Re: [Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
Services Europe CDT Techn. Operations Nike Inc. : Mobile +31 6 23902697 On 2/15/16, 5:16 PM, "Jakub Hrozek" <jhro...@redhat.com> wrote: >On Mon, Feb 15, 2016 at 03:58:15PM +0000, Birnbaum, Warren (ETW) wrote: >> Jakub, >> >> We want to use password stored in

Re: [Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
b 15, 2016 at 11:24:08AM +0000, Birnbaum, Warren (ETW) wrote: >> Hi Jakub, >> >> Thanks but I have sudo working OK. > >I'm sorry, my fault.. > >> What I am trying make work is HBAC. >> That I canĀ¹t get to work with the proxy hack. Is there a way to do &g

Re: [Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
. Operations Nike Inc. : Mobile +31 6 23902697 On 2/15/16, 12:52 PM, "Alexander Bokovoy" <aboko...@redhat.com> wrote: >On Mon, 15 Feb 2016, Birnbaum, Warren (ETW) wrote: >>Thanks Lukas. >> >>Unfortunately setting up a IPA Ad Trust is something n

Re: [Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
Services Digital Linux Infrastructure Services Europe CDT Techn. Operations Nike Inc. : Mobile +31 6 23902697 On 2/15/16, 12:36 PM, "Lukas Slebodnik" <lsleb...@redhat.com> wrote: >On (15/02/16 09:34), Birnbaum, Warren (ETW) wrote: >>Hello, >> >&g

Re: [Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
. Operations Nike Inc. : Mobile +31 6 23902697 On 2/15/16, 11:31 AM, "freeipa-users-boun...@redhat.com on behalf of Jakub Hrozek" <freeipa-users-boun...@redhat.com on behalf of jhro...@redhat.com> wrote: >On Mon, Feb 15, 2016 at 09:34:33AM +0000, Birnbaum, Warren (ETW) wrote:

[Freeipa-users] Question about ldap proxy/AD + sudo + HBAC

2016-02-15 Thread Birnbaum, Warren (ETW)
Hello, I would like to get freeipa to work with a proxy solution ( I currently have this working with an active directory/no trust authentication and sudo but no HBAC) including HBAC. I can get sudo to work but not HBAC. I see there is a ticket for this as a new enhancement #4634 but wanted

Re: [Freeipa-users] Active Directory users are not controlled by HBAC

2016-01-27 Thread Birnbaum, Warren (ETW)
ss to systems, but already have total access to all systems by all users. Thanks for your help! Warren On 1/25/16, 2:47 PM, "Alexander Bokovoy" <aboko...@redhat.com> wrote: >On Mon, 25 Jan 2016, Birnbaum, Warren (ETW) wrote: >>OK. I have done this and am using the pam stack

[Freeipa-users] Problem adding user

2016-01-26 Thread Birnbaum, Warren (ETW)
Hello, I am trying to add a user into FreeIPA that already exists in /etc/passwd. How can I add him into FreeIPA and employ all the functionality? Thanks, Warren -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to

Re: [Freeipa-users] Problem adding user

2016-01-26 Thread Birnbaum, Warren (ETW)
Services Web Automation Engineer Europe CDT Techn. Operations Nike Inc. : Mobile +31 6 23902697 On 1/26/16, 11:06 AM, "Rob Crittenden" <rcrit...@redhat.com> wrote: >Birnbaum, Warren (ETW) wrote: >> Hello, >> >> I am trying to add a user into FreeIPA

Re: [Freeipa-users] Active Directory users are not controlled by HBAC

2016-01-25 Thread Birnbaum, Warren (ETW)
sss.so ___ Warren Birnbaum : Infrastructure Services Web Automation Engineer Europe CDT Techn. Operations Nike Inc. : Mobile +31 6 23902697 On 1/25/16, 1:26 PM, "Birnbaum, Warren (ETW)" <warren.birnb...@nike.com> wrote: >Thanks Alexander. Is there a place where the

Re: [Freeipa-users] Active Directory users are not controlled by HBAC

2016-01-25 Thread Birnbaum, Warren (ETW)
te: >On Mon, 25 Jan 2016, Birnbaum, Warren (ETW) wrote: >>Thanks Alexander. Is there a place where there are example pam stacks >>that work with active directory and hbac? >Defaults in RHEL/Fedora should be enough: > - install RHEL/Fedora, > - apply ipa-client-install, &

[Freeipa-users] Active Directory users are not controlled by HBAC

2016-01-22 Thread Birnbaum, Warren (ETW)
Hi. I have a been successful using Freeipa 4.1 configuring active directory users and with sudo. The problem I am having is that the HBAC rules are not applying to my active directory users. They have access to all systems even if I disable my Allow_ALL rule. Is there something special I

Re: [Freeipa-users] Active Directory users are not controlled by HBAC

2016-01-22 Thread Birnbaum, Warren (ETW)
-boun...@redhat.com on behalf of Jakub Hrozek" <freeipa-users-boun...@redhat.com on behalf of jhro...@redhat.com> wrote: >On Fri, Jan 22, 2016 at 09:27:40AM +0000, Birnbaum, Warren (ETW) wrote: >> Hi. >> >> I have a been successful using Freeipa 4.1 configuring a