Re: [Freeipa-users] Active directory trust and SSH

2016-09-05 Thread Tomas Krizek
On 09/06/2016 07:02 AM, Jim Richard wrote: So I have two-way trust setup and it seems to work. And as described here: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Windows_Integration_Guide/trust-ssh.html SSSD allows user names in the format user@AD.DOMAIN, ad

[Freeipa-users] Active directory trust and SSH

2016-09-05 Thread Jim Richard
So I have two-way trust setup and it seems to work. And as described here: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Windows_Integration_Guide/trust-ssh.html SSSD allows user names in the format user@AD.DOMAIN, ad.domain\user and AD\user That works just as de

Re: [Freeipa-users] Default gid for AD trust users

2016-09-05 Thread Orion Poplawski
On 09/02/2016 03:15 PM, Lukas Slebodnik wrote: On (24/08/16 11:42), Orion Poplawski wrote: While that is definitely *a* convention, it's not the one we've used which puts users by default in shared groups (nwra, visitors, etc). For example: uid=2941(user) gid=1991(nwra) The user "user" shoul

Re: [Freeipa-users] Error by creating a services

2016-09-05 Thread Günther J . Niederwimmer
Hello, Am Montag, 5. September 2016, 17:09:03 schrieb Martin Basti: > On 05.09.2016 16:53, Günther J. Niederwimmer wrote: > > Hello, > > > > CentOs 7.2 > > FreeIPA: 4.2.0-15 > > > > Why is this Error only on one Server ? > > Hello, > > probably you have something DNS related misconfigured on t

Re: [Freeipa-users] Error by creating a services

2016-09-05 Thread Martin Basti
On 05.09.2016 16:53, Günther J. Niederwimmer wrote: Hello, CentOs 7.2 FreeIPA: 4.2.0-15 Why is this Error only on one Server ? Hello, probably you have something DNS related misconfigured on that particular server. Can you resolve hostname manually from server? (host, dig A commands) Ma

[Freeipa-users] Error by creating a services

2016-09-05 Thread Günther J . Niederwimmer
Hello, CentOs 7.2 FreeIPA: 4.2.0-15 Why is this Error only on one Server ? IPA Error 4019: DNSNotARecordError Host does not have corresponding DNS A/ record When I create on a other Server (KVM) a service, this is no Problem, but on my new "mx03.example.com" I have this Errors ? The DNS i

Re: [Freeipa-users] Freeipa 4.2.0 hangs intermittently

2016-09-05 Thread Rakesh Rajasekharan
Hi Thierry, I was getting the hang issue while running ipa-client-install simultaneously on few clients.. However, today, I am not able to replicate that. I could not get a gdb . But i will try getting that the next time I face this issue. The CPU does not stay high.. it just momentarily touche

Re: [Freeipa-users] Freeipa 4.2.0 hangs intermittently

2016-09-05 Thread thierry bordaz
Hi Rakesh, Were you able to get a pstack or full stack with gdb (http://www.port389.org/docs/389ds/FAQ/faq.html#debugging-crashes) when the server hangs ? If it happens with 500 threads as well as with 30, using 30 threads is a better choice to debug this issue. I will try to reproduce usin

Re: [Freeipa-users] SUDO and group lookup in AD trust

2016-09-05 Thread Jakub Hrozek
On Mon, Sep 05, 2016 at 09:02:04AM +0200, Troels Hansen wrote: > > > - On Sep 2, 2016, at 9:56 AM, Jakub Hrozek jhro...@redhat.com wrote: > >> >We were debugging this yesterday with Troels and the logs said it's: > >> >https://fedorahosted.org/sssd/ticket/3127 > >> > > >> Fixed version is

Re: [Freeipa-users] General query regarding nameserver enrtry

2016-09-05 Thread Martin Basti
On 02.09.2016 20:06, Deepak Dimri wrote: Hi All, My ipa-client-install fails until etc/resolve.conf gets updated with IPA nameserver entry. I want to avoid a task of updating resolve.conf in my automation script. Is there a way i can get my IPA client installation successful without upd

Re: [Freeipa-users] SUDO and group lookup in AD trust

2016-09-05 Thread Troels Hansen
- On Sep 2, 2016, at 9:56 AM, Jakub Hrozek jhro...@redhat.com wrote: >> >We were debugging this yesterday with Troels and the logs said it's: >> >https://fedorahosted.org/sssd/ticket/3127 >> > >> Fixed version is in 1.14 copr > > Thank you, btw another affected user confirmed that the pa