Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Ondrej Valousek
On 03.08.2011 23:52, Dmitri Pal wrote: But this has not been even filed as an enhancement as no one cared about such functionality until now. What is your use case for this functionality? Actually, I do not need such a functionality. I was asking because I know Windows rotate keytabs so I

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Simo Sorce
On Thu, 2011-08-04 at 10:25 -0400, Dmitri Pal wrote: On 08/04/2011 03:52 AM, Ondrej Valousek wrote: On 03.08.2011 23:52, Dmitri Pal wrote: But this has not been even filed as an enhancement as no one cared about such functionality until now. What is your use case for this

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Dmitri Pal
On 08/04/2011 10:28 AM, Simo Sorce wrote: On Thu, 2011-08-04 at 10:25 -0400, Dmitri Pal wrote: On 08/04/2011 03:52 AM, Ondrej Valousek wrote: On 03.08.2011 23:52, Dmitri Pal wrote: But this has not been even filed as an enhancement as no one cared about such functionality until now. What

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Ondrej Valousek
I agree with Simo, I would expect this from sssd instead, also given the fact that sssd will in future also handle winbind's net * commands, this seems to me like a most natural way... Ondrej On 04.08.2011 16:28, Simo Sorce wrote: SSSD is probably a more appropriate component for keytabs,

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Dmitri Pal
On 08/04/2011 10:47 AM, Simo Sorce wrote: On Thu, 2011-08-04 at 10:43 -0400, Dmitri Pal wrote: On 08/04/2011 10:28 AM, Simo Sorce wrote: On Thu, 2011-08-04 at 10:25 -0400, Dmitri Pal wrote: On 08/04/2011 03:52 AM, Ondrej Valousek wrote: On 03.08.2011 23:52, Dmitri Pal wrote: But this has

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Ondrej Valousek
On 04.08.2011 16:53, Dmitri Pal wrote: Yes but server can indicate in some attribute to the client that it is time to start doing this and the client will do the change. Would not be just easiest to steal some code from winbind? It is doing the same thing for Samba right? I guess it should

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-04 Thread Dmitri Pal
On 08/04/2011 10:59 AM, Ondrej Valousek wrote: On 04.08.2011 16:53, Dmitri Pal wrote: Yes but server can indicate in some attribute to the client that it is time to start doing this and the client will do the change. Would not be just easiest to steal some code from winbind? It is doing

[Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-03 Thread Ondrej Valousek
Hi List, I have some questions regarding IPA: 1. On the IPA client side, which daemon is looking after machine Kerberos host/ principal renewal? 2. If I installed Samba4 on the IPA server, what would happen? Is it possible? Would I get 2xKDCs, 2xLDAP servers and 2x DNS server or is

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-03 Thread Simo Sorce
On Wed, 2011-08-03 at 10:22 +0200, Ondrej Valousek wrote: Hi List, I have some questions regarding IPA: 1. On the IPA client side, which daemon is looking after machine Kerberos host/ principal renewal? Keytabs are random secrets and do not need to expire as cracking them is

Re: [Freeipa-users] Some questions regarding IPA, DNS and Samba4

2011-08-03 Thread Dmitri Pal
On 08/03/2011 07:44 AM, Simo Sorce wrote: I have some questions regarding IPA: 1. On the IPA client side, which daemon is looking after machine Kerberos host/ principal renewal? Keytabs are random secrets and do not need to expire as cracking them is consider a problem out of