[Freeipa-users] UPDATE: NOT Resolved After All -- sudo NOPASSWD for a single command

2017-02-23 Thread Auerbach, Steven
ript run when I re-ran it. I am being prompted for password by the sudo line again. From: Jason B. Nance [mailto:ja...@tresgeek.net] Sent: Wednesday, February 22, 2017 11:59 AM To: Auerbach, Steven <steven.auerb...@flbog.edu> Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] sudo NOP

[Freeipa-users] UPDATE: Resolved sudo NOPASSWD for a single command

2017-02-23 Thread Auerbach, Steven
ch I corrected and added sudo to the “services=” directive. One or both of those changes corrected the situation and vgs runs under sudo without a password prompt. From: Jason B. Nance [mailto:ja...@tresgeek.net] Sent: Wednesday, February 22, 2017 11:59 AM To: Auerbach, Steven <steven.auerb..

[Freeipa-users] Recall: sudo NOPASSWD for a single command

2017-02-23 Thread Auerbach, Steven
Auerbach, Steven would like to recall the message, "[Freeipa-users] sudo NOPASSWD for a single command". -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] sudo NOPASSWD for a single command

2017-02-23 Thread Auerbach, Steven
sults.txt uname -r >> statresults.txt printf "\n " >> statresults.txt sudo vgs >> statresults.txt ….. Running the script I still was prompted for a password. So I guess this does not work. From: Jason B. Nance [mailto:ja...@tresgeek.net] Sent: Wednesday, February 22, 2017 11:59 AM T

[Freeipa-users] sudo NOPASSWD for a single command

2017-02-22 Thread Auerbach, Steven
We have a script stored on a particular server in our realm that executes a number of non-privileged commands and are wanting to add /sbin/vgs command. The script uses SSH to then execute the same set of commands on all the servers in the realm. The owner of the script is in the administrator

[Freeipa-users] Odd Password Issue Across the realm

2016-07-21 Thread Auerbach, Steven
We have our IPA set up as master-master and we have about 25 clients in realm (including the IPA servers themselves). We have a single user who changed his unexpired password using the passwd command logged on to one of the registered clients. Thereafter, when he logs on to any of the client

[Freeipa-users] IPA active-active node failure

2016-06-27 Thread Auerbach, Steven
We have an active-active dual-node IPA. The second node stopped accepting logins thru the Web GUI. I rebooted the server. Now it is really botched. Directory service will not restart: # service ipa restart Restarting Directory Service Shutting down dirsrv: domain-LOCAL... server already

[Freeipa-users] I think I have an issue, but maybe not.....Is IPA Replica Clean-up Needed?

2016-03-03 Thread Auerbach, Steven
We have IPA set up in active-active mode. The first node (ipa01) logs errors regularly (every few minutes) that seem to be based upon an attempt to communicate with a replica that no longer exists. Feb 25 14:38:04 ipa01 named[2161]: LDAP query timed out. Try to adjust "timeout" parameter Feb

[Freeipa-users] IPA Replicant Clean-up Needed?

2016-02-25 Thread Auerbach, Steven
My IPA LDAP/CS Master logs errors regularly (every few minutes) that seem o be based upon an attempt to communicate with a replica that no longer exists. Feb 25 14:38:04 ipa01 named[2161]: LDAP query timed out. Try to adjust "timeout" parameter Feb 25 14:38:04 ipa01 named[2161]: LDAP query

Re: [Freeipa-users] Replication not happening for user password changes even after increasing the nsslapd-sasl-max-buffers to 2M

2015-02-06 Thread Auerbach, Steven
-Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: Thursday, February 05, 2015 4:10 PM To: Auerbach, Steven; IPA User Maillist (freeipa-users@redhat.com) Cc: Ouellet, Dan Subject: Re: [Freeipa-users] Replication not happening for user password changes even after

[Freeipa-users] Replication not happening for user password changes even after increasing the nsslapd-sasl-max-buffers to 2M

2015-02-05 Thread Auerbach, Steven
A user contacted me today for a password reset. I made the reset on the ipa-primary. The user opened a terminal session on an SSH Client to a server in the realm and logged in. They received the required immediate password change requirement and did so. They can log off and log back on that

[Freeipa-users] IPA-Server v3.0 Replication Broken

2015-01-29 Thread Auerbach, Steven
We have a pair of IPA Servers for our network. Our servers are Oracle Linux 6 x86_64 with the ipa-server.3.0.X packages [up to date as distributed by Oracle Linux]. Recently we noticed that the master (IPA01) is replicating fine to the designated replicant. But changes that are made on the