Re: [Freeipa-users] best practices for subdomains

2014-03-03 Thread Petr Spacek
On 1.3.2014 23:20, Brendan Kearney wrote: i am using bind-dyndb-ldap outside of freeipa, and want to create _tcp.my-domain.com and _udp.my-domain.com subdomains. i have tried, but seem to come up short and nslookup fails for the records i try to create in the subdomains. some googling and

[Freeipa-users] Cert auto-renew probem.

2014-03-03 Thread Lager, Nathan T.
Today i found that i was unable to authenticate to FreeIPA. I logged into my IPA master, and found that the cert had expired. Which has never been a problem in the past. I did some googling, and found a few others with similar problems. but none quite matched the issue i'm seeing. The

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-03-03 Thread Steve Dainard
Hi Jakub, id info from earlier response: Very interesting, my IPA group membership in ad_admins isn't shown by that command on first run (new login) sdainard-ad...@miovision.corp@__ubu1310:~$ id sdainard-admin

[Freeipa-users] F19 - F20 yum upgrade success report (WAS: Re: WARNING: Do not upgrade FreeIPA deployments to Fedora 20 final (yet))

2014-03-03 Thread Anthony Messina
On Saturday, March 01, 2014 04:18:11 AM Anthony Messina wrote: I've been waiting patiently for F20 to settle before upgrading my two VM installations of FreeIPA: ipa1 (original master) ipa2 (clone) I'm considering doing a yum upgrade this weekend and was wondering if any users had

Re: [Freeipa-users] best practices for subdomains

2014-03-03 Thread Brendan Kearney
On Mon, 2014-03-03 at 09:33 +0100, Petr Spacek wrote: On 1.3.2014 23:20, Brendan Kearney wrote: i am using bind-dyndb-ldap outside of freeipa, and want to create _tcp.my-domain.com and _udp.my-domain.com subdomains. i have tried, but seem to come up short and nslookup fails for the records

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-03-03 Thread Steve Dainard
Sumit, Unfortunately 1.11.1 is the only version available for Ubuntu 13.10. I've also had the same problem with an updated version of Fedora 20, so I don't think its specific to this package version. *Steve Dainard * IT Infrastructure Manager Miovision http://miovision.com/ | *Rethink Traffic*

Re: [Freeipa-users] Cert auto-renew probem.

2014-03-03 Thread Dmitri Pal
On 03/03/2014 08:50 AM, Lager, Nathan T. wrote: Today i found that i was unable to authenticate to FreeIPA. I logged into my IPA master, and found that the cert had expired. Which has never been a problem in the past. I did some googling, and found a few others with similar problems. but

[Freeipa-users] Using external KDC

2014-03-03 Thread Trey Dockendorf
Is it possible with FreeIPA to use an external KDC or pass some or all authentication to an external KDC? The KDC at our University may give me a one way trust if I describe my implementation plan for FreeIPA. Currently I use 389DS with PAM pass through using untrusted pam_krb5. I'd like to fully

Re: [Freeipa-users] Using external KDC

2014-03-03 Thread Simo Sorce
On Mon, 2014-03-03 at 18:42 -0600, Trey Dockendorf wrote: Is it possible with FreeIPA to use an external KDC or pass some or all authentication to an external KDC? The KDC at our University may give me a one way trust if I describe my implementation plan for FreeIPA. Currently I use 389DS

Re: [Freeipa-users] Using external KDC

2014-03-03 Thread Dmitri Pal
On 03/03/2014 07:47 PM, Simo Sorce wrote: On Mon, 2014-03-03 at 18:42 -0600, Trey Dockendorf wrote: Is it possible with FreeIPA to use an external KDC or pass some or all authentication to an external KDC? The KDC at our University may give me a one way trust if I describe my implementation