[Freeipa-users] FreeIPA 4.4 / Winsync issues.

2017-02-23 Thread Devin Acosta
I have installed a new replica in our IPA domain and configured it to do a winsync with Windows 2012R2. It creates the agreement but then after a while it dies. It appears something isn't configured just right. The Windows client is using the passync user on my side, and i'm creating the sync

Re: [Freeipa-users] FreeIPA upgrade from ipa-server-4.2.0-15.0.1.el7.centos.18 to ipa-server-4.2.0-15.0.1.el7.centos.19 (went sideways)

2016-09-23 Thread Devin Acosta
com> wrote: > can you check if you have > /var/lock/dirsrv/slapd-RSINC-LOCAL > > if the server user has permissions to write into this directory and its > subdirs or if any pid file still exists in /var/lock/dirsrv/slapd-RSINC- > LOCAL/server > > > On 09/23/

[Freeipa-users] FreeIPA upgrade from ipa-server-4.2.0-15.0.1.el7.centos.18 to ipa-server-4.2.0-15.0.1.el7.centos.19 (went sideways)

2016-09-22 Thread Devin Acosta
Tonight, I noticed there was like 30 packages to be applied on my IPA server. I did the normal 'yum update' process and it completed. I then rebooted the box for the new kernel to take affect and then that is when IPA stopped working completely. When I try to start the

[Freeipa-users] FreeIPA / CentOS 7.2 / Issues on Startup

2016-08-17 Thread Devin Acosta
My first primary FreeIPA Master server has gone belly up. When I try to start the server it shows this message in the "error' log. However the other issue i have is when I try to start the server using "ipactl start" it times out after 300 seconds, how do I get past this issue?

[Freeipa-users] FreeIPA / Change SSL Certificate for Web Server

2016-07-21 Thread Devin Acosta
I have just installed a newly created FreeIPA server running CentOS 7.2. I have a (wildcard) SSL Certificate that I want to use for the FreeIPA Web Management GUI. I tried to follow the directions listed here at the URL of https://www.freeipa.org/page/Using_3rd_part_certificates_for_HTTP/LDAP

Re: [Freeipa-users] FreeIPA (Add Replica fails on GSSAPI)

2016-07-14 Thread Devin Acosta
stallation against other replica work? > > Could you provide dirsrv error log of the master from the time of > installation? > > > > > > > *From:*Devin Acosta [mailto:linuxguru...@gmail.com] > > *Sent:* 12. juli 2016 21:35 > > *To:* freeipa-users@redhat.com >

Re: [Freeipa-users] Replication Agreement issues noticed with repl-monitor.pl

2016-07-14 Thread Devin Acosta
ipa01-jap was a host that is no more, is there a simple way to clear these replication agreements to clean it up? On Thu, Jul 14, 2016 at 7:14 AM, Petr Vobornik <pvobo...@redhat.com> wrote: > On 07/14/2016 12:57 PM, Martin Kosek wrote: > > On 07/13/2016 04:24 AM, Devin Acosta wro

[Freeipa-users] Replication Agreement issues noticed with repl-monitor.pl

2016-07-12 Thread Devin Acosta
I was trying to create another Replica but then noticed it was constantly having issues trying to finish the joining of the replication. I then ran the command: repl-monitor.pl, It appears i have several replicaid's and they seem to be having issues, wondering if this is adding to my issue.

[Freeipa-users] ipa-replica-install fails at [6/8]: enable GSSAPI for replication

2016-05-09 Thread Devin Acosta
Attempting to create replica fails during ipa-replica-install. I have attached below what I am seeing during attempting to add a replica into my environment. Currently there are (3) Masters. When I try to add the (4th) it dies. The 4th node will only be able to talk to ipa01-aws, ipa02-aws,

Re: [Freeipa-users] nsds5ReplConflict / Replication issue!

2016-05-06 Thread Devin Acosta
I did try to resync idm1-i2x from ipa01-aws, probably was a bad idea.. Is there any way to basically have it resync and get a fresh copy from the other nodes that are ok? Well it initially started when I noticed errors in the logs about having a conflict on a record. So i was trying

[Freeipa-users] nsds5ReplConflict / Replication issue!

2016-05-06 Thread Devin Acosta
I am running the latest FreeIPA on CentOS 7.2. I noticed I had a “nsds5ReplConflict” with an item, i tried to follow the webpage to rename and delete but that failed. I then tried to have ipa1-i2x reload from ipa01-aws instance, now now it seems to have gone maybe worse? can you please advise

Re: [Freeipa-users] Inplace upgrade

2016-05-03 Thread Devin Acosta
Barry, Yes you should be able to just do a: "yum update ipa-server" and you should be good to go. --  Devin Acosta, RHCE, LFCE Linux Certified Engineer e: de...@linuxguru.co On May 3, 2016 at 9:10:04 PM, barry...@gmail.com (barry...@gmail.com) wrote: Hi : How to in place upgrade