Re: [Freeipa-users] Server Ports

2014-04-03 Thread Petr Spacek
On 3.4.2014 07:55, Justin Brown wrote: I'm having some trouble determining which ports my servers need open to communicate and what ports client servers and users will need. The last documentation that I was able to find was included in Fedora 15

Re: [Freeipa-users] Server Ports

2014-04-03 Thread Justin Brown
Petr, I'll try another replica for testing tomorrow, and unfortunately the logs were purged when I reinstalled. The error message was not helpful and said something along the lines of CA installation failed, but did not list any reason. I'll get you the exact message tomorrow. I'll also try some

Re: [Freeipa-users] Server Ports

2014-04-03 Thread Martin Kosek
On 04/03/2014 09:46 AM, Justin Brown wrote: Petr, I'll try another replica for testing tomorrow, and unfortunately the logs were purged when I reinstalled. The error message was not helpful and said something along the lines of CA installation failed, but did not list any reason. I'll get

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-03 Thread Redmond, Stacy
Yes, I did that, here is the log [Thu Apr 03 13:21:52 2014] [error] [client 10.130.82.68] Credentials for HTTP/linuxtest1.sbx.local@UNIX have expired or will soon expire - now 1396556512 endtime 1396551629, referer: https://linuxtest1.sbx.local/ipa/xml [Thu Apr 03 13:21:52 2014] [error] [client

Re: [Freeipa-users] DDNS with DHCPD and IPA

2014-04-03 Thread William Brown
On Thu, 2014-04-03 at 11:02 -0700, Andy Tomlin wrote: That would be my preference, would then work same as bind/dhcpd before switching to ipa. I just dont know how to do it correctly. This assumes dhcp and named are on the same system. For an unrelated project I wrote some docs here:

Re: [Freeipa-users] IPA Replica Issues (Total update abortedLDAP error: Can't contact LDAP server)

2014-04-03 Thread Rich Megginson
On 04/03/2014 03:46 PM, Nevada Sanchez wrote: Okay, I updated the gist and extended some of the logs (ipa2-errors does stop at 20:50:21). I'll follow up when I have the debug stuff in place. https://gist.github.com/nevsan/8b6f78d7396963dc5f70 Another strange thing - it looks as if the

Re: [Freeipa-users] DDNS with DHCPD and IPA

2014-04-03 Thread Andy Tomlin
Awesome, adding the grant line with my key (DDNS_UPDATE) did the trick. This makes it perform exactly like old config. Thanks for the help. Someone should put this example in the docs. -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On

Re: [Freeipa-users] IPA Replica Issues (Total update abortedLDAP error: Can't contact LDAP server)

2014-04-03 Thread Nevada Sanchez
Okay, I updated the gist and extended some of the logs (ipa2-errors does stop at 20:50:21). I'll follow up when I have the debug stuff in place. https://gist.github.com/nevsan/8b6f78d7396963dc5f70 On Thu, Apr 3, 2014 at 10:38 AM, Rich Megginson rmegg...@redhat.com wrote: On 04/02/2014 09:22

Re: [Freeipa-users] Unable to establish trust with FreeIPA and Active Directory

2014-04-03 Thread Alexander Bokovoy
On Thu, 03 Apr 2014, Redmond, Stacy wrote: Yes, I did that, here is the log [Thu Apr 03 13:21:52 2014] [error] [client 10.130.82.68] Credentials for HTTP/linuxtest1.sbx.local@UNIX have expired or will soon expire - now 1396556512 endtime 1396551629, referer: https://linuxtest1.sbx.local/ipa/xml