Re: [Freeipa-users] Migration mode fun and confusion

2015-04-01 Thread Martin Kosek
On 03/31/2015 04:50 PM, Janelle wrote: On 3/31/15 6:49 AM, Dmitri Pal wrote: On 03/31/2015 09:38 AM, Janelle wrote: Hello again, Is this a feature or a bug? Migration mode - works fine the first time. However, if you need to run it a second time because someone added either new users

Re: [Freeipa-users] Migration mode fun and confusion

2015-03-31 Thread Rob Crittenden
Dmitri Pal wrote: On 03/31/2015 09:38 AM, Janelle wrote: Hello again, Is this a feature or a bug? Migration mode - works fine the first time. However, if you need to run it a second time because someone added either new users or groups to your LDAP config and you want to bring those over,

Re: [Freeipa-users] Migration mode fun and confusion

2015-03-31 Thread Dmitri Pal
On 03/31/2015 10:50 AM, Janelle wrote: On 3/31/15 6:49 AM, Dmitri Pal wrote: On 03/31/2015 09:38 AM, Janelle wrote: Hello again, Is this a feature or a bug? Migration mode - works fine the first time. However, if you need to run it a second time because someone added either new users or

Re: [Freeipa-users] Migration mode fun and confusion

2015-03-31 Thread Dmitri Pal
On 03/31/2015 09:38 AM, Janelle wrote: Hello again, Is this a feature or a bug? Migration mode - works fine the first time. However, if you need to run it a second time because someone added either new users or groups to your LDAP config and you want to bring those over, if you re-run

Re: [Freeipa-users] Migration mode fun and confusion

2015-03-31 Thread Janelle
On 3/31/15 6:49 AM, Dmitri Pal wrote: On 03/31/2015 09:38 AM, Janelle wrote: Hello again, Is this a feature or a bug? Migration mode - works fine the first time. However, if you need to run it a second time because someone added either new users or groups to your LDAP config and you want

Re: [Freeipa-users] Migration mode

2014-03-13 Thread Jitse Klomp
2014-03-11 16:15 GMT+01:00 Jitse Klomp jitsekl...@gmail.com: On 03/11/2014 03:06 PM, Sumit Bose wrote: On Mon, Mar 10, 2014 at 11:09:48PM +0100, Jitse Klomp wrote: On 10-03-14 22:06, Sumit Bose wrote: Thank you. Maybe there is a change in return codes between MIT Kerberos 1.10 (Centos 6)

Re: [Freeipa-users] Migration mode

2014-03-13 Thread Lukas Slebodnik
On (13/03/14 14:51), Jitse Klomp wrote: 2014-03-11 16:15 GMT+01:00 Jitse Klomp jitsekl...@gmail.com: On 03/11/2014 03:06 PM, Sumit Bose wrote: On Mon, Mar 10, 2014 at 11:09:48PM +0100, Jitse Klomp wrote: On 10-03-14 22:06, Sumit Bose wrote: Thank you. Maybe there is a change in return

Re: [Freeipa-users] Migration mode

2014-03-13 Thread Jitse Klomp
2014-03-13 18:00 GMT+01:00 Lukas Slebodnik lsleb...@redhat.com: On (13/03/14 14:51), Jitse Klomp wrote: 2014-03-11 16:15 GMT+01:00 Jitse Klomp jitsekl...@gmail.com: On 03/11/2014 03:06 PM, Sumit Bose wrote: On Mon, Mar 10, 2014 at 11:09:48PM +0100, Jitse Klomp wrote: On 10-03-14

Re: [Freeipa-users] Migration mode

2014-03-11 Thread Jitse Klomp
On 03/11/2014 03:06 PM, Sumit Bose wrote: On Mon, Mar 10, 2014 at 11:09:48PM +0100, Jitse Klomp wrote: On 10-03-14 22:06, Sumit Bose wrote: Thank you. Maybe there is a change in return codes between MIT Kerberos 1.10 (Centos 6) and 1.11 (F20, RHEL7). Can you try to run KRB5_TRACE=/dev/stdout

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using migrate-ds I used some custom scripts to import all of our users (~250) and groups (~85) with IPA commands (ipa user-add etc.). To move passwords I configured the ipa-server to

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using migrate-ds I used some custom scripts to import all of our users (~250) and groups (~85) with IPA commands (ipa user-add etc.). To

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using migrate-ds I used some custom scripts to import all of our users (~250) and groups (~85)

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jakub Hrozek
On Mon, Mar 10, 2014 at 03:19:28PM +0100, Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using migrate-ds I used some

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using migrate-ds I used some custom scripts to import all of

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system to IPA. Instead of using

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all, I'm migrating our OpenLDAP-based IdM-system

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55), Jitse Klomp wrote: Hello all,

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Rob Crittenden
Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59, Jitse Klomp wrote: On 10-03-14 14:35, Lukas Slebodnik wrote: On (10/03/14 13:55),

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Sumit Bose
On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19), Jitse Klomp wrote: On 10-03-14 14:59,

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On (10/03/14 15:19),

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Rob Crittenden
Jitse Klomp wrote: On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14 16:10, Lukas Slebodnik wrote: On

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Sumit Bose
On Mon, Mar 10, 2014 at 07:56:07PM +0100, Jitse Klomp wrote: On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 20:34, Sumit Bose wrote: On Mon, Mar 10, 2014 at 07:56:07PM +0100, Jitse Klomp wrote: On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 15:14), Rob Crittenden wrote: Jitse Klomp wrote: On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On (10/03/14 16:35), Jitse Klomp wrote: On 10-03-14

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Lukas Slebodnik
On (10/03/14 21:47), Lukas Slebodnik wrote: On (10/03/14 15:14), Rob Crittenden wrote: Jitse Klomp wrote: On 10-03-14 18:57, Sumit Bose wrote: On Mon, Mar 10, 2014 at 05:23:59PM +0100, Jitse Klomp wrote: On 10-03-14 17:03, Lukas Slebodnik wrote: On (10/03/14 16:58), Lukas Slebodnik wrote: On

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Simo Sorce
On Mon, 2014-03-10 at 21:47 +0100, Lukas Slebodnik wrote: Output of ldapsearch *after* logging in to CentOS for the first time: krbPasswordExpiration: 20140310183603Z krbLastPwdChange: 20140310183603Z Why is the password exporation the same as the last password change? This

Re: [Freeipa-users] Migration mode

2014-03-10 Thread Jitse Klomp
On 10-03-14 22:06, Sumit Bose wrote: Thank you. Maybe there is a change in return codes between MIT Kerberos 1.10 (Centos 6) and 1.11 (F20, RHEL7). Can you try to run KRB5_TRACE=/dev/stdout kinit unmigrated_u...@domain.nl on the different platforms and paste the results? I would expect to see