[Freeipa-users] freeIPA 2.2.0 on Fedora core 16?

2012-05-23 Thread Gelen James
Hi all,  Could FC16 installed FreeIPA 2.2.0? the freeIPA site said that FC16 has some underlying dependencies. Thanks. --Gelen___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] [Freeipa-devel] I've done it by myself and it works -- Re: Feature request: Web UI for IPA users to reset their own expired passwords

2012-05-23 Thread Gelen James
a prototype, it is not well-tested, nor DOS attack prove at all, so it could potentially harm or totally destroy someone's authentication system. :( Thanks. --Gelen From: Rob Crittenden To: Gelen James Cc: "freeipa-de...@redhat.com" ;

[Freeipa-users] I've done it by myself and it works -- Re: Feature request: Web UI for IPA users to reset their own expired passwords

2012-05-23 Thread Gelen James
I've coded it with python-kerberos and it works. Pretty rough though. --Gelen. From: Gelen James To: "freeipa-de...@redhat.com" Sent: Sunday, May 20, 2012 2:22 AM Subject: Feature request: Web UI for IPA users to reset their own expired p

Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup???

2012-05-21 Thread Gelen James
    Thanks. --Gelen ____ From: Gelen James To: Rob Crittenden ; Dmitri Pal Cc: "Freeipa-users@redhat.com" Sent: Sunday, May 20, 2012 12:08 AM Subject: Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup??? Hi Mmi

Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup???

2012-05-20 Thread Gelen James
. Thanks. --Gelen   From: Gelen James To: Rob Crittenden ; Dmitri Pal Cc: "Freeipa-users@redhat.com" Sent: Sunday, May 20, 2012 12:08 AM Subject: Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup???

Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup???

2012-05-20 Thread Gelen James
Hi Mmitri, Rob and all.  Thanks for your instructions. I've performed your steps on case#1: replacing failed IPA master.  The results, and my confusion and questions, are all detailed below. In general, please setup your own real test environment, and write down the detailed steps one by one cl

Re: [Freeipa-users] sudo rules in IPA infrastructure

2012-05-18 Thread Gelen James
Hi Stephen,  That's very helpful. Thanks a lot. --Gelen From: Stephen Ingram To: Gelen James Cc: "freeipa-users@redhat.com" ; Rob Crittenden ; Rich Megginson Sent: Friday, May 18, 2012 2:58 PM Subject: Re: [Freeipa-users] sudo rules in IPA

[Freeipa-users] sudo rules in IPA infrastructure

2012-05-18 Thread Gelen James
Hi all,  Are the sudo rules applied to IPA clients through nss_ldap, instead of sssd?   I tried that on Redhat 6.2 clients, and some documents said that sudo rules would work when enabled inside /etc/nslcd.conf, but we need to hack the script /etc/init.d/nslcd.conf a little bit -- basically to

[Freeipa-users] HBAC rules take in effect on IPA clients immediately after installation?

2012-05-18 Thread Gelen James
Hi all,  Just like to clarify my confusion: Are the HBAC (Host Based Access Control) rules immediately in effect after IPA client software configurations through sssd? Do we have any options inside sssd.conf to enable/disable the HBAC rules per machine (inside IPA domain)? I have this question

[Freeipa-users] Thanks -- Re: Bug or feature regarding External Host in IPA net groups?

2012-05-15 Thread Gelen James
ber Hosts after ipa-client-install ..  I'll follow your steps to test the replication recovery on another thread now. Thanks again for your help. --Gelen. From: Rob Crittenden To: Gelen James Cc: "d...@redhat.com" ; "Freeipa-users@redhat.

Re: [Freeipa-users] Please help: What the purposes of '--usercat' and '--hostcat' options to IPA net groups?

2012-05-15 Thread Gelen James
Hi Sumit,  Thanks for your quick reply.    In the chapter http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/Identity_Management_Guide/migrating-from-nis.html#nis-import-netgroups, The Netgroup migration script sets '--usercat' and '--hostcat' options to IPA netgroups thro

Re: [Freeipa-users] Please help: How to restore IPA Master/Replicas from daily IPA Replica setup???

2012-05-14 Thread Gelen James
Hi Dimitri,  thanks a lot for your offer. It will be more than appreciated if Rob, or some other talented genius could wiki the steps. The more details, the sooner, and the better. It will help IPA projects and its users dramatically, especially for newbies like me. :) Thanks again for you, Ro

[Freeipa-users] Bug or feature regarding External Host in IPA net groups?

2012-05-14 Thread Gelen James
Hi all,   Not sure whether it is bug or a feature, but when I evaluate the IPA net groups, the 'external host' feature brings me some unexpected results. I'll listed them below -- I am running IPA 2.1.3-9 on Redhat 6.2.  1, when I added a host into IPA netgroup in command line mode, 'ipa net