Re: [Freeipa-users] FreeIPA 2.1 - restrict users to a set of hosts

2012-06-04 Thread Martin Kosek
On Sat, 2012-06-02 at 06:52 -0700, Joe Linoff wrote: Hi: I am a newbie that is trying out FreeIPA for the first time. So far I am extremely impressed with this system but I ran into a problem that I need some help with. I am trying to figure out how to HBAC to restrict a set of users

Re: [Freeipa-users] FreeIPA 2.1 - restrict users to a set of hosts

2012-06-04 Thread Stephen Gallagher
On Mon, 2012-06-04 at 08:39 +0200, Martin Kosek wrote: On Sat, 2012-06-02 at 06:52 -0700, Joe Linoff wrote: Hi: I am a newbie that is trying out FreeIPA for the first time. So far I am extremely impressed with this system but I ran into a problem that I need some help with. I am

Re: [Freeipa-users] FreeIPA 2.1 - restrict users to a set of hosts

2012-06-04 Thread Joe Linoff
Hi Mark: Thank you for your suggestion. I will try it later today. Regards, Joe -Original Message- From: Martin Kosek [mailto:mko...@redhat.com] Sent: Sunday, June 03, 2012 11:40 PM To: Joe Linoff Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] FreeIPA 2.1 - restrict users

Re: [Freeipa-users] FreeIPA 2.1 - restrict users to a set of hosts

2012-06-04 Thread Joe Linoff
Thank you both. Turning off allow_all did the trick. Now everything works perfectly. This tool rocks! Thanks, Joe -Original Message- From: Stephen Gallagher [mailto:sgall...@redhat.com] Sent: Monday, June 04, 2012 5:10 AM To: Martin Kosek Cc: Joe Linoff; freeipa-users@redhat.com

Re: [Freeipa-users] HOWTO: Zimbra Authentication and GAL lookups with FreeIPA backend

2012-06-04 Thread Rob Crittenden
Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Morning all Just a quick mail to to let everyone know that I have placed a new wiki page for integrating Zimbra authentication and GAL lookups into IPA. Link is here

Re: [Freeipa-users] SSH Keys?

2012-06-04 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/06/12 18:28, Kline, Sara wrote: Some of my users have expressed concerns about moving to FreeIPA because they prefer to use SSH. The main reason behind that is because they can use agent forwarding and only have to sign on once. I did find

Re: [Freeipa-users] SSH Keys?

2012-06-04 Thread Kline, Sara
Yes, it does. I don't see what the problem is having to authenticate to each server. It is more secure that way, I think they are just used to being able to take shortcuts. I guess if they really fuss about it we could set up forwardable tickets. I would definitely prefer to have all of the

[Freeipa-users] su: [ID 219349 auth.debug] pam_unix_auth: user craig not found (Solaris 10 IPA client)

2012-06-04 Thread freeipa
Hi All, I'm sooo close to getting my Solaris 10 (SPARC) client to work with IPA Server: - Red Hat Enterprise Linux Server release 6.2 ipa-admintools-2.1.3-9.el6.x86_64 ipa-client-2.1.3-9.el6.x86_64 ipa-pki-ca-theme-9.0.3-7.el6.noarch ipa-pki-common-theme-9.0.3-7.el6.noarch

Re: [Freeipa-users] su: [ID 219349 auth.debug] pam_unix_auth: user craig not found (Solaris 10 IPA client)

2012-06-04 Thread Rob Crittenden
free...@noboost.org wrote: Hi All, I'm sooo close to getting my Solaris 10 (SPARC) client to work with IPA Server: - Red Hat Enterprise Linux Server release 6.2 ipa-admintools-2.1.3-9.el6.x86_64 ipa-client-2.1.3-9.el6.x86_64 ipa-pki-ca-theme-9.0.3-7.el6.noarch

[Freeipa-users] sudo documentation 6.3beta documentation page 279 section 13.2.1.1.

2012-06-04 Thread Steven Jones
Hi, Trying to setup sudo via the gui but I suspect at least one stage is missing can we have some screenshots also so I know what I'm expecting to see? = 5. Click the Add and Edit button to go immediately to the edit pages for the command. 6. In the Sudo Command Groups tab, click the

Re: [Freeipa-users] sudo documentation 6.3beta documentation page 279 section 13.2.1.1.

2012-06-04 Thread Steven Jones
or maybe instead of, 6. In the Sudo Command Groups tab, click the Add button to add the sudo command to a command group. It should be, 6. In the Sudo Command Groups tab, click the Enrol button to add the sudo command to a command group. ? regards Steven Jones Technical Specialist - Linux

Re: [Freeipa-users] sudo documentation 6.3beta documentation page 279 section 13.2.1.1.

2012-06-04 Thread Steven Jones
Also, 8. Click the Add button. should be, 8. Click the enrol button. ? Without screenshots I have no idea in the web ui if I am in the right place.. regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272