Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Natxo Asenjo
On Tue, Jan 5, 2016 at 7:22 PM, Karl Forner wrote: > update: > > modifying the /etc/krb5.conf, and replacing the name of my freeipa master > by the replica fixes the problem. > So that proves that the kdc is not picked up by discovery. > > The problem is that my ubuntu box was enrolled using the

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Karl Forner
Thanks a lot, that works if I comment out the explicit reference to a server name, and that I switch dns_lookup_kdc to true. I think I understand why it was not working from the install: I used the ipa-client-install with the option --server. According to the man page, in the "Failover" section, I

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Alexander Bokovoy
On Tue, 05 Jan 2016, Karl Forner wrote: update: modifying the /etc/krb5.conf, and replacing the name of my freeipa master by the replica fixes the problem. So that proves that the kdc is not picked up by discovery. This implies you have explicit line stating the KDC address in your krb5.conf. T

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Natxo Asenjo
On Tue, Jan 5, 2016 at 7:31 PM, Natxo Asenjo wrote: > includedir /var/lib/sss/pubconf/krb5.include.d/ > #File modified by ipa-client-install > > [libdefaults] > default_realm = IPA.DOMAIN.TLD > dns_lookup_realm = true > dns_lookup_kdc = true > rdns = false > ticket_lifetime = 24h > fo

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Karl Forner
update: modifying the /etc/krb5.conf, and replacing the name of my freeipa master by the replica fixes the problem. So that proves that the kdc is not picked up by discovery. The problem is that my ubuntu box was enrolled using the ipa-client-install script, and so should be properly configured.

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Karl Forner
Another piece of information: the linux boxes are running ubuntu too, with the same configuration. I have configured 2 dns servers, the first for my main freeipa server (which is down), and rhe second for the replica. After boot, the linux box can resolve addresses just fine, using the secondary d

Re: [Freeipa-users] how to force switch to another kdc

2016-01-05 Thread Karl Forner
On Tue, Jan 5, 2016 at 8:14 AM, Jakub Hrozek wrote: > On Tue, Jan 05, 2016 at 12:16:48AM +0100, Karl Forner wrote: > > Hello, > > > > My freeipa master has crashed, and I have a replica running. > > The problem is that I can not use anymore the webapps on my main server > > which use a kerberos a

Re: [Freeipa-users] how to force switch to another kdc

2016-01-04 Thread Jakub Hrozek
On Tue, Jan 05, 2016 at 12:16:48AM +0100, Karl Forner wrote: > Hello, > > My freeipa master has crashed, and I have a replica running. > The problem is that I can not use anymore the webapps on my main server > which use a kerberos authentication since my server will not switch to the > kdc on my

[Freeipa-users] how to force switch to another kdc

2016-01-04 Thread Karl Forner
Hello, My freeipa master has crashed, and I have a replica running. The problem is that I can not use anymore the webapps on my main server which use a kerberos authentication since my server will not switch to the kdc on my replica. I remember that someone replied me on this list about that prob