[Freeipa-users] ca-error 2100

2016-07-25 Thread mohammad sereshki
hido you know how can i solve it? getcert list|grep -i err     ca-error: Server denied our request, giving up: 2100 (RPC failed at server.  Insufficient access: Insufficient 'write' privilege to the 'userCertificate' attribute of entry

[Freeipa-users] Insufficient 'write' privilege to the 'userCertificate'

2016-07-24 Thread mohammad sereshki
hiI get below error from "getcert list",would you please help me to solve it?  ca-error: Server denied our request, giving up: 2100 (RPC failed at server.  Insufficient access: Insufficient 'write' privilege to the 'userCertificate' attribute of entry

[Freeipa-users] Insufficient access

2016-07-24 Thread mohammad sereshki
hiI got below error , when I tried to check certificates, I ran kinit admin before and it was okaywould you please help me ? ipa cert-show 1- ipa: ERROR: Insufficient access: not allowed to perform this command -- Manage your subscription for the Freeipa-users mailing list:

[Freeipa-users] ccache for local "host" service using default keytab

2016-07-24 Thread mohammad sereshki
hiI get below error ,is there any suggestion to solve it? ca-error: Error setting up ccache for local "host" service using default keytab: Cannot contact any KDC for realm 'EXAMPLE.COM'. getcert list |less Number of certificates and requests being tracked: 8. Request ID '20140817125452':   

[Freeipa-users] replica cms issue

2016-07-24 Thread mohammad sereshki
hiI get below error when I want to prepare a server as replica .would you please help me? Certificate operation cannot be completed: Unable to communicate with CMS -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to

Re: [Freeipa-users] ipa-getcert shows error

2016-07-23 Thread mohammad sereshki
O=EXAMPLE.COM     subject: CN=ipasrv.EXAMPLE.COM,O=EXAMPLE.COM     expCOMes: 2016-08-17 12:37:51 UTC     eku: id-kp-serverAuth,id-kp-clientAuth     pre-save command:     post-save command: /usr/lib64/ipa/certmonger/restart_httpd     track: yes     auto-renew: yes

[Freeipa-users] ipa-getcert shows error

2016-07-23 Thread mohammad sereshki
hi I get below errorca-error: Error setting up ccache for local "host" service using default keytab: Cannot contact any KDC for realm 'EXAMPLE.COM'. when I run ipa-getcert list, also how can I check my CAs are renewed or not?  Request ID '20140817123602':     status: MONITORING    

Re: [Freeipa-users] Freeipa-users Digest, Vol 96, Issue 125

2016-07-21 Thread mohammad sereshki
-Cert cert-pki-ca  u,u,u auditSigningCert cert-pki-ca u,u,Pu ocspSigningCert cert-pki-ca  u,u,Pu From: Rob Crittenden <rcrit...@redhat.com> To: mohammad sereshki <mohammadseres...@

Re: [Freeipa-users] Freeipa-users Digest, Vol 96, Issue 125

2016-07-21 Thread mohammad sereshki
digest..." Today's Topics:   1. Re: regenerate certificate (mohammad sereshki) -- Message: 1 Date: Thu, 21 Jul 2016 19:08:16 + (UTC) From: mohammad sereshki <mohammadseres...@yahoo.com> To: Rob Crittenden <rcri

Re: [Freeipa-users] regenerate certificate

2016-07-21 Thread mohammad sereshki
ably O.K. unless ECC support has been installed. Warning: SSL ECC cipher "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA" unsupported by NSS. This is probably O.K. unless ECC support has been installed. : From: mohammad sereshki <mohammadseres...@yahoo.com> To: Rob Crittenden <rcri

Re: [Freeipa-users] regenerate certificate

2016-07-21 Thread mohammad sereshki
selftests.container.instance.SystemCertsVerification running at startup FAILED! (END) From: mohammad sereshki <mohammadseres...@yahoo.com> To: Rob Crittenden <rcrit...@redhat.com>; Florence Blanc-Renaud <f...@redhat.com>; Freeipa-users <freeipa-users@redhat.com> Sent: Thursday, July 21, 2016 11:34 PM Sub

Re: [Freeipa-users] regenerate certificate

2016-07-21 Thread mohammad sereshki
Crittenden <rcrit...@redhat.com> To: mohammad sereshki <mohammadseres...@yahoo.com>; Florence Blanc-Renaud <f...@redhat.com>; Freeipa-users <freeipa-users@redhat.com> Sent: Thursday, July 21, 2016 11:21 PM Subject: Re: [Freeipa-users] regenerate certificate moham

Re: [Freeipa-users] regenerate certificate

2016-07-21 Thread mohammad sereshki
hiwould you please explain more? From: Rob Crittenden <rcrit...@redhat.com> To: mohammad sereshki <mohammadseres...@yahoo.com>; Florence Blanc-Renaud <f...@redhat.com>; Freeipa-users <freeipa-users@redhat.com> Sent: Thursday, July 21, 2016 11:09 PM Sub

Re: [Freeipa-users] regenerate certificate

2016-07-21 Thread mohammad sereshki
hiit is result of command, seems issue is another thing  ipa cert-show 1 ipa: ERROR: Certificate operation cannot be completed: Unable to communicate with CMS (Not Found) From: Rob Crittenden <rcrit...@redhat.com> To: mohammad sereshki <mohammadseres...@yahoo.com>; Fl

[Freeipa-users] regenerate certificate

2016-07-20 Thread mohammad sereshki
hiI check my IPA server which is version ipa-server-3.0.0-25 , command "ipa-get-cert list" show, my certificate will be expired in next 20 days, I do not know how to regenerate thembut command "getcert list" shows epirtion certificates are related just to "CA:IPA" and certificate " CA:

Re: [Freeipa-users] add suse 11 sp3 to ipa

2015-06-10 Thread mohammad sereshki
hido you know where is the path of certification file and certification key file for clients? From: Rob Crittenden rcrit...@redhat.com To: mohammad sereshki mohammadseres...@yahoo.com; Freeipa-users freeipa-users@redhat.com Sent: Tuesday, June 9, 2015 10:29 PM Subject: Re: [Freeipa

[Freeipa-users] add suse 11 sp3 to ipa

2015-06-09 Thread mohammad sereshki
 hiWould you please let me know is it possible to add suse 11 sp3 to IPA? and how it is possible?Regards -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Freeipa-users Digest, Vol 79, Issue 57

2015-02-16 Thread mohammad sereshki
' to     freeipa-users-requ...@redhat.com You can reach the person managing the list at     freeipa-users-ow...@redhat.com When replying, please edit your Subject line so it is more specific than Re: Contents of Freeipa-users digest... Today's Topics:   1. join error (mohammad sereshki)   2. Re: resolving

Re: [Freeipa-users] join error

2015-02-16 Thread mohammad sereshki
dear I  use ipa-client-3.0.0-42 and I added with ipa-client-install so it asks to enter admin user and password. From: Martin Basti mba...@redhat.com To: mohammad sereshki mohammadseres...@yahoo.com; freeipa-users@redhat.com freeipa-users@redhat.com Sent: Monday, February 16, 2015 2

Re: [Freeipa-users] join error

2015-02-16 Thread mohammad sereshki
dear I use the admin user, at the same time  I added another server with this permission. From: Martin Basti mba...@redhat.com To: mohammad sereshki mohammadseres...@yahoo.com; freeipa-users@redhat.com freeipa-users@redhat.com Sent: Monday, February 16, 2015 2:35 PM Subject: Re

[Freeipa-users] join error

2015-02-16 Thread mohammad sereshki
hi when I want to add a host to IPA I get below error, My server is centOS, is there anyone to help me? HTTP response code is 401, not 200 stderr= trying to retrieve CA cert via LDAP from ldap://linux126.example.com Existing CA cert and Retrieved CA cert are identical

Re: [Freeipa-users] Solaris 10 client auth (ssh + kerberos) not working

2014-09-09 Thread mohammad sereshki
pam_authtok_check.so.1 force_check other password sufficient pam_krb5.so.1 other password required pam_authtok_store.so.1 From: Gerardo Padierna asl.gera...@gmail.com To: mohammad sereshki mohammadseres...@yahoo.com; freeipa-users@redhat.com freeipa

Re: [Freeipa-users] webmin can't work after installing freeipa

2014-09-08 Thread mohammad sereshki
, 2014 6:56 AM Subject: Re: [Freeipa-users] webmin can't work after installing freeipa On 09/07/2014 01:45 PM, mohammad sereshki wrote: Hi I configured IPA on solaris as client and it works correctly. but the problem is I have webmin to manage my servers and it can't login after IPA

Re: [Freeipa-users] Solaris 10 client auth (ssh + kerberos) not working

2014-09-08 Thread mohammad sereshki
hi Please go ahead with below structure, It works! Re: [Freeipa-users] Does Solaris 11 work as client to IPA server? Re: [Freeipa-users] Does Solaris 11 work as client to IPA server? [Date Prev][Date Next] [Thread Prev][Thread Next] [Thread Index] [Date Index] [Author

[Freeipa-users] webmin can't work after installing freeipa

2014-09-07 Thread mohammad sereshki
Hi I configured IPA on solaris as client and it works correctly. but the problem is I have webmin to manage my servers and it can't login after IPA installation. Please help me. thanks-- Manage your subscription for the Freeipa-users mailing list:

[Freeipa-users] IPuser can't authenticated with sssd

2014-08-29 Thread mohammad sereshki
Hi I have configured IPA(ipa-client-2.1.3-7.el5) but the problem is that Ican connect with kerberos from another client but I can't login to client directly and I chet below error  pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.211.166 user=

[Freeipa-users] add solaris attribiutes to IPA

2014-07-28 Thread mohammad sereshki
hi Would you please let me know who can i add /etc/user_attr,prof_attr,projet,auth_attr to IPA ? Iwant to configure RBAC solaris on IPA . Thanks -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more

Re: [Freeipa-users] add solaris attribiutes to IPA

2014-07-28 Thread mohammad sereshki
through web interface. anyway I had done it through command line. From: Rob Crittenden rcrit...@redhat.com To: mohammad sereshki mohammadseres...@yahoo.com; freeipa-users@redhat.com freeipa-users@redhat.com Sent: Monday, July 28, 2014 6:45 PM Subject: Re