what I needed. Thank you David. On Tue, Aug 18, 2015 at 12:06 PM, David Kupka dku...@redhat.com wrote: On 18/08/15 20:47, Wood Peter wrote: Is it possible to setup different user shell for different systems? I want users to have /bin/bash on all systems but I'd like them to get

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Janelle
Simo, I read your blog sometime ago and do like it. However in this case, this is only for HTTPS, not kerberos, so the names do not have to match. It is for users managing accounts across any number of hosts. But thank you. ~J On 8/18/15 3:02 PM, Simo Sorce wrote: On Tue, 2015-08-18 at

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Janelle
Tried that -- but it gives a blank screen. I will try playing with it some more. At least I know we are thinking in the same ballpark Thank you ~J On 8/18/15 1:55 PM, Rob Crittenden wrote: Janelle wrote: Hi, Is there a way to force freeipa web server to accept http requests and not

Re: [Freeipa-users] freeipa on http?

2015-08-18 Thread Simo Sorce
The load balancer would have to have the exact same name (for the clients) as the IPA server, which may be challenging depending on the network configuration you have. On Tue, 2015-08-18 at 14:58 -0700, Janelle wrote: Tried that -- but it gives a blank screen. I will try playing with it some