Re: [Freeipa-users] cross realm trust - SID doesn't resolve

2012-12-10 Thread Alexander Bokovoy
On Sun, 09 Dec 2012, Brian Cook wrote: Good to know my setup is working, but for administration purposes displaying a SID in the GUI is as useless as displaying UID's with no user name. SID's are not meant for human eyes. Is there some issue with resolving it to the name and displaying the

Re: [Freeipa-users] how to allow a remote realm user to be an IPA admin?

2012-12-10 Thread Alexander Bokovoy
On Sun, 09 Dec 2012, Brian Cook wrote: How do you let a remote user be an admin for IPA? You cannot do it, at least right now. I followed the fedora group example external group:ad_admins_external Posix Group: ad_admins Then I made ad_admins a group member of ipa group 'admins' -

Re: [Freeipa-users] Certificate serial number not found error

2012-12-10 Thread Rob Crittenden
James Hogarth wrote: Hi, When trying to view a particular service (or the related host) I'm getting the following error in the UI: IPA Error 4301 Certificate operation cannot be completed: EXCEPTION (Certificate serial number 0xffe000c not found) Now I've seen similar issue in the past when

Re: [Freeipa-users] Cmd-line Unprovision OTP setting for a host

2012-12-10 Thread Dmitri Pal
On 12/07/2012 10:15 PM, Charlie Derwent wrote: Sorry for the extremely late reply, rebuilds of clients, keytab and configuration primarily but certs too would be nice. What we currently do during our provisioning process is disable the host and reset the password (as previously mentioned)

Re: [Freeipa-users] how to allow a remote realm user to be an IPA admin?

2012-12-10 Thread Simo Sorce
On Mon, 2012-12-10 at 14:25 +0200, Alexander Bokovoy wrote: On Sun, 09 Dec 2012, Brian Cook wrote: How do you let a remote user be an admin for IPA? You cannot do it, at least right now. I followed the fedora group example external group:ad_admins_external Posix Group: ad_admins

Re: [Freeipa-users] cross realm trust - SID doesn't resolve

2012-12-10 Thread Brian Cook
Okay, I'll open an RFE. Fwiw, when AD can't resolve a SID for any reason, it does display the SID itself but only as a fallback mechanism. I think this would be acceptable behavior. -Brian On Dec 10, 2012, at 4:12 AM, Alexander Bokovoy aboko...@redhat.com wrote: On Sun, 09 Dec 2012,

Re: [Freeipa-users] cross realm trust - SID doesn't resolve

2012-12-10 Thread Dmitri Pal
On 12/10/2012 12:04 PM, Brian Cook wrote: Okay, I'll open an RFE. Fwiw, when AD can't resolve a SID for any reason, it does display the SID itself but only as a fallback mechanism. I think this would be acceptable behavior. Now I think you understand why it is a tech preview. You hit

[Freeipa-users] Announcing FreeIPA v3.1.0 Release

2012-12-10 Thread Rob Crittenden
The FreeIPA team is proud to announce version FreeIPA v3.1.0. It can be downloaded from http://www.freeipa.org/page/Downloads. A build will be submitted to updates-testing for Fedora 18 soon. == Highlights in 3.1.0 == * A single 389-ds instance is used both for IPA identity data and for the