Re: [Freeipa-users] [SSSD] New mailing list: sssd-users

2012-05-23 Thread Greg.Lehmann
Hi All, Thanks for the new list. I hope the user list will still get to see some of the design decisions. It would be nice to have input as a user to what is going to be added feature wise to sssd. Cheers, Greg -Original Message- From:

Re: [Freeipa-users] [SSSD] New mailing list: sssd-users

2012-05-23 Thread Ondrej Valousek
+1 On 05/22/2012 11:47 PM, greg.lehm...@csiro.au wrote: Hi All, Thanks for the new list. I hope the user list will still get to see some of the design decisions. It would be nice to have input as a user to what is going to be added feature wise to sssd. Cheers, Greg -Original

[Freeipa-users] PKI Subsystem Type: CA Clone convert to Root

2012-05-23 Thread James Hogarth
I'll see if I can get one of the dogtag guys to take a look at this. In general, this is not really a big problem. All we are doing here is deciding which of the CAs will generate the CRL. You want just one because other operations are happening at the same time, potentially on other CAs,

Re: [Freeipa-users] PKI Subsystem Type: CA Clone convert to Root

2012-05-23 Thread Andrew Wnuk
On 05/23/2012 08:59 AM, James Hogarth wrote: I'll see if I can get one of the dogtag guys to take a look at this. In general, this is not really a big problem. All we are doing here is deciding which of the CAs will generate the CRL. You want just one because other operations are happening at

[Freeipa-users] I've done it by myself and it works -- Re: Feature request: Web UI for IPA users to reset their own expired passwords

2012-05-23 Thread Gelen James
I've coded it with python-kerberos and it works. Pretty rough though. --Gelen. From: Gelen James hahaha_...@yahoo.com To: freeipa-de...@redhat.com freeipa-de...@redhat.com Sent: Sunday, May 20, 2012 2:22 AM Subject: Feature request: Web UI for IPA users to

Re: [Freeipa-users] [Freeipa-devel] I've done it by myself and it works -- Re: Feature request: Web UI for IPA users to reset their own expired passwords

2012-05-23 Thread Rob Crittenden
Gelen James wrote: I've coded it with python-kerberos and it works. Pretty rough though. Is this something you'd be interested in contributing? rob --Gelen. *From:* Gelen James hahaha_...@yahoo.com *To:*

Re: [Freeipa-users] [Freeipa-devel] I've done it by myself and it works -- Re: Feature request: Web UI for IPA users to reset their own expired passwords

2012-05-23 Thread Gelen James
No problem. The code is attached. It is just one python script, with configuration items on the top.  Please be reminded that this code is pretty rough and not well-tested as I can not find appropriate documents on how to use python kerberos module.  Disclaim: This piece of code just works as

[Freeipa-users] ipa ports

2012-05-23 Thread Jan-Frode Myklebust
We have quite strict firewalls, so I need to specify the IPA network ports accurately. So, we have now opening for: 80/tcp, 88/tcp, 389/tcp, 443/tcp, 464/tcp, 636/tcp 88/udp, 464/udp in to our first IPA server. Now I'm in the process of configuring the first replica. Is there any

Re: [Freeipa-users] freeipa 2.1.3-9 install with external CA failed

2012-05-23 Thread TChow
This is a fresh OS and IPA install. I did not create testnick, it was from the install. # certutil -V -u C -n ipa-ca-agent -d /tmp/tmp-aZzm2V certutil: certificate is invalid: Issuer certificate is invalid. # certutil -L -n ipa-ca-agent -d /tmp/tmp-aZzm2V Certificate: Data:

Re: [Freeipa-users] ipa ports

2012-05-23 Thread Dmitri Pal
On 05/23/2012 05:40 PM, Jan-Frode Myklebust wrote: We have quite strict firewalls, so I need to specify the IPA network ports accurately. So, we have now opening for: 80/tcp, 88/tcp, 389/tcp, 443/tcp, 464/tcp, 636/tcp 88/udp, 464/udp in to our first IPA server. Now I'm in the

[Freeipa-users] two way changes

2012-05-23 Thread Steven Jones
Hi, Just windering but I thought that whether I did change son the original master, or on the replica that changes would flow to the other both ways? or do changes only flow original master to replica? regards Steven Jones Technical Specialist - Linux RHCE Victoria University,