Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-07 Thread Alexander Bokovoy
On Thu, 03 Apr 2014, Matthew W Hanley wrote: I'm in the midst of setting up a trust with FreeIPA and Active Directory and am receiving the following error: # ipa trust-add --type=ad ad.example.com --admin 'mwhanley' --password Active directory domain administrator's password: ipa: ERROR:

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-04 Thread Redmond, Stacy
You are absolutlely right, I had rebuilt the server, and had forgotten to put the log level back in, here it is. [root@linuxtest1 ~]# cat /var/log/httpd/error_log /dev/null lpcfg_load: refreshing parameters from /usr/share/ipa/smb.conf.empty params.c:pm_process() - Processing configuration file

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-04 Thread Alexander Bokovoy
On Fri, 04 Apr 2014, Redmond, Stacy wrote: You are absolutlely right, I had rebuilt the server, and had forgotten to put the log level back in, here it is. [root@linuxtest1 ~]# cat /var/log/httpd/error_log /dev/null lpcfg_load: refreshing parameters from /usr/share/ipa/smb.conf.empty

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-04 Thread Redmond, Stacy
We will be using unix as the Kerberos realm and unix.sbx.local as the domain so we can use srv records for the unix hosts to point at ipa. The AD domain is sbx.local, here is the output using the AD domain [root@linuxtest1 ~]# ipa trust-add --type=ad sbx.local --admin Administrator --password

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-04 Thread Alexander Bokovoy
On Fri, 04 Apr 2014, Redmond, Stacy wrote: We will be using unix as the Kerberos realm and unix.sbx.local as the domain so we can use srv records for the unix hosts to point at ipa. The AD domain is sbx.local, here is the output using the AD domain [root@linuxtest1 ~]# ipa trust-add --type=ad

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-03 Thread Redmond, Stacy
Yes, I did that, here is the log [Thu Apr 03 13:21:52 2014] [error] [client 10.130.82.68] Credentials for HTTP/linuxtest1.sbx.local@UNIX have expired or will soon expire - now 1396556512 endtime 1396551629, referer: https://linuxtest1.sbx.local/ipa/xml [Thu Apr 03 13:21:52 2014] [error] [client

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-03 Thread Alexander Bokovoy
On Thu, 03 Apr 2014, Redmond, Stacy wrote: Yes, I did that, here is the log [Thu Apr 03 13:21:52 2014] [error] [client 10.130.82.68] Credentials for HTTP/linuxtest1.sbx.local@UNIX have expired or will soon expire - now 1396556512 endtime 1396551629, referer: https://linuxtest1.sbx.local/ipa/xml