Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-09 Thread reesb
I've update the ACI's but am still getting the same error as before. I am guessing this is probably related to the same issue in the other concurrent vsphere 5.5 email thread that is going. I'll just keep my eye on that to see the resolution. On 3/6/2015 at 3:45 PM, Martin Kosek

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread reesb
Ok here is the search result; # ldapsearch -x -D cn=Directory Manager -W -b cn=config cn=groups Enter LDAP Password: # extended LDIF # # LDAPv3 # base cn=config with scope subtree # filter: cn=groups # requesting: ALL # # groups, Schema Compatibility, plugins, config dn: cn=groups,cn=Schema

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread Gianluca Cecchi
On Thu, Mar 5, 2015 at 8:54 AM, Martin Kosek mko...@redhat.com wrote: I am also CCing Gialunca who contributed the HOWTO. I checked it again and tried to apply it on my FreeIPA 4.1.3, my compat group now contain the proper uniqueMember attribute and groupOfUniqueNames objectclass. I am not

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread Martin Kosek
On 03/05/2015 02:37 AM, re...@hushmail.com wrote: Opps, I got that wrong, my groups don't show the 'uniqueMember' attribute. Here is an example returned from ldapsearch; # admins, groups, compat, localdomain.local dn: cn=admins,cn=groups,cn=compat,dc=localdomain,dc=local gidNumber:

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread reesb
Just to confirm I should restart the server after i've run the ldapmodify? Also I've used ldap modify to remove the 'uniqueMember' object class from the compat schema and added the 'sn=%{sn}' attribute and I still am having no luck. I get the same 'identity source may be malfunctioning error'

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread Martin Kosek
On 03/06/2015 08:35 AM, Alexander Bokovoy wrote: On Fri, 06 Mar 2015, Martin Kosek wrote: On 03/06/2015 02:24 AM, re...@hushmail.com wrote: Just to confirm I should restart the server after i've run the ldapmodify? Right. It would be safer thing to do, if you modified the Schema

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread Martin Kosek
On 03/06/2015 02:24 AM, re...@hushmail.com wrote: Just to confirm I should restart the server after i've run the ldapmodify? Right. It would be safer thing to do, if you modified the Schema Compatibility config. At least to make sure it re-creates the entries from scratch. Also I've used

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-05 Thread Alexander Bokovoy
On Fri, 06 Mar 2015, Martin Kosek wrote: On 03/06/2015 02:24 AM, re...@hushmail.com wrote: Just to confirm I should restart the server after i've run the ldapmodify? Right. It would be safer thing to do, if you modified the Schema Compatibility config. At least to make sure it re-creates the

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-04 Thread reesb
Opps, I got that wrong, my groups don't show the 'uniqueMember' attribute. Here is an example returned from ldapsearch; # admins, groups, compat, localdomain.local dn: cn=admins,cn=groups,cn=compat,dc=localdomain,dc=local gidNumber: 75620 memberUid: admin memberUid: vadmin objectClass:

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-04 Thread reesb
Hi Martin, Using my vadmin account, uid=vadmin,cn=users,cn=compat,dc=localdomain,dc=local, the search completes successfully and i get a list of my users and groups however when I've watched the ldap queries between vcenter and freeipa I can see it's applying a filter to the user search looking

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-04 Thread Martin Kosek
On 03/04/2015 09:43 AM, re...@hushmail.com wrote: Hi,I've read the thread from Nov and checked out http://www.freeipa.org/page/HowTo/vsphere5_integration however i'm still having trouble getting vpshere to use freeipa as an identity source. I've set the base DN for users and groups, the