[Freeipa-users] LDAP Conflicts

2017-05-04 Thread James Harrison
lution API | | | But not sure if I am looking in the right place. Many thanks,James Harrison -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1

2017-02-14 Thread James Harrison
Hi,Was there any out-come to this? I running: sudo1.8.12-1ubuntu3, which is well behind up to date releases. Many thanks,James Harrison From: James Harrison <jamesaharriso...@yahoo.co.uk> To: "freeipa-users@redhat.com" <freeipa-users@redhat.com>; "pbrez...@redha

Re: [Freeipa-users] FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1

2017-01-09 Thread James Harrison
All,debian 1.8.19-1 doesnt work, but Ubuntu 1.8.12-1ubuntu3 does. James From: Lukas Slebodnik <lsleb...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.co.uk> Cc: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Saturday, 7 January 2017,

Re: [Freeipa-users] FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1

2017-01-09 Thread James Harrison
All,1.8.19-1 from Debian does not appear to work too. James From: Lukas Slebodnik <lsleb...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.co.uk> Cc: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Saturday, 7 January 2017, 15:34 Subject:

Re: [Freeipa-users] FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1

2017-01-06 Thread James Harrison
Any ideas? From: James Harrison <jamesaharriso...@yahoo.co.uk> To: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Thursday, 5 January 2017, 13:36 Subject: FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1 Hi all,I having p

[Freeipa-users] FreeIPA sudo not working on ububtu xenial sssd version 1.13.4-1ubuntu1.1

2017-01-05 Thread James Harrison
Hi all,I having problems with a FreeIPA client running Ububtu Xenial. I can authenticate OK, I get a kerberos ticket, but cannot run sudo. I get 1 rule returned, which I expect. Many thanks,James Harrison (Thu Jan  5 12:09:57 2017) [sssd[sudo]] [ldb] (0x4000): Destroying timer event 0x1c11e30

[Freeipa-users] Manually configuring Freeipa bind configs to host secondary zones

2017-01-04 Thread James Harrison
. Is it supported or will they just be over-written by Freeipa? I've been hunting for an answer online, but found nothing about this. Many thanks,James Harrison -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org

Re: [Freeipa-users] Free IPA Openssh client install error

2016-12-14 Thread James Harrison
. Public key authentication of IPA users will not be available. From: James Harrison <jamesaharriso...@yahoo.co.uk> To: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Wednesday, 14 December 2016, 15:18 Subject: Free IPA Openssh client install er

[Freeipa-users] Free IPA Openssh client install error

2016-12-14 Thread James Harrison
Any clues? Is there a fix? Best regards,James Harrison -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Problem with Free IPA Client Ubuntu Precise (12.04) authenticating with AD account

2016-12-08 Thread James Harrison
Hi,From this URL: https://launchpad.net/~sssd/+archive/ubuntu/updates i updated sssd on Trusty and I can now ssh to it using a FreeIPA user's  credentials. AD Still doesn't work. Thanks From: Lukas Slebodnik <lsleb...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.c

Re: [Freeipa-users] Problem with Free IPA Client Ubuntu Precise (12.04) authenticating with AD account

2016-12-08 Thread James Harrison
I tried to clone the git repos and I got access right errors James From: Lukas Slebodnik <lsleb...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.co.uk> Cc: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Thursday, 8 December 2016, 11:22

Re: [Freeipa-users] Problem with Free IPA Client Ubuntu Precise (12.04) authenticating with AD account

2016-12-08 Thread James Harrison
(x_james.harrison@ad.domain.local) groups=1039812876(x_james.harrison@ad.domain.locall) However auth issues still the same as Precise. Doesnt accept the ssh public key stored with the IPA user or the Trust ID view user. Xenial has no problems. Regards,James Harrison From: James Harrison

Re: [Freeipa-users] Problem with Free IPA Client Ubuntu Precise (12.04) authenticating with AD account

2016-12-08 Thread James Harrison
tions Redundant SSSD configuration file /etc/sssd/sssd.conf was moved to /etc/sssd/sssd.conf.deleted SSSD service could not be stopped Client uninstall complete. From: Lukas Slebodnik <lsleb...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.co.uk> Cc: "freeipa-users@redhat.

[Freeipa-users] Problem with Free IPA Client Ubuntu Precise (12.04) authenticating with AD account

2016-12-07 Thread James Harrison
seem to authenticate against the public ssh key from the id override user. I appreciate any help you can send my way. Best regards, James Harrison Below is more information root@jamesprecise:~# kinit x_james.harrison@AD.DOMAIN.LOCAL Password for x_james.harrison@AD.DOMAIN.LOCAL: root

[Freeipa-users] Something I dont get with FriiIPA and AD Trusts and Users and Greoups

2016-11-21 Thread James Harrison
) allows me to do what? Am I supposed to get a synchronised list of Domain Admin users in Free IPA? I can log in to a Linux client using AD credentials, regardless of the AD users external map (The user I'm logging is with is a member of the AD Domain Admins group). Many thanks,James Harrison

[Freeipa-users] Differences between "ipa-replica-manage connect --winsync..." and ipa-adtrust-install ... ipa trust-add...

2016-11-15 Thread James Harrison
accomplish the same goal: to get AD user accounts? Which one is preferred? Best regards,James Harrison -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Specify different ssh port for ipa-conncheck

2016-11-10 Thread James Harrison
Hello.Thanks for your help Martin that worked. James Harrison  On Thu, 10 Nov, 2016 at 12:15, Martin Basti<mba...@redhat.com> wrote: On 10.11.2016 13:00, James Harrison wrote: Hi All, We use port 2234 for all sshd connections on our systems. It looks loke ipa-connchec

Re: [Freeipa-users] Specify different ssh port for ipa-conncheck

2016-11-10 Thread James Harrison
settings according to error messages above. If the check results are not valid it can be skipped with --skip-conncheck parameter. From: James Harrison <jamesaharriso...@yahoo.co.uk> To: "freeipa-users@redhat.com" <freeipa-users@redhat.com> Sent: Thursday, 10 Novembe

[Freeipa-users] Specify different ssh port for ipa-conncheck

2016-11-10 Thread James Harrison
Hi All,We use port 2234 for all sshd connections on our systems. It looks loke ipa-conncheck uses port 22. Can this be changed to use 2234? This would be for replicas and clients I presume. This is quite urgent. Many thanks,James Harrison -- Manage your subscription for the Freeipa-users

Re: [Freeipa-users] Remove AD domain in auth commands

2016-11-07 Thread James Harrison
swered thathttps://www.redhat.com/archives/freeipa-users/2016-November/msg00031.html On 07.11.2016 12:05, James Harrison wrote: Anyone ? Sent from Yahoo Mail on Android On Fri, 4 Nov, 2016 at 11:04, James Harrison <jamesaharriso...@yahoo.co.uk> wrote: Hello, I've installed

Re: [Freeipa-users] Remove AD domain in auth commands

2016-11-07 Thread James Harrison
Anyone ? Sent from Yahoo Mail on Android On Fri, 4 Nov, 2016 at 11:04, James Harrison<jamesaharriso...@yahoo.co.uk> wrote: Hello, I've installed FreeIPA 4.2 master using Centos and I have a Windows 2012R2 with its AD schema emulating a Windows 2012 system I have established a

[Freeipa-users] Remove AD domain in auth commands

2016-11-04 Thread James Harrison
way to ssh to the master IPA server is like this: ssh "x_@IPAWIN.LOCAL"@10.10.10.10 Another example is using kinit: I have to do the following to get a credential:kinit x_@IPAWIN.LOCAL Ideally I would not need or use the "@IPAWIN.LOCAL". Can anyone help? Best re

Re: [Freeipa-users] Promote CA-less replica

2016-10-21 Thread James Harrison
t.com" <freeipa-users@redhat.com> Sent: Friday, 21 October 2016, 14:18 Subject: Re: [Freeipa-users] Promote CA-less replica James Harrison wrote: > Hi, > Thanks again. > > Lastly, we've switched away from Ubuntu's FreeIPA due to a bad Samba > compilation choi

Re: [Freeipa-users] Promote CA-less replica

2016-10-20 Thread James Harrison
of FreeIPA, but the Ubuntu version is 4.4.2. Is there 4.4.2 for CentOS? Best regardsJames Harrison  From: Rob Crittenden <rcrit...@redhat.com> To: James Harrison <jamesaharriso...@yahoo.co.uk>; Martin Babinsky <mbabi...@redhat.com>; "freeipa-users@redhat.com" <f

Re: [Freeipa-users] Promote CA-less replica

2016-10-19 Thread James Harrison
"replica" run the ipa-replica-prepare script once ipa-replica-install has been successfully run? Thank you for any help.Best regards,James Harrison From: Martin Babinsky <mbabi...@redhat.com> To: freeipa-users@redhat.com Sent: Wednesday, 19 October 2016, 11:01 Subject: Re:

[Freeipa-users] Promote CA-less replica

2016-10-19 Thread James Harrison
a CA. Our CA is Comodo and we have configured FreeIPA to use a certificate, key and interim certificates from Comodo. using the options: --http_pkcs12=--http_pin= --dirsrv_pkcs12=... --dirsrv_pin= Hope someone can help. Quite urgent. Regards, James Harrison -- Manage your