[Freeipa-users] Freeipa web UI: An error has occurred (IPA Error 4302: CertificateFormatError)

2017-04-17 Thread Andrew Krause
Many hosts in our web ui show a null status for “enrolled”. When you do a search that includes any of these host objects the web UI posts errors, and if you click on one of the problem hosts the same error stops anything from loading on the host page. I’ve been trying to solve this problem

[Freeipa-users] Repair a corrupted database

2017-04-17 Thread Chris Mohler
Hi List, I've got two boxes running FreeIPA 4.1.4. The Database on the first master is corrupted. Log looks like this: [17/Apr/2017:10:22:51 -0400] - libdb: BDB0689 changelog/id2entry.db page 27523 is on free list with type 5 [17/Apr/2017:10:22:51 -0400] - libdb: BDB0061 PANIC: Invalid

Re: [Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Jan Pazdziora
On Mon, Apr 17, 2017 at 04:49:59PM +0300, Alexander Bokovoy wrote: > On Mon, 17 Apr 2017, Jan Pazdziora wrote: > > > > Hello, > > > > on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve > > new keytab for a service but they cannot retrieve the existing keys > > with the -r

Re: [Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Alexander Bokovoy
On Mon, 17 Apr 2017, Jan Pazdziora wrote: Hello, on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve new keytab for a service but they cannot retrieve the existing keys with the -r option. Is that expected? Yes. Access to existing keys is intentionally restricted. There are

[Freeipa-users] Admin cannot retrieve keytab -- is that expected?

2017-04-17 Thread Jan Pazdziora
Hello, on freeipa-server-4.4.4-1.fc25.x86_64, admin can generate and retrieve new keytab for a service but they cannot retrieve the existing keys with the -r option. Is that expected? # kdestroy -A # kinit admin Password for ad...@example.test: # ipa host-add test1.example.test --force