Re: [Freeipa-users] IPA web ui always giving Your session has expired. Please re-login.

2015-03-09 Thread Ben .T.George
HI thanks sure this is the only place i can ask questions :) but i don't know from where i am getting that basic authentication window like .htaccess based. i think when i tried from chome only i got this window On Mon, Mar 9, 2015 at 2:21 PM, Martin Kosek mko...@redhat.com wrote: Ok,

Re: [Freeipa-users] IPA web ui always giving Your session has expired. Please re-login.

2015-03-09 Thread Martin Kosek
Ok, thanks for information. I would still love to know the real root cause, but we will now find it now I assume. Of this issue re-appears, let us know :-) Thanks, Martin On 03/09/2015 09:10 AM, Ben .T.George wrote: Hi Martin, thanks for your replay. yesterday i did lot of this to fix

[Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Traiano Welcome
Hi List I have AD trusts configured and working between an IPA server and a master primary domain controller (dc-1) in a forest in one data center. This allows me to connect with SSH to linux servers in the same data-center, authenticating with my AD credentials. I'm trying to test a scenario

[Freeipa-users] Errors while adding DNS Zone

2015-03-09 Thread Matt Wells
I'm getting some errors on a DNS Zone that I'm attempting to create. My systems reside within a sub-domain of example.com. (xyz.example.com) Of course example.com is the internet address, but I want to host the internal example.com so we're able to point to internal intranets and so on. So to the

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Alexander Bokovoy
On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a master primary domain controller (dc-1) in a forest in one data center. This allows me to connect with SSH to linux servers in the same data-center, authenticating with my AD

Re: [Freeipa-users] Error establishing trust with AD domain

2015-03-09 Thread Baird, Josh
Ok - I'll answer my own question. I needed to establish the trust with the forest-root domain (domain.com), not the child domain. I have verified using 'ipa trustdomain-find' that I can see the child domain (ad.domain.com) now. Sorry for the noise! Thanks, Josh From:

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Dmitri Pal
On 03/09/2015 02:29 PM, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a master

[Freeipa-users] Error establishing trust with AD domain

2015-03-09 Thread Baird, Josh
Hi, I have successfully established a trust in my lab environment running IPA 4.1 (RHEL7.1) and a Windows 2008 R2 domain with Windows 2003 domain/forest functional levels. I'm now trying to establish a trust with my production AD domain (same functional level). The only difference is that

Re: [Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Rich Megginson
On 03/09/2015 03:35 PM, Steven Jones wrote: Any idea what is going on here please? == [root@vuwunicoipam004 mailto:root@vuwunicoipam004 ipa-certs]# ipa-replica-install --setup-dns --forwarder=10.100.32.31 -U replica-info-vuwunicoipam004.ods.vuw.ac.nz.gpg --skip-conncheck

[Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Steven Jones
Any idea what is going on here please? == [root@vuwunicoipam004mailto:root@vuwunicoipam004 ipa-certs]# ipa-replica-install --setup-dns --forwarder=10.100.32.31 -U replica-info-vuwunicoipam004.ods.vuw.ac.nz.gpg --skip-conncheck Checking forwarders, please wait ... WARNING: DNS

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Alexander Bokovoy
On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I have AD trusts configured and working between an IPA server and a master

Re: [Freeipa-users] Trying to migrate, can't set hashed passwords

2015-03-09 Thread Alexander Bokovoy
On Mon, 09 Mar 2015, Ben Slusky wrote: Greetings FreeIPA users, I'm setting up FreeIPA service in our production environment to replace several different authentication methods for various systems. I'm trying to migrate the first wave of users now My plan was to copy their passwords from an old

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Jakub Hrozek
On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: On 03/09/2015 02:29 PM, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015, Traiano Welcome wrote: Hi List I

Re: [Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Dmitri Pal
On 03/09/2015 05:35 PM, Steven Jones wrote: Any idea what is going on here please? == [root@vuwunicoipam004 mailto:root@vuwunicoipam004 ipa-certs]# ipa-replica-install --setup-dns --forwarder=10.100.32.31 -U replica-info-vuwunicoipam004.ods.vuw.ac.nz.gpg --skip-conncheck Why

Re: [Freeipa-users] Adding FreeIPA as a vsphere identity source

2015-03-09 Thread reesb
I've update the ACI's but am still getting the same error as before. I am guessing this is probably related to the same issue in the other concurrent vsphere 5.5 email thread that is going. I'll just keep my eye on that to see the resolution. On 3/6/2015 at 3:45 PM, Martin Kosek

Re: [Freeipa-users] Filter/Block/Limit Interaction with Multiple Domain Controllers

2015-03-09 Thread Dmitri Pal
On 03/09/2015 03:40 PM, Jakub Hrozek wrote: On Mon, Mar 09, 2015 at 02:58:14PM -0400, Dmitri Pal wrote: On 03/09/2015 02:29 PM, Traiano Welcome wrote: Hi Alexander Thanks for the response: On Mon, Mar 9, 2015 at 8:04 PM, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 09 Mar 2015,

Re: [Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Steven Jones
It usually fails, hence I skip it. Since I have no firewall either side and I know I have a simple network since I built there is nothing possible blocking in-between. I will double check the DNS zone file. I had to rename the server to ipam004 as the replica attempt sulked if i re-used an

Re: [Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Steven Jones
== 2015-03-09T21:15:31Z DEBUG flushing ldap://vuwunicoipam002.ods.vuw.ac.nz:389 from SchemaCache 2015-03-09T21:15:31Z DEBUG retrieving schema for SchemaCache url=ldap://vuwunicoipam002.ods.vuw.ac.nz:389 conn=ldap.ldapobject.SimpleLDAPObject instance at 0x4226cb0 2015-03-09T21:15:31Z DEBUG

Re: [Freeipa-users] Error in replication while inserting a RHEL7.1 server into a RHEL6.6 IPA setup.

2015-03-09 Thread Steven Jones
= Check connection from replica to remote master 'vuwunicoipam002.ods.vuw.ac.nz': Directory Service: Unsecure port (389): OK Directory Service: Secure port (636): OK Kerberos KDC: TCP (88): OK Kerberos Kpasswd: TCP (464): OK HTTP Server: Unsecure port (80): OK HTTP

Re: [Freeipa-users] IPA web ui always giving Your session has expired. Please re-login.

2015-03-09 Thread Martin Kosek
Thanks for all the data. So it looks like your browser properly forward the session cookie, but it is not recognized on the server even though it was stored before. Especially these lines are strange: [Sun Mar 08 13:16:29.909637 2015] [:error] [pid 3004] ipa: DEBUG: store session:

Re: [Freeipa-users] IPA web ui always giving Your session has expired. Please re-login.

2015-03-09 Thread Ben .T.George
Hi Martin, thanks for your replay. yesterday i did lot of this to fix this issue. the issue has been solved by kdestroy and re-initiate the ticket. after that restarted ipa service, it got worked Regards, ben On Mon, Mar 9, 2015 at 10:57 AM, Martin Kosek mko...@redhat.com wrote: Thanks