Re: [Freeipa-users] Serving RFC2307 to OS X clients

2012-06-07 Thread Nalin Dahyabhai
On Thu, Jun 07, 2012 at 05:03:11PM -0400, Ian Levesque wrote: Hello, I've read that the schema compatibility plugin should provide a vanilla RFC 2307 view of groups with memberUid attributes. I need this for our OS X clients, which don't seem capable of understanding the RFC 2307bis format

Re: [Freeipa-users] Serving RFC2307 to OS X clients

2012-06-07 Thread Ian Levesque
On Jun 7, 2012, at 5:27 PM, Nalin Dahyabhai wrote: On Thu, Jun 07, 2012 at 05:03:11PM -0400, Ian Levesque wrote: Hello, I've read that the schema compatibility plugin should provide a vanilla RFC 2307 view of groups with memberUid attributes. I need this for our OS X clients, which

Re: [Freeipa-users] Serving RFC2307 to OS X clients

2012-06-07 Thread Nalin Dahyabhai
On Thu, Jun 07, 2012 at 05:44:16PM -0400, Nalin Dahyabhai wrote: The results should look like this: dn: cn=Schema Compatibility,cn=plugins,cn=config nsslapd-pluginEnabled: off Yeah, that second line should be nsslapd-pluginEnabled: on. *facepalm* Nalin

Re: [Freeipa-users] running ipa-server-install --uninstall hangs

2012-06-07 Thread Rob Crittenden
It is hanging because the dirsrv instance isn't starting. Check for AVCs, /var/log/messages, dmesg, /var/log/dirsrv/slapd-YOURINSTANCE/errors to see if any errors are being reported. Steven Jones wrote: NB ipam005 is the renamed ipam002, which despite trying to remove seems to have residual

[Freeipa-users] ipa server is not version 2 error

2012-06-07 Thread Steven Jones
Hi, I am getting this while trying to join a new client to a IPA domain. um? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272attachment: ipa-not-v2-error-01.jpeg___ Freeipa-users mailing

Re: [Freeipa-users] Serving RFC2307 to OS X clients

2012-06-07 Thread Ian Levesque
On Jun 7, 2012, at 6:46 PM, Nalin Dahyabhai wrote: On Thu, Jun 07, 2012 at 05:56:14PM -0400, Ian Levesque wrote: On Jun 7, 2012, at 5:44 PM, Nalin Dahyabhai wrote: ldapsearch -h sbgrid-directory -Y GSSAPI \ -b cn=Schema Compatibility,cn=plugins,cn=config \ nsslapd-pluginEnabled

[Freeipa-users] HBAC rule refreshes and read-only slaves

2012-06-07 Thread Cam McK
Hello Thanks for an awesome product! I have two questions that I can't seem to find answers for... 1). How long is the delay between changing a HBAC rule and it coming into affect on the host machine? Currently this information only seems to be updated on the host after an 'service sssd

Re: [Freeipa-users] running ipa-server-install --uninstall hangs

2012-06-07 Thread Rob Crittenden
Steven Jones wrote: Hi, Im must not be getting it, If I am un-installing and the dirsrv has been stopped as part of that process? why does it need to restart? if Im uninstalling? Because it needs to stop all the IPA services. The list of services is stored in LDAP. If I run a host del

Re: [Freeipa-users] ipa server is not version 2 error

2012-06-07 Thread Rob Crittenden
Steven Jones wrote: Hi, I am getting this while trying to join a new client to a IPA domain. Look in the client install log, there should be more detail there. Basically we were given a server to try, we tried it and either we couldn't reach it at all or we weren't able to read the version

Re: [Freeipa-users] running ipa-server-install --uninstall hangs

2012-06-07 Thread Steven Jones
Hi, The replica server no long exists, I bare metal kick-started it...so I need to get it to rejoin the domain which it wont. Given all the other issues Im wondering if a totally clean start isnt a plan now... regards Steven Jones Technical Specialist - Linux RHCE Victoria University,