[Freeipa-users] goddday wild card cert error

2014-06-04 Thread barrykfl
Dear all: my host is abc.def.com I import a cert *.def.com of godaddy to dirsrv and warning / error prompt any idea? is it i cannot use *.def cert and must use a full host cert . abc.def.com??? Shutting down dirsrv: PKI-IPA... [ OK ]

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Johan Petersson
Yes Client is default RHEL 7 and both IPA and NFS Server is aswell. server.ad.home = AD Server share.linux.home = NFS Server ipa.linux.home = IPA Server client.linux.home = Client NFS with automounted krb5p Home Directories work for IPA users. sssd-1.11.2-65.el7.x86_64 id adt...@ad.home

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Johan Petersson
I found one clue to the issue and as i thought it has to do with m From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Johan Petersson Sent: Wednesday, June 04, 2014 12:02 PM To: d...@redhat.com; freeipa-users@redhat.com Subject: Re: [Freeipa-users]

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Johan Petersson
Mail got posted before I was finished sorry. I found one clue to the issue after increasing autofs logging to debug and as i thought it has to do with id-mapping. From /var/log/messages: Nfsidmap[1696]: nss_getpwnam: name 'adt...@ad.home@linux.home,' does not map into domain 'linux.home,'

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Sumit Bose
On Wed, Jun 04, 2014 at 12:24:11PM +, Johan Petersson wrote: Mail got posted before I was finished sorry. I found one clue to the issue after increasing autofs logging to debug and as i thought it has to do with id-mapping. From /var/log/messages: Nfsidmap[1696]: nss_getpwnam: name

Re: [Freeipa-users] goddday wild card cert error

2014-06-04 Thread Rob Crittenden
barry...@gmail.com wrote: Dear all: my host is abc.def.com http://abc.def.com I import a cert *.def.com http://def.com of godaddy to dirsrv and warning / error prompt any idea? is it i cannot use *.def cert and must use a full host cert . abc.def.com? http://abc.def.com??? Shutting

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Alexander Bokovoy
On Wed, 04 Jun 2014, Johan Petersson wrote: Mail got posted before I was finished sorry. I found one clue to the issue after increasing autofs logging to debug and as i thought it has to do with id-mapping. From /var/log/messages: Nfsidmap[1696]: nss_getpwnam: name

Re: [Freeipa-users] Getting Samba3 and FreeIPAv3 working together

2014-06-04 Thread Sumit Bose
On Tue, Jun 03, 2014 at 03:37:05PM +0100, Dylan Evans wrote: Hello again, Just realised by re-reading this thread that I still needed to create the DNA plugin. I've now done that and I can add users, sorry for being stupid... I think the issue is on my side :-) I forgot that samba uses a

Re: [Freeipa-users] IPA+AD trust and NFS nobody issue

2014-06-04 Thread Johan Petersson
Yes the message is exactly like that with commas, I double checked. To anser Sumit's question: Maybe adding 'linux.home' and 'ad.home' to Local-Realms in idmap.conf might help? I did on all machines and got rid of that specific message but I still get user nobody unfortunately. Here are logs

[Freeipa-users] FreeIPA Clients and Firewall rules

2014-06-04 Thread Mark Gardner
Does all communication used for the FreeIPA client go between the FreeIPA client and the FreeIPA server? Or if we're using FreeIPA / AD Trusts, does some communication go to the AD Server? ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] FreeIPA Clients and Firewall rules

2014-06-04 Thread Alexander Bokovoy
On Wed, 04 Jun 2014, Mark Gardner wrote: Does all communication used for the FreeIPA client go between the FreeIPA client and the FreeIPA server? Or if we're using FreeIPA / AD Trusts, does some communication go to the AD Server? Yes, an authentication exchange for AD users may happen between