[Freeipa-users] ipa: ERROR: attribute idnsAllowTransfer not allowed

2013-02-25 Thread Sigbjorn Lie
Hi, I am trying to add a new DNS zone to our IPA server, but I receive the following error: $ ipa dnszone-add example.com --name-server=ns01.example.com --admin-email=hostmaster.example.com ipa: ERROR: attribute idnsAllowTransfer not allowed I get the same error no matter if I attempt to add

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Jakub Hrozek
On Sat, Feb 23, 2013 at 10:40:03PM +, Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/23/2013 10:36 PM, Rob Crittenden wrote: Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Even folks I've verified this both in a kickstart

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2013 10:15 AM, Jakub Hrozek wrote: On Sat, Feb 23, 2013 at 10:40:03PM +, Dale Macartney wrote: On 02/23/2013 10:36 PM, Rob Crittenden wrote: Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Even folks

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Jakub Hrozek
On Mon, Feb 25, 2013 at 10:30:44AM +, Dale Macartney wrote: What state is your SELinux in? Permissive/Enforcing/Disabled ? Another fail on my part. Works fine in permissive mode. No, the SSSD should be working out of the box with SELinux Enforcing. AVC denials listed below..

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2013 10:58 AM, Jakub Hrozek wrote: On Mon, Feb 25, 2013 at 10:30:44AM +, Dale Macartney wrote: What state is your SELinux in? Permissive/Enforcing/Disabled ? Another fail on my part. Works fine in permissive mode. No, the SSSD

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Jakub Hrozek
On Mon, Feb 25, 2013 at 11:06:09AM +, Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2013 10:58 AM, Jakub Hrozek wrote: On Mon, Feb 25, 2013 at 10:30:44AM +, Dale Macartney wrote: What state is your SELinux in? Permissive/Enforcing/Disabled ?

Re: [Freeipa-users] RHEL 6.4 ipa-client install on ipa member server

2013-02-25 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2013 11:15 AM, Jakub Hrozek wrote: On Mon, Feb 25, 2013 at 11:06:09AM +, Dale Macartney wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/25/2013 10:58 AM, Jakub Hrozek wrote: On Mon, Feb 25, 2013 at 10:30:44AM +,

Re: [Freeipa-users] ipa: ERROR: attribute idnsAllowTransfer not allowed

2013-02-25 Thread Christian Horn
Hi, On Mon, Feb 25, 2013 at 09:46:49AM +0100, Sigbjorn Lie wrote: $ ipa dnszone-add example.com --name-server=ns01.example.com --admin-email=hostmaster.example.com ipa: ERROR: attribute idnsAllowTransfer not allowed [..] Is this a known error? Yes, the idnsZone objectClass entry was

Re: [Freeipa-users] Transferring mastership to a new server

2013-02-25 Thread Petr Viktorin
On 02/25/2013 03:04 PM, Bret Wortman wrote: So I managed to replicate my old IPA master onto a new server, and now I'd like that server to be the center of the universe. The master from which all (new) replicas are created. At present, there are no other replicas, just this one server now that

Re: [Freeipa-users] ipa: ERROR: attribute 'idnsAllowTransfer' not allowed

2013-02-25 Thread Sigbjorn Lie
On Mon, February 25, 2013 12:59, Christian Horn wrote: Hi, On Mon, Feb 25, 2013 at 09:46:49AM +0100, Sigbjorn Lie wrote: $ ipa dnszone-add example.com --name-server=ns01.example.com --admin-email=hostmaster.example.com ipa: ERROR: attribute idnsAllowTransfer not allowed [..] Is this

[Freeipa-users] Non-Prod instance

2013-02-25 Thread Guy Matz
Hello! Does anyone out there run two instances of freeipa, prod non-prod instances? Are there any issues to be wary of in this scenario? Any gotchas? Do you use the same realms domain names between instances? Perhaps the fellow who upgraded his prod server to 6.4 might appreciate this

[Freeipa-users] nsslapd-changelogmaxage

2013-02-25 Thread Kriss Von Prosst
Hi, I have multimaster replication enviroment, IPA v2.2 on Fedora 17. On each replica, folder /var/lib/dirsrv/slapd-cosp/cldb/ has big size (~7GB). This is half of all available space for '/'. I found that changelog file can be trim using 'nsslapd-changelogmaxage' parameter. By default, this

Re: [Freeipa-users] nsslapd-changelogmaxage

2013-02-25 Thread Rich Megginson
On 02/25/2013 11:33 AM, Kriss Von Prosst wrote: Hi, I have multimaster replication enviroment, IPA v2.2 on Fedora 17. On each replica, folder /var/lib/dirsrv/slapd-cosp/cldb/ has big size (~7GB). This is half of all available space for '/'. I found that changelog file can be trim using

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-25 Thread Mercer, Rodney
On Mon, 2013-02-25 at 18:48 +, Mercer, Rodney wrote: On Thu, 2013-02-21 at 03:53 -0500, Dmitri Pal wrote: On 02/20/2013 08:44 AM, Rodney L. Mercer wrote: On Tue, 2013-02-19 at 21:05 -0500, Dmitri Pal wrote: On 02/19/2013 09:14 AM, Rodney L. Mercer wrote: On Sun, 2013-02-17