Re: [Freeipa-users] Trusted AD Users login via gdm

2013-06-21 Thread Sumit Bose
On Thu, Jun 20, 2013 at 04:04:06PM +0200, Leah Zimmermann wrote: On 06/19/2013 03:01 PM, Sumit Bose wrote: On Tue, Jun 18, 2013 at 08:00:02AM +0200, Leah Zimmermann wrote: On 06/14/2013 09:08 AM, Sumit Bose wrote: On Thu, Jun 13, 2013 at 01:49:30PM +0200, Leah Zimmermann wrote: Hello Sumit,

Re: [Freeipa-users] FreeIPA install fails on config. of certificate server with Required parameter -client_token_name is not specified.

2013-06-21 Thread Andrew Wasielewski
Hi Rob, Thanks for the quick response. pki-ca is ver. 9.0.26, installed as a dependency by FreeIPA itself. Regards, Andrew On Thursday 20 June 2013 17:39:30 Rob Crittenden wrote: Andrew Wasielewski wrote: Hello everyone, I am trying to install FreeIPA 2.2.2 on Fedora 17 (kernel

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Rob Crittenden
Joshua J. Kugler wrote: On Wednesday, June 19, 2013 16:34:31 Joshua J. Kugler wrote: Check SSH connection to remote master Execute check on remote master Remote master check failed with following error message(s): bash: /usr/sbin/ipa-replica-conncheck: No such file or directory Connection

Re: [Freeipa-users] Trying to renew the CA cert, but NEWLY_ADDED_NEED_KEYINFO_READ_PIN

2013-06-21 Thread Rob Crittenden
Joshua J. Kugler wrote: So, ongoing saga of a FreeIPA 2.x system with an expired cert for the CA server: ca-error: Server failed request, will retry: 907 (RPC failed at server. cannot connect to 'https://ipa0.lab.whamcloud.com:9443/ca/agent/ca/displayBySerial': [Errno -8181]

Re: [Freeipa-users] Trying to renew the CA cert, but NEWLY_ADDED_NEED_KEYINFO_READ_PIN

2013-06-21 Thread Joshua J. Kugler
On Friday, June 21, 2013 09:30:12 Rob Crittenden wrote: Joshua J. Kugler wrote: So, ongoing saga of a FreeIPA 2.x system with an expired cert for the CA server: ca-error: Server failed request, will retry: 907 (RPC failed at server. cannot connect to

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Joshua J. Kugler
On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: export LDAPTLS_CACERT=/etc/ipa/ca.crt; ipa-replica-install --setup-ca -N replica-info-ipan.lab.whamcloud.com.gpg --skip-conncheck Same error message. I'm lost. Help? This is unrelated to passing in the CA certificate. We'd

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Joshua J. Kugler
On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: We'd need to see /var/log/ipareplica-install.log to see what the LDAP error is. If you look on the remote master DS access log it may have additional information on what was requested. Logs attached. 10.10.0.50 is the new replica. No

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Rich Megginson
On 06/21/2013 02:39 PM, Joshua J. Kugler wrote: On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: We'd need to see /var/log/ipareplica-install.log to see what the LDAP error is. If you look on the remote master DS access log it may have additional information on what was requested. Logs

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Joshua J. Kugler
On Friday, June 21, 2013 14:46:50 Rich Megginson wrote: On 06/21/2013 02:39 PM, Joshua J. Kugler wrote: On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: We'd need to see /var/log/ipareplica-install.log to see what the LDAP error is. If you look on the remote master DS access log it

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Rich Megginson
On 06/21/2013 02:50 PM, Joshua J. Kugler wrote: On Friday, June 21, 2013 14:46:50 Rich Megginson wrote: On 06/21/2013 02:39 PM, Joshua J. Kugler wrote: On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: We'd need to see /var/log/ipareplica-install.log to see what the LDAP error is. If

Re: [Freeipa-users] Upgrade/Migration steps

2013-06-21 Thread Rob Crittenden
Joshua J. Kugler wrote: On Friday, June 21, 2013 14:46:50 Rich Megginson wrote: On 06/21/2013 02:39 PM, Joshua J. Kugler wrote: On Friday, June 21, 2013 09:26:36 Rob Crittenden wrote: We'd need to see /var/log/ipareplica-install.log to see what the LDAP error is. If you look on the remote