Re: [Freeipa-users] Jenkins integration?

2017-02-10 Thread Harald Dunkel
On 02/10/17 15:07, Tomasz Torcz wrote: > On Fri, Feb 10, 2017 at 02:03:48PM +0100, Harald Dunkel wrote: >> Hi folks, >> >> did anybody succeed in using Freeipa for Jenkins' LDAP module? >> I can't make it work :-(. > > I'm using Jenkins with FreeIPA, but not with Jenkins's LDAP. > I have

Re: [Freeipa-users] bind-dyndb-ldap, AXFR and DS records

2017-02-10 Thread Ben Roberts
Hi Tomas, > If I understand you correctly, the primary server is filled with data > using bind-dyndb-ldap from an LDAP backend. Then the DS records are > present on the primary server. At this point, bind-dyndb-ldap's work > should be done, since it only serves as the backend LDAP driver for

Re: [Freeipa-users] [SOLVED] CA not found?

2017-02-10 Thread Guillermo Fuentes
Hi Fraser, Although I modified the ids to release the data, I made sure to use consistent ids where they appeared. As you noted, there was a discrepancy and changing the 'ipacaid' attribute of cn=ipa,cn=cas,cn=ca,dc=ipa,dc=local to match the authorityID from Dogtag fixed the issue. We're now

Re: [Freeipa-users] Jenkins integration?

2017-02-10 Thread Tomasz Torcz
On Fri, Feb 10, 2017 at 02:03:48PM +0100, Harald Dunkel wrote: > Hi folks, > > did anybody succeed in using Freeipa for Jenkins' LDAP module? > I can't make it work :-(. I'm using Jenkins with FreeIPA, but not with Jenkins's LDAP. I have Jenkins set to PAM authentication, which in turn goes

[Freeipa-users] Jenkins integration?

2017-02-10 Thread Harald Dunkel
Hi folks, did anybody succeed in using Freeipa for Jenkins' LDAP module? I can't make it work :-(. On the command line the jenkins user appears to have read access to the LDAP database. The config UI for Jenkin's LDAP plugin doesn't complain, either. Jenkins System Log appears to be fine. But if

Re: [Freeipa-users] replica install - Insufficient 'add' privilege ?

2017-02-10 Thread Martin Babinsky
On 02/10/2017 01:29 PM, lejeczek wrote: hi everyone, I'm trying something mundane(can't think why, how my setup would be special/different) - replica installation - but I hit this: [42/44]: activating extdom plugin [43/44]: tuning directory server [44/44]: configuring directory to start

[Freeipa-users] replica install - Insufficient 'add' privilege ?

2017-02-10 Thread lejeczek
hi everyone, I'm trying something mundane(can't think why, how my setup would be special/different) - replica installation - but I hit this: [42/44]: activating extdom plugin [43/44]: tuning directory server [44/44]: configuring directory to start on boot Done configuring directory

Re: [Freeipa-users] CA not found?

2017-02-10 Thread Fraser Tweedale
On Thu, Feb 09, 2017 at 09:01:01PM -0500, Guillermo Fuentes wrote: > As we're enforcing encryption, here is via ldaps: > $ ldapsearch -H ldaps://`hostname` -D "cn=Directory Manager" -W -s > sub -b ou=authorities,ou=ca,o=ipaca Enter LDAP > Password: > # extended LDIF > # > #

Re: [Freeipa-users] bind-dyndb-ldap, AXFR and DS records

2017-02-10 Thread Tomas Krizek
On 02/10/2017 08:42 AM, Ben Roberts wrote: > Hi Martin, > >> I'm not sure how your DNS data are structured, but usually (properly) >> DS record is located in parent zone, so AXFR for >> subdomain.exmale.com should not return DS record, but AXFR >> for example.com should return DS record of >>

Re: [Freeipa-users] Looking for instructions on one way subtree sync IPA->IPA

2017-02-10 Thread David Kupka
On Thu, Feb 09, 2017 at 01:45:42PM +, Piper, Nick wrote: > Hi Alexander, > > Alexander Bokovoy wrote: > >On to, 09 helmi 2017, Piper, Nick wrote: > > >>We're currently using FreeIPA 4.2.0, and we have two unrelated > >>instances of IdM server. We'd like the user list which IPA maintains >