Re: [Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-04 Thread Chris Evich
On 05/04/2012 03:18 PM, Rob Crittenden wrote: Chris Evich wrote: Hi, I've got a FreeIPA setup at home I just built the other week on Fedora 16. It's a very small/basic setup I'm mainly using for secure NFS+Kerberos and automount. Today, I updated everything and rebooted, ...cut... [04/May/201

Re: [Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-04 Thread Rob Crittenden
Chris Evich wrote: Hi, I've got a FreeIPA setup at home I just built the other week on Fedora 16. It's a very small/basic setup I'm mainly using for secure NFS+Kerberos and automount. Today, I updated everything and rebooted, and all seemed to be working okay (even /var/log/ipaupgrade.log). I'm

[Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-04 Thread Chris Evich
Hi, I've got a FreeIPA setup at home I just built the other week on Fedora 16. It's a very small/basic setup I'm mainly using for secure NFS+Kerberos and automount. Today, I updated everything and rebooted, and all seemed to be working okay (even /var/log/ipaupgrade.log). I'm now running:

Re: [Freeipa-users] Does FreeIPA support web services SSO gracefully?

2012-05-04 Thread Simo Sorce
On Fri, 2012-05-04 at 11:44 -0400, John Dennis wrote: > On 05/04/2012 11:26 AM, Rob Crittenden wrote: > > Firefox needs to be configured to be allowed to perform Kerberos SSO in > > a domain. FreeIPA 2.2 introduced a forms-based login so you don't have > > to fall back to basic authentication (with

Re: [Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread Simo Sorce
On Fri, 2012-05-04 at 17:14 +0200, David Juran wrote: > On fre, 2012-05-04 at 10:52 -0400, Simo Sorce wrote: > > > > > please run: > > rpm -qa |grep cyrus-sasl > > root@zlin2011:/var/log/dirsrv/slapd-SRV-VOLVO-COM# rpm -qa |grep cyrus-sasl > cyrus-sasl-lib-2.1.23-13.el6.s390x > cyrus-sasl-md5-2.

Re: [Freeipa-users] Does FreeIPA support web services SSO gracefully?

2012-05-04 Thread John Dennis
On 05/04/2012 11:26 AM, Rob Crittenden wrote: Firefox needs to be configured to be allowed to perform Kerberos SSO in a domain. FreeIPA 2.2 introduced a forms-based login so you don't have to fall back to basic authentication (with KrbMethodK5Passwd on). The forms based login applies to the IPA

Re: [Freeipa-users] Does FreeIPA support web services SSO gracefully?

2012-05-04 Thread Rob Crittenden
cee1 wrote: 2012/5/4 Paul Robert Marino: There is a apache module for kerberos auth that works well two notes about it turn on credential caching because it significantly reduces the load on the kerberos server and keep in mind that internet explorer leaves native kerberos on (you won't get prom

Re: [Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread David Juran
On fre, 2012-05-04 at 10:52 -0400, Simo Sorce wrote: > > please run: > rpm -qa |grep cyrus-sasl root@zlin2011:/var/log/dirsrv/slapd-SRV-VOLVO-COM# rpm -qa |grep cyrus-sasl cyrus-sasl-lib-2.1.23-13.el6.s390x cyrus-sasl-md5-2.1.23-13.el6.s390x cyrus-sasl-2.1.23-13.el6.s390x cyrus-sasl-plain-2.1.23

Re: [Freeipa-users] Integrate with Samba

2012-05-04 Thread Alexander Bokovoy
On Fri, 04 May 2012, Matthew Davidson wrote: Hello, Does anyone have any pointers or documentation on integrating Samba or "file" shares with IPA? http://techslaves.org/2011/08/24/freeipa-and-samba-3-integration/ Some aspects of this instruction could be done a bit better and also IPAv3 will ha

Re: [Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread Simo Sorce
On Fri, 2012-05-04 at 16:44 +0200, David Juran wrote: > On fre, 2012-05-04 at 10:25 -0400, Simo Sorce wrote: > > On Fri, 2012-05-04 at 16:04 +0200, David Juran wrote: > > > > > > [04/May/2012:15:22:27 +0200] conn=8 fd=66 slot=66 connection from > > > local to /var/run/slapd-SRV-VOLVO-COM.socket >

[Freeipa-users] Integrate with Samba

2012-05-04 Thread Matthew Davidson
Hello, Does anyone have any pointers or documentation on integrating Samba or "file" shares with IPA? thanksMatt___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freei

Re: [Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread David Juran
On fre, 2012-05-04 at 10:25 -0400, Simo Sorce wrote: > On Fri, 2012-05-04 at 16:04 +0200, David Juran wrote: > > > > [04/May/2012:15:22:27 +0200] conn=8 fd=66 slot=66 connection from > > local to /var/run/slapd-SRV-VOLVO-COM.socket > > [04/May/2012:15:22:27 +0200] conn=8 op=0 BIND > > dn="uid=kdc,

Re: [Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread Simo Sorce
On Fri, 2012-05-04 at 16:04 +0200, David Juran wrote: > > [04/May/2012:15:22:27 +0200] conn=8 fd=66 slot=66 connection from > local to /var/run/slapd-SRV-VOLVO-COM.socket > [04/May/2012:15:22:27 +0200] conn=8 op=0 BIND > dn="uid=kdc,cn=sysaccounts,cn=etc,dc=srv,dc=volvo,dc=com" method=128 > versio

[Freeipa-users] Trying out ipa on zlinux

2012-05-04 Thread David Juran
Hello We've been trying to get IPA running on a RHEL6.2 zLinux (s390x). We've recompiled the RHEL6 SRPMS (including the 389 packages) for the architecture and eventually they installed. But when trying to set up the server, it fails when trying to create the KDC. Configuring Kerberos KDC: Estimat

Re: [Freeipa-users] Announcing FreeIPA v2.2.0 Release

2012-05-04 Thread Christoph Kaminski
are there already el5/el6 rpms somewhere? - MfG Christoph Kaminski Von: Rob Crittenden An: freeipa-devel , freeipa-users , freeipa-inter...@redhat.com Datum: 03.05.2012 21:50 Betreff: [Freeipa-users] Announcing FreeIPA v2.2.0 Release Gesendet von: freeipa-users-boun...@redhat.com The FreeI