Re: [Freeipa-users] rhel 6.7 upgrade - sssd/sudo

2015-09-30 Thread Andy Thompson
> On Wed, Sep 30, 2015 at 12:17:22PM +, Andy Thompson wrote: > > > On 09/21/2015 10:42 PM, Andy Thompson wrote: > > > >> On Mon, Sep 21, 2015 at 07:39:01PM +, Andy Thompson wrote: > > > -Original Message- > > > From: Jakub Hrozek [mailto:jhro...@redhat.com] > > >

Re: [Freeipa-users] NFS Automount Domain Homedirs

2015-09-30 Thread Sadettin Albasan
Here is a list of installed sssd packages: sssd-client-1.12.4-47.el6.x86_64 sssd-common-1.12.4-47.el6.x86_64 sssd-ad-1.12.4-47.el6.x86_64 sssd-1.12.4-47.el6.x86_64 python-sssdconfig-1.12.4-47.el6.noarch sssd-krb5-common-1.12.4-47.el6.x86_64 sssd-ipa-1.12.4-47.el6.x86_64

[Freeipa-users] Trust Issues W/ Logins on Windows Desktops

2015-09-30 Thread Matt Wells
Hi all, I hoped I may glean some brilliance from the group. I have a Freeipa Server sitting atop a Fedora 21 server. The initial plan was to replicate users+passwords with Windows 2012R2 server but following some of the information in the other posts and docs we've moved to a trust. The trust

[Freeipa-users] Weird error when attempting to create a new 3.0.0 replica with CA - Could really use some help

2015-09-30 Thread Alex Williams
Hi guys, I'm new to the list and I've got a really strange error when trying to create a new 3.0.0 replica of our existing 3.0.0 servers, with CA. I can create a replica without the CA, but once this replica is created, I need to disconnect it, upgrade the schema and hang a 4.0.0 server off

Re: [Freeipa-users] FreeIPA with third-party wildcard certificate

2015-09-30 Thread Martin Kosek
FreeIPA allows running with CA-less mode, where there is no CA and FreeIPA simply users the offered CA/LDAP certificates: http://www.freeipa.org/page/PKI#Blending_in_PKI_infrastructure Some information is also here:

Re: [Freeipa-users] rhel 6.7 upgrade - sssd/sudo

2015-09-30 Thread Andy Thompson
> On 09/21/2015 10:42 PM, Andy Thompson wrote: > >> On Mon, Sep 21, 2015 at 07:39:01PM +, Andy Thompson wrote: > -Original Message- > From: Jakub Hrozek [mailto:jhro...@redhat.com] > Sent: Monday, September 21, 2015 3:29 PM > To: Andy Thompson

Re: [Freeipa-users] What todo when a company/domain name should be changed ?

2015-09-30 Thread Martin Kosek
On 09/27/2015 01:34 PM, Matt . wrote: > Hi All, > > I'm investigating what the possibillities are when you have a existing > domain/realm and the company name is changed, so the domain should be > also. I came on this idea because of I wanted to know how flexible the > integration is here. > >

Re: [Freeipa-users] rhel 6.7 upgrade - sssd/sudo

2015-09-30 Thread Jakub Hrozek
On Wed, Sep 30, 2015 at 12:17:22PM +, Andy Thompson wrote: > > On 09/21/2015 10:42 PM, Andy Thompson wrote: > > >> On Mon, Sep 21, 2015 at 07:39:01PM +, Andy Thompson wrote: > > -Original Message- > > From: Jakub Hrozek [mailto:jhro...@redhat.com] > > Sent: Monday,

Re: [Freeipa-users] HBAC

2015-09-30 Thread Martin Kosek
On 09/30/2015 07:50 AM, Alexander Bokovoy wrote: > On Tue, 29 Sep 2015, TomK wrote: >> Hey Guy's, >> >> (Sending this again as I didn't have this email included in the freeipa-users >> mailing list so not sure if the other message will get posted.) >> >> Before I post a ticket to RH Support for an

[Freeipa-users] System for Cross-domain Identity Management (SCIM) support?

2015-09-30 Thread Petr Spacek
Dear users, we have few questions for you: 1) Would you like to see support for SCIM protocol in FreeIPA? 2) What are your use-cases? Further reading: * Presentations about SCIM from LDAPCon: http://lanyrd.com/2013/ldapcon/ * Quote from RFC 7642: 1. Introduction [...] Unlike the practice

Re: [Freeipa-users] What todo when a company/domain name should be changed ?

2015-09-30 Thread Simo Sorce
On 30/09/15 07:57, Martin Kosek wrote: On 09/27/2015 01:34 PM, Matt . wrote: Hi All, I'm investigating what the possibillities are when you have a existing domain/realm and the company name is changed, so the domain should be also. I came on this idea because of I wanted to know how flexible

Re: [Freeipa-users] NFS Automount Domain Homedirs

2015-09-30 Thread Sadettin Albasan
Hi Alexander, Currently; FreeIPA 7.1 (Centos) Client 6.6 (Centos) NFS 6.6 (Centos) + Samba 3.6 I have also samba file sharing running on NFS server which shares home directories to windows users as well. So NFS server is joined to windows domain as well as FreeIPA domain. *FreeIPA Server

Re: [Freeipa-users] HBAC

2015-09-30 Thread TomK
On 9/30/2015 8:12 AM, Martin Kosek wrote: On 09/30/2015 07:50 AM, Alexander Bokovoy wrote: On Tue, 29 Sep 2015, TomK wrote: Hey Guy's, (Sending this again as I didn't have this email included in the freeipa-users mailing list so not sure if the other message will get posted.) Before I post

Re: [Freeipa-users] NFS Automount Domain Homedirs

2015-09-30 Thread Alexander Bokovoy
On Wed, 30 Sep 2015, Sadettin Albasan wrote: Hi Alexander, Currently; FreeIPA 7.1 (Centos) Client 6.6 (Centos) NFS 6.6 (Centos) + Samba 3.6 I have also samba file sharing running on NFS server which shares home directories to windows users as well. So NFS server is joined to windows domain

Re: [Freeipa-users] NFS Automount Domain Homedirs

2015-09-30 Thread Sadettin Albasan
*idmap.conf for NFS Server:* [General] #Verbosity = 0 # The following should be set to the local NFSv4 domain name # The default is the host's DNS domain name. #Domain = local.domain.edu # The following is a comma-separated list of Kerberos realm # names that should be considered to be

Re: [Freeipa-users] NFS Automount Domain Homedirs

2015-09-30 Thread Alexander Bokovoy
On Wed, 30 Sep 2015, Sadettin Albasan wrote: *idmap.conf for NFS Server:* [General] #Verbosity = 0 # The following should be set to the local NFSv4 domain name # The default is the host's DNS domain name. #Domain = local.domain.edu # The following is a comma-separated list of Kerberos realm #

Re: [Freeipa-users] password resets - errors

2015-09-30 Thread Janelle
On 9/28/15 11:33 AM, Rob Crittenden wrote: Simo Sorce wrote: On 27/09/15 09:21, Janelle wrote: Hello, I continue to see these a lot, but only on some servers. It causes a lot of confusions with my users. There must be a way to troubleshoot this and find the issue. Also, there is nothing wrong