[Freeipa-users] SELinux error during ipa-server-install

2012-02-10 Thread Marco Pizzoli
Hi guys, I'm working on Fedora16 and FreeIPA 2.1.4. I executed the command ipa-server-install and during the setup digging in the logs i can find this error, related to SELinux. I'm running in Permissive mode, so nothing prevented me to successfully complete my setup. Is this an error in the

Re: [Freeipa-users] SELinux error during ipa-server-install

2012-02-10 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Marco I had a very similar issue trying to do the same thing a while back on the day RHEL 6.2 went GA.. My situation was SElinux enforcing, then run ipa-server-install.. it gets half way through the process and it fails then I tried SELinux

Re: [Freeipa-users] SELinux error during ipa-server-install

2012-02-10 Thread Marco Pizzoli
Hi Dale, On Fri, Feb 10, 2012 at 1:50 PM, Dale Macartney d...@themacartneyclan.comwrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Marco I had a very similar issue trying to do the same thing a while back on the day RHEL 6.2 went GA.. My situation was SElinux enforcing, then

Re: [Freeipa-users] SELinux error during ipa-server-install

2012-02-10 Thread Alexander Bokovoy
On Fri, 10 Feb 2012, Marco Pizzoli wrote: Hi guys, I'm working on Fedora16 and FreeIPA 2.1.4. I executed the command ipa-server-install and during the setup digging in the logs i can find this error, related to SELinux. I'm running in Permissive mode, so nothing prevented me to successfully

Re: [Freeipa-users] SELinux error during ipa-server-install

2012-02-10 Thread Marco Pizzoli
Hi Alexander, On Fri, Feb 10, 2012 at 2:47 PM, Alexander Bokovoy aboko...@redhat.comwrote: On Fri, 10 Feb 2012, Marco Pizzoli wrote: Hi guys, I'm working on Fedora16 and FreeIPA 2.1.4. I executed the command ipa-server-install and during the setup digging in the logs i can find this

Re: [Freeipa-users] Replicas in a state of confusion

2012-02-10 Thread Simo Sorce
On Thu, 2012-02-09 at 17:01 -0700, Rich Megginson wrote: This may be related to https://fedorahosted.org/389/ticket/273 and https://fedorahosted.org/389/ticket/274 which have been fixed in 1.2.10 In this case Ian please open a bugzilla, it looks like we need to address this in RHEL6. Simo.

[Freeipa-users] Dovecot SSO Authentication HowTo is now available on Wiki

2012-02-10 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi All I have added a walk through on configuring Dovecot to use IMAPS with SSO support to the Wiki. http://freeipa.org/page/Dovecot_IMAPS_Integration_with_FreeIPA_using_Single_Sign_On Feed back is more than welcome Dale -BEGIN PGP

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Stephen Gallagher
On Fri, 2012-02-10 at 10:50 +0100, Marco Pizzoli wrote: Hi, On Mon, Jan 30, 2012 at 4:55 PM, Dmitri Pal d...@redhat.com wrote: On 01/30/2012 09:47 AM, Marco Pizzoli wrote: Hi guys, Next days I'm going to start a test deployment of FreeIPA 2.1 but the

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Simo Sorce
On Fri, 2012-02-10 at 15:30 +0100, Marco Pizzoli wrote: On Fri, Feb 10, 2012 at 3:24 PM, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2012-02-10 at 10:50 +0100, Marco Pizzoli wrote: Hi, On Mon, Jan 30, 2012 at 4:55 PM, Dmitri Pal

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Rob Crittenden
Simo Sorce wrote: On Fri, 2012-02-10 at 15:30 +0100, Marco Pizzoli wrote: On Fri, Feb 10, 2012 at 3:24 PM, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2012-02-10 at 10:50 +0100, Marco Pizzoli wrote: Hi, On Mon, Jan 30, 2012 at 4:55 PM, Dmitri

Re: [Freeipa-users] syncing users more not limited to a subtree

2012-02-10 Thread Rich Megginson
On 02/10/2012 04:01 AM, David Juran wrote: Hello I wonder if it's somehow possible to sync AD-users more selectively then just by sub-tree. In my case, I'm dealing with a very large organisation where the users that are to be synced to IPA aren't grouped by a subtree in AD but rather spread

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Marco Pizzoli
On Fri, Feb 10, 2012 at 3:56 PM, Rob Crittenden rcrit...@redhat.com wrote: Simo Sorce wrote: On Fri, 2012-02-10 at 15:30 +0100, Marco Pizzoli wrote: On Fri, Feb 10, 2012 at 3:24 PM, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2012-02-10 at 10:50 +0100, Marco Pizzoli

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Rob Crittenden
Marco Pizzoli wrote: On Fri, Feb 10, 2012 at 3:56 PM, Rob Crittenden rcrit...@redhat.com mailto:rcrit...@redhat.com wrote: Simo Sorce wrote: On Fri, 2012-02-10 at 15:30 +0100, Marco Pizzoli wrote: On Fri, Feb 10, 2012 at 3:24 PM, Stephen Gallagher

Re: [Freeipa-users] syncing users more not limited to a subtree

2012-02-10 Thread Rich Megginson
On 02/10/2012 11:41 AM, Dmitri Pal wrote: On 02/10/2012 10:28 AM, Rich Megginson wrote: On 02/10/2012 04:01 AM, David Juran wrote: Hello I wonder if it's somehow possible to sync AD-users more selectively then just by sub-tree. In my case, I'm dealing with a very large organisation where the

Re: [Freeipa-users] syncing users more not limited to a subtree

2012-02-10 Thread Dmitri Pal
On 02/10/2012 01:46 PM, Rich Megginson wrote: On 02/10/2012 11:41 AM, Dmitri Pal wrote: On 02/10/2012 10:28 AM, Rich Megginson wrote: On 02/10/2012 04:01 AM, David Juran wrote: Hello I wonder if it's somehow possible to sync AD-users more selectively then just by sub-tree. In my case, I'm

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Marco Pizzoli
On Fri, Feb 10, 2012 at 3:24 PM, Stephen Gallagher sgall...@redhat.comwrote: On Fri, 2012-02-10 at 10:50 +0100, Marco Pizzoli wrote: Hi, On Mon, Jan 30, 2012 at 4:55 PM, Dmitri Pal d...@redhat.com wrote: On 01/30/2012 09:47 AM, Marco Pizzoli wrote: Hi guys,

Re: [Freeipa-users] syncing users more not limited to a subtree

2012-02-10 Thread Rich Megginson
On 02/10/2012 12:18 PM, Dmitri Pal wrote: On 02/10/2012 01:46 PM, Rich Megginson wrote: On 02/10/2012 11:41 AM, Dmitri Pal wrote: On 02/10/2012 10:28 AM, Rich Megginson wrote: On 02/10/2012 04:01 AM, David Juran wrote: Hello I wonder if it's somehow possible to sync AD-users more

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread John Dennis
On 02/10/2012 02:22 PM, Marco Pizzoli wrote: I wget-ed the repo file on a 64bit fedora16 system but I'm failing in seeing the package for 64-bit systems. Please, could you tell me what my error is? We just finished rebuilding the repo. Please try again. We don't have a mechanism to lock the

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread John Dennis
On 02/10/2012 02:35 PM, Marco Pizzoli wrote: No, same as before. Is it yum makecache sufficient to renew my metadata? Sounds like it should work, I'm not in the habit of using makecache, I tend to use the big hammer 'yum clean --all' I just checked the repo the files are there, so I assume

Re: [Freeipa-users] Replicas in a state of confusion

2012-02-10 Thread Ian Levesque
On Feb 10, 2012, at 1:36 PM, Rich Megginson wrote: This may be related to https://fedorahosted.org/389/ticket/273 and https://fedorahosted.org/389/ticket/274 which have been fixed in 1.2.10 In this case Ian please open a bugzilla, it looks like we need to address this in RHEL6. I'll

Re: [Freeipa-users] syncing users more not limited to a subtree

2012-02-10 Thread Rob Crittenden
Rich Megginson wrote: On 02/10/2012 11:41 AM, Dmitri Pal wrote: On 02/10/2012 10:28 AM, Rich Megginson wrote: On 02/10/2012 04:01 AM, David Juran wrote: Hello I wonder if it's somehow possible to sync AD-users more selectively then just by sub-tree. In my case, I'm dealing with a very large

[Freeipa-users] FreeIPA support for AIX as a client?

2012-02-10 Thread Marco Pizzoli
Hi guys, I see in the (Fedora 15) FreeIPA documentation that IBM AIX as a client is supported for version 5.3. What about versions 6.1 and 7.1? Are they really not supported or simply not been verified they can work? Thanks Marco ___ Freeipa-users

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Stephen Gallagher
On Fri, 2012-02-10 at 16:18 -0500, John Dennis wrote: On 02/10/2012 03:49 PM, Marco Pizzoli wrote: -- Finished Dependency Resolution *Error: Protected multilib versions: libldb-1.1.0-1.fc16.i686 != libldb-1.1.4-1.fc16.1.x86_64* This error is because you've got both a 32-bit and 64-bit

Re: [Freeipa-users] FreeIPA 2.2 alpha or beta available somewhere?

2012-02-10 Thread Marco Pizzoli
On Fri, Feb 10, 2012 at 10:18 PM, John Dennis jden...@redhat.com wrote: On 02/10/2012 03:49 PM, Marco Pizzoli wrote: -- Finished Dependency Resolution *Error: Protected multilib versions: libldb-1.1.0-1.fc16.i686 != libldb-1.1.4-1.fc16.1.x86_64* This error is because you've got both a

Re: [Freeipa-users] FreeIPA support for AIX as a client?

2012-02-10 Thread Dmitri Pal
On 02/10/2012 04:16 PM, Marco Pizzoli wrote: Hi guys, I see in the (Fedora 15) FreeIPA documentation that IBM AIX as a client is supported for version 5.3. What about versions 6.1 and 7.1? Are they really not supported or simply not been verified they can work? You are definitely welcome to

Re: [Freeipa-users] Roles and permissions

2012-02-10 Thread Adam Young
On 02/07/2012 03:54 PM, Steven Jones wrote: Hi, Users in group A can manage the membership of group B Users in group A can manage this small set of attributes of members of group B Yes, I can see that delegating is going to be very hard to do securely / properly.at least with [my] limited