Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Sumit Bose
On Mon, Mar 31, 2014 at 11:05:18PM +, Todd Maugh wrote: [root@black-62 sssd]# tail -f sssd_ops.boingo.com.log (Mon Mar 31 22:58:01 2014) [sssd[be[ops.boingo.com]]] [be_resolve_server_done] (4): Found address for server idm-master-els.ops.boingo.com: [172.22.170.46] TTL 7200 (Mon Mar

[Freeipa-users] IPA Replica Issues (Total update abortedLDAP error: Can't contact LDAP server)

2014-04-01 Thread Nevada Sanchez
I've had a replica working with FreeIPA 3.2.1 for awhile. After upgrading to 3.3.4, the replica wouldn't recognize my admin login anymore. After much troubleshooting, I decided to try to redo the replica since it was quite straightforward when I first set it up (what could go wrong, right?)

Re: [Freeipa-users] Issue on import official cert of godaddy.

2014-04-01 Thread Rob Crittenden
barry...@gmail.com wrote: I found the cause and remove the error. ...i used the bundle cert to make the p12 file by official guide ...bnudle cert can use only even i download another root ca cert of godday it fail says somelike local chain error,

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Todd Maugh
I set my debug level to 5 and these were the messages I got. I checked the sshd_config and it seems to be using gsapi what lines should be uncommented or entered or set to true or yes for Pam. I tried the one pam line I saw to true. But it made no difference -Original Message- From:

[Freeipa-users] using keytabs for auth to ldap

2014-04-01 Thread Brendan Kearney
What distribution you use? Fedora Which distribution version you use? Fedora 20, with latest updates Which architecture you use? x86_64 on a qemu VM What plugin version you use? bind-dyndb-ldap-4.1-1.fc20.x86_64 Do you use bind-dyndb-ldap as part of ​FreeIPA installation? no, using

Re: [Freeipa-users] IPA Replica Issues (Total update abortedLDAP error: Can't contact LDAP server)

2014-04-01 Thread Rich Megginson
On 04/01/2014 03:46 AM, Nevada Sanchez wrote: I've had a replica working with FreeIPA 3.2.1 for awhile. After upgrading to 3.3.4, the replica wouldn't recognize my admin login anymore. After much troubleshooting, I decided to try to redo the replica since it was quite straightforward when I

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Todd Maugh
I am seeing this error in /var/log/secure [r...@black-64.qa ~]# tail /var/log/secure Apr 1 17:54:05 black-64 sshd[3649]: pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.194.1.250 user=tmaugh Apr 1 17:54:05 black-64 sshd[3649]: pam_sss(sshd:auth):

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Todd Maugh
here is my sssd.conf [r...@black-64.qa ~]# cat /etc/sssd/sssd.conf [sssd] config_file_version = 2 services = nss, pam # SSSD will not start if you do not configure any domains. # Add new domain configurations as [domain/NAME] sections, and # then add the list of domains (in the order you want

Re: [Freeipa-users] bind-dyndb-ldap: using keytabs for auth to ldap

2014-04-01 Thread Petr Spacek
Hello! On 1.4.2014 16:17, Brendan Kearney wrote: What plugin version you use? bind-dyndb-ldap-4.1-1.fc20.x86_64 Before I dive into details, please read about the following bug: https://fedorahosted.org/bind-dyndb-ldap/ticket/134 I just found it, fixed it and I'm attaching patch for you so you

Re: [Freeipa-users] bind-dyndb-ldap: using keytabs for auth to ldap

2014-04-01 Thread Brendan Kearney
Hello! Before I dive into details, please read about the following bug: https://fedorahosted.org/bind-dyndb-ldap/ticket/134 I just found it, fixed it and I'm attaching patch for you so you don't need to wait for a new release :-) thanks, but i am not sure how to apply patches. Your

Re: [Freeipa-users] bind-dyndb-ldap: using keytabs for auth to ldap

2014-04-01 Thread Rich Megginson
On 04/01/2014 01:34 PM, Brendan Kearney wrote: Hello! Before I dive into details, please read about the following bug: https://fedorahosted.org/bind-dyndb-ldap/ticket/134 I just found it, fixed it and I'm attaching patch for you so you don't need to wait for a new release :-) thanks, but i am

Re: [Freeipa-users] bind-dyndb-ldap: using keytabs for auth to ldap

2014-04-01 Thread Brendan Kearney
No, it is not. http://port389.org/wiki/History ok then. still, i am trying to learn the individual pieces and get them working together. ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Jakub Hrozek
On Tue, Apr 01, 2014 at 05:58:00PM +, Todd Maugh wrote: I am seeing this error in /var/log/secure [r...@black-64.qa ~]# tail /var/log/secure Apr 1 17:54:05 black-64 sshd[3649]: pam_sss(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=10.194.1.250

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Todd Maugh
/var/log/sssd/krb5_child.log is empty here is the sssd domain logsssd_ops.boingo.com.log 97][1][name=tmp.UiK3X6] (Tue Apr 1 19:28:01 2014) [sssd[be[ops.boingo.com]]] [acctinfo_callback] (4): Request processed. Returned 0,0,Success (Tue Apr 1 19:29:01 2014) [sssd[be[ops.boingo.com]]]

Re: [Freeipa-users] IPA Replica Issues (Total update abortedLDAP error: Can't contact LDAP server)

2014-04-01 Thread Rob Crittenden
Rich Megginson wrote: On 04/01/2014 03:28 PM, Nevada Sanchez wrote: Okay, I just tried doing this on a FRESH fedora 19 image (applied all updates, installed freeipa, made a new replica file for the new test server, and went state to ipa-replica-insntall). Exact same errors. Anything else I

Re: [Freeipa-users] uninstalled IPA client and reinstalled and enrolled to new server cant authenticate

2014-04-01 Thread Todd Maugh
Ok so On 2 of the servers I found that UsePAM was not even in the sshd_conf when I put that in I was fine but 3 other servers that have it in the sshd_conf are exhibiting the password not accepted error then I went and cleared the sssd cache and IM back in business thank you for the help

[Freeipa-users] force uninstall from Ubunutu 12.04

2014-04-01 Thread Todd Maugh
Has any one been able to successfully uninstall a client from Ubuntu 12.04 I have the install down for these boxes. But I need to transfer an ubunutu client from our old ipa server to the new The error I get during uninstall is Failed to remove krb5/LDAP Configuration Even if I remove the