Re: [Freeipa-users] ipactl services running, but auth not working

2017-02-06 Thread Aaron Collins
It sounds like your IPA service is hanging. The fastest way to check is do an ldap search against that host to see if it replies. If it doesn’t look under /var/log/dirvsrv/sapd-$INSTANCE-NAME/error to see if you have an error. I’ve seen this with the out of fd error, or if you server is in a

Re: [Freeipa-users] IPA replica issue

2017-02-06 Thread Giorgio Biacchi
On 02/06/2017 05:14 PM, Giorgio Biacchi wrote: On 02/06/2017 04:54 PM, Rob Crittenden wrote: Giorgio Biacchi wrote: Hi list, I have this message in the logs: Feb 6 16:43:10 dc01 ns-slapd: [06/Feb/2017:16:43:10.157801305 +0100] NSMMReplicationPlugin -

Re: [Freeipa-users] IPA replica issue

2017-02-06 Thread Giorgio Biacchi
On 02/06/2017 04:54 PM, Rob Crittenden wrote: Giorgio Biacchi wrote: Hi list, I have this message in the logs: Feb 6 16:43:10 dc01 ns-slapd: [06/Feb/2017:16:43:10.157801305 +0100] NSMMReplicationPlugin - agmt="cn=masterAgreement1-dc02.myorg.local-pki-tomcat" (dc02:389): Data required to

Re: [Freeipa-users] IPA replica issue

2017-02-06 Thread Rob Crittenden
Giorgio Biacchi wrote: > Hi list, > I have this message in the logs: > > Feb 6 16:43:10 dc01 ns-slapd: [06/Feb/2017:16:43:10.157801305 +0100] > NSMMReplicationPlugin - > agmt="cn=masterAgreement1-dc02.myorg.local-pki-tomcat" (dc02:389): Data > required to update replica has been purged from the

Re: [Freeipa-users] Needs help understand this timeout issue

2017-02-06 Thread Sullivan, Daniel [CRI]
Have you looked at the ignore_group_members option? Maybe this is the problem you are seeing? https://jhrozek.wordpress.com/2015/08/19/performance-tuning-sssd-for-large-ipa-ad-trust-deployments/ ==snip== ignore_group_members Normally the most data-intensive operation is downloading the groups

Re: [Freeipa-users] client in many IPA domains

2017-02-06 Thread David Kupka
On Fri, Feb 03, 2017 at 02:04:55PM -0200, Raul Dias wrote: > Hello, > > Can ipa-client (e.g., anotebook) be in more than one realm? e.g. depending > on the network where it is connected. > > -rsd > > -- > Manage your subscription for the Freeipa-users mailing list: >

Re: [Freeipa-users] IPA replica setup for version 4.4

2017-02-06 Thread Martin Basti
On 04.02.2017 10:21, deepak dimri wrote: I am trying to install ipa replica but getting below error when running ipa-replica-install i am following below link for ipa 4.4:

Re: [Freeipa-users] VERSION: 4.4.0, IPA Replica DOES NOT Work

2017-02-06 Thread Alexander Bokovoy
On la, 04 helmi 2017, deepak dimri wrote: I am wondering Does IPA Replica as standalone without IPA Master being up works for you guys? Mine and my collogue IPA setup in our own Dev environment with VERSION: 4.2 works perfectly fine. but now when we are moving to staging env we are getting IPA

Re: [Freeipa-users] Needs help understand this timeout issue

2017-02-06 Thread Troels Hansen
Hi I'm aware of the anatomy of how the lookup is done, but I would suppose a valid cache on the IPA server would result in the cache from the IPA server being used? I have been debugging this issue some more, and can confirm is the client have its sssd cache invalidated by "sss_cache -E" and