[Freeipa-users] IPA sporadic behavior

2016-03-24 Thread John Williams
I've got some sporadic behavior on my IPA instance and I'm hoping someone can help me resolve the issue.  The problem is that many times my clients cannot authenticate to the respective hosts.  First, my environment.  Some details: ipa2 - centos 6.3 -  ipa server 3.0.0ipa3 - centos 7.1 - ipa

[Freeipa-users] Announcing FreeIPA 4.3.1

2016-03-24 Thread Petr Vobornik
The FreeIPA team would like to announce FreeIPA v4.3.1 bug fixing release! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds are available for Fedora 24 and rawhide. Builds for Fedora 23 are available in the official COPR

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Christophe TREFOIS
Hi, Are you not missing “sudo” in [sssd] and did you restard the services on the machine? We found quite a significant cache, which sometimes lead to asking passwords. https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Deployment_Guide/sssd-ldap-sudo.html You might

Re: [Freeipa-users] Lock screen when Smart Card is removed.

2016-03-24 Thread Michael Rainey (Contractor)
Hi Sumit, Your test packages and configuration changes are working very well. I See no issues with the two machines on which the fixes were applied. The two systems are running Scientific LInux 7.2 and Centos 7.2. I will continue to perform more tests to see if there are any issues. I do

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Ash Alam
I should clarify. I was just following the fedora/ipa docs. My Ipa servers are Centos 7.2 and Ipa 4.2. Clients are Centos 6.6 and 3.0.0 $ rpm -q sssd ipa-client sssd-1.11.6-30.el6_6.3.x86_64 ipa-client-3.0.0-42.el6.centos.x86_64 On Thu, Mar 24, 2016 at 3:04 PM, Rob Crittenden

Re: [Freeipa-users] IPA command to batch create users.

2016-03-24 Thread Rob Crittenden
Natxo Asenjo wrote: hi, On Thu, Mar 24, 2016 at 8:14 PM, Armstrong, Jeffrey > wrote: Hello, __ __ I would like to find out if I can create a large number of users in IPA at one time. If so, what is the

Re: [Freeipa-users] IPA command to batch create users.

2016-03-24 Thread Natxo Asenjo
hi, On Thu, Mar 24, 2016 at 8:14 PM, Armstrong, Jeffrey < jeffrey.armstr...@gasoc.com> wrote: > Hello, > > > > I would like to find out if I can create a large number of users in IPA at > one time. If so, what is the command to do that. > > > you can use ipa user-add command in a bash loop, or

[Freeipa-users] IPA command to batch create users.

2016-03-24 Thread Armstrong, Jeffrey
Hello, I would like to find out if I can create a large number of users in IPA at one time. If so, what is the command to do that. Jeff -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Rob Crittenden
Ash Alam wrote: Based on (How to troubleshoot Sudo) - Maybe i miss spoke when i said it fails completely. Rather it keeps asking for the users password which it does not accept. - I do not have sudo in sssd.conf - I do not have sudoers: sss defined in nsswitch.conf - Per Fedora/Freeipa doc

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Ash Alam
Based on (How to troubleshoot Sudo) - Maybe i miss spoke when i said it fails completely. Rather it keeps asking for the users password which it does not accept. - I do not have sudo in sssd.conf - I do not have sudoers: sss defined in nsswitch.conf - Per Fedora/Freeipa doc (Defining Sudo), its

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Brad Bendy
What's your config look like in the GUI? Long as you assign the users to the group and everything it should work. Your sssd.conf file shows sudo in there as well? On Thu, Mar 24, 2016 at 9:21 AM, Ash Alam wrote: > Hello > > I am looking for some guidance on how to

Re: [Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Jakub Hrozek
> On 24 Mar 2016, at 17:21, Ash Alam wrote: > > Hello > > I am looking for some guidance on how to properly do sudo with Freeipa. I > have read up on what i need to do but i cant seem to get to work correctly. > Now with sudoers.d i can accomplish this fairly

[Freeipa-users] Freeipa Sudo / sudoers.d / nopasswd

2016-03-24 Thread Ash Alam
Hello I am looking for some guidance on how to properly do sudo with Freeipa. I have read up on what i need to do but i cant seem to get to work correctly. Now with sudoers.d i can accomplish this fairly quickly. Example: %dev ALL=(ALL) NOPASSWD:/usr/bin/chef-client What i have configured in

[Freeipa-users] 7.x replica install from 6.x master fails

2016-03-24 Thread Ott, Dennis
I am trying to migrate from OS 6.x / IPA 3.0 to OS 7.x / IPA 4.x. After working through and solving a few issues, my current efforts fail when setting up the replica CA. If I set up a new, pristine master on OS 6.7, I am able to create an OS 7.x replica without any problem. However, if I try

Re: [Freeipa-users] Lock screen when Smart Card is removed.

2016-03-24 Thread Sumit Bose
On Wed, Mar 23, 2016 at 12:25:50PM -0500, Michael Rainey (Contractor) wrote: > Hi Sumit, > > I've trying to download the rpm via the Koji client and have been unable to > locate package. Are there any extra steps I need to complete before I can > find the package, such as, create an account in

Re: [Freeipa-users] Can't Search For Users

2016-03-24 Thread Petr Spacek
On 23.3.2016 17:52, Garrett Hyde wrote: > I'm currently running ipa-server version 4.2.0, release 15.el7_2.6 on a > RHEL 7.2 server. > > When a user **not** in the "admins" group tries searching for a user, they > receive "No entries." In the WebUI, this happens on the "Active users" page > or