Re: [Freeipa-users] IPA weirdness with Samba, Dovecot IMAP and SSHD

2012-11-19 Thread Natxo Asenjo
hi, Qing On Sat, Nov 17, 2012 at 8:20 PM, Qing Chang qch...@sri.utoronto.ca wrote: 2, Dovecot + IPA: it is not an IPA issue but sss cache timeout issue, I read it's 90 min? When a user changes his/her password, the cache usually is not updated, hence problem checking IMAP email with

[Freeipa-users] DNSSEC DNS zone spoofing (was: Problem adding DNS Zones)

2012-11-19 Thread Petr Spacek
Hello, On 11/16/2012 04:11 PM, Bret Wortman wrote: Using FreeIPA on a private network (where it's easier to just alias our own servers to these names than to edit config file after config file). Any idea what I'm doing wrong here? # ipa dnszone-add 0.pool.ntp.org http://0.pool.ntp.org

[Freeipa-users] IPA'd users not going through .bashrc

2012-11-19 Thread Bret Wortman
I've noticed that my users who are provided identities through IPA aren't having their .bashrc and other login profile files run when they log in. I tried googling this issue but haven't found anything. Has anyone else encountered this? Puppet 3.0.1 from puppetlabs' repos on F17. -- Bret

Re: [Freeipa-users] IPA'd users not going through .bashrc

2012-11-19 Thread Bret Wortman
Never mind. Had the default shell set to /bin/sh. On Mon, Nov 19, 2012 at 10:22 AM, Bret Wortman bret.wort...@damascusgrp.com wrote: I've noticed that my users who are provided identities through IPA aren't having their .bashrc and other login profile files run when they log in. I tried

Re: [Freeipa-users] Problem with password reset on ubuntu 12.04 (lightdm)

2012-11-19 Thread Dmitri Pal
On 11/19/2012 04:37 AM, Marc Grimme wrote: (Mon Nov 19 10:33:33 2012) [[sssd[krb5_child[19943 [krb5_child_setup] (0x4000): Not using FAST. (Mon Nov 19 10:33:33 2012) [[sssd[krb5_child[19943 [changepw_child] (0x0020): krb5_change_password failed [2][Server error]. (Mon Nov 19 10:33:33

Re: [Freeipa-users] IPA weirdness with Samba, Dovecot IMAP and SSHD

2012-11-19 Thread Qing Chang
On 19/11/2012 3:33 AM, Natxo Asenjo wrote: hi, Qing On Sat, Nov 17, 2012 at 8:20 PM, Qing Chang qch...@sri.utoronto.ca wrote: 2, Dovecot + IPA: it is not an IPA issue but sss cache timeout issue, I read it's 90 min? When a user changes his/her password, the cache usually is not updated,

Re: [Freeipa-users] Problem with password reset on ubuntu 12.04 (lightdm)

2012-11-19 Thread Marc Grimme
This is what the kerberos (kadmin.log) shows on the relevant IPA server. Nov 19 17:29:54 axinfra02-1.cl.atix kadmind[18851](Error): password quality module empty rejected password for tu...@cl.atix: Empty passwords are not allowed Nov 19 17:29:54 axinfra02-1.cl.atix kadmind[18851](Notice): chpw

Re: [Freeipa-users] IPA weirdness with Samba, Dovecot IMAP and SSHD

2012-11-19 Thread Dmitri Pal
On 11/17/2012 02:20 PM, Qing Chang wrote: On 16/11/2012 12:11 PM, Dmitri Pal wrote: On 11/16/2012 10:59 AM, Qing Chang wrote: just migrated all my user from OpenLDAP and MIT Kerberos to IPA. Out of more than 400 users, there are around 10 that have problem accessing Samba or Dovecot IMAP or

[Freeipa-users] passwd: Authentication token manipulation error

2012-11-19 Thread Marcello Giannoni UCLA
Hi THis morning I was asked to reset the user password of one of our IPA/LDAP user accounts. After I reset the password I tried to logon to a particular ssh machine . The system asked to cheange the password as expeceted. I entered the NEw Password and the Re enter the the new password

Re: [Freeipa-users] passwd: Authentication token manipulation error

2012-11-19 Thread Dmitri Pal
On 11/19/2012 05:51 PM, Marcello Giannoni UCLA wrote: Hi THis morning I was asked to reset the user password of one of our IPA/LDAP user accounts. After I reset the password I tried to logon to a particular ssh machine . The system asked to cheange the password as expeceted. I entered