Re: [Freeipa-users] Slow user logon with IPA

2015-04-15 Thread Lukas Slebodnik
On (15/04/15 08:53), Jakub Hrozek wrote: On Tue, Apr 14, 2015 at 05:36:16PM +0200, Mateusz Malek wrote: On Fri, Apr 10, 2015 at 08:48 PM, Jakub Hrozek wrote: On Fri, Apr 10, 2015 at 12:39:20PM -0400, Dmitri Pal wrote: On 04/10/2015 08:13 AM, Mateusz Malek wrote: I'm about to migrate my

Re: [Freeipa-users] ipa-getcert Problem ?

2015-04-15 Thread Nalin Dahyabhai
On Wed, Apr 15, 2015 at 08:47:12AM +0200, Günther J. Niederwimmer wrote: Thank you for the answer and help I mean this is working now ;) after some --uninstall and delete the certificate (?) . The wrong command I found with google :-(. The status command is not working on my system!

Re: [Freeipa-users] multihome - single interface?

2015-04-15 Thread Petr Spacek
On 15.4.2015 09:59, Janne Blomqvist wrote: On 2015-04-14 10:17, Petr Spacek wrote: On 13.4.2015 16:07, Janne Blomqvist wrote: On 2015-04-10 12:05, Petr Spacek wrote: On 10.4.2015 10:52, Janne Blomqvist wrote: On 2015-04-07 14:29, Martin Kosek wrote: On 04/05/2015 08:03 PM, Dmitri Pal wrote:

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread Rich Megginson
On 04/15/2015 09:46 AM, James James wrote: Hello, I have been looking to solve my problem but I 'm asking for some help. The replication begins but cannot be completed I want to install a new fresh replica but I've always got this error : [21/35]: configure dirsrv ccache [22/35]:

Re: [Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Lukas Slebodnik
On (15/04/15 13:43), Aric Wilisch wrote: Today I managed to finally get a trust established between my AD Domain and my FreeIPA 4 environment. However I’m noticing a couple issues and hope someone might be able to give me some help. First when the user logs in it creates their home directory

Re: [Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Alexander Bokovoy
On Wed, 15 Apr 2015, Aric Wilisch wrote: Today I managed to finally get a trust established between my AD Domain and my FreeIPA 4 environment. However I’m noticing a couple issues and hope someone might be able to give me some help. First when the user logs in it creates their home directory

Re: [Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Aric Wilisch
So I would have to setup an ID View Override for every user in AD that needs to login to to a FreeIPA host? I guess I’m having trouble understanding why it wouldn’t just use the defaults set into FreeIPA? The Default home directory is set to /home and the default shell is set to /bin/bash.

[Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Aric Wilisch
Today I managed to finally get a trust established between my AD Domain and my FreeIPA 4 environment. However I’m noticing a couple issues and hope someone might be able to give me some help. First when the user logs in it creates their home directory in /home/fioptics/username rather than

[Freeipa-users] indirect automount offsets

2015-04-15 Thread Rob Verduijn
Hello, I'm trying to figure out how to use automounts in freeipa with offsets. currently I have this: the default location containing 3 maps auto.direct auto.home auto.master auto.direct is empty auto.home contains: key : * mount information : -rw nfs.example.com:/homes/ auto.master contains

Re: [Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Simo Sorce
On Wed, 2015-04-15 at 14:19 -0400, Aric Wilisch wrote: So I would have to setup an ID View Override for every user in AD that needs to login to to a FreeIPA host? If you just need a different default shell you should set the default_shell option in sssd.conf I guess I’m having trouble

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread Rich Megginson
On 04/15/2015 12:43 PM, James James wrote: Here the log 2015-04-15 18:58 GMT+02:00 Rich Megginson rmegg...@redhat.com mailto:rmegg...@redhat.com: On 04/15/2015 09:46 AM, James James wrote: Hello, I have been looking to solve my problem but I 'm asking for some help.

Re: [Freeipa-users] Freeipa4 - AD SSH logins

2015-04-15 Thread Alexander Bokovoy
On Wed, 15 Apr 2015, Aric Wilisch wrote: So I would have to setup an ID View Override for every user in AD that needs to login to to a FreeIPA host? I guess I’m having trouble understanding why it wouldn’t just use the defaults set into FreeIPA? The Default home directory is set to /home and

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread Rich Megginson
On 04/15/2015 02:58 PM, James James wrote: Nothing on the replica .. maybye a process on the master. How can I check that ? I have no idea. But it seems highly unlikely that a process on the master is able to shutdown a process on the replica . . . I would say that there is some problem

Re: [Freeipa-users] ipa: ERROR: AD DC was unable to reach any IPA domain controller --- AD domain controller complains about communication sequence.

2015-04-15 Thread g . fer . ordas
Hi Alexander I do trust the diagnostics and I thank you so much for that explanation as I know now now a bit better what to expect or for the less what is the sequence it follows. This does not seem to be a port issue (below windows): PORT STATE SERVICE 53/tcpopen domain 80/tcp

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread James James
The ipareplica-install.log file in attachment ... 2015-04-16 2:22 GMT+02:00 Rob Crittenden rcrit...@redhat.com: Rich Megginson wrote: On 04/15/2015 02:58 PM, James James wrote: Nothing on the replica .. maybye a process on the master. How can I check that ? I have no idea. But it

Re: [Freeipa-users] ipa: ERROR: AD DC was unable to reach any IPA domain controller --- AD domain controller complains about communication sequence.

2015-04-15 Thread Alexander Bokovoy
On Wed, 15 Apr 2015, g.fer.or...@unicyber.co.uk wrote: Hi Alexander I do trust the diagnostics and I thank you so much for that explanation as I know now now a bit better what to expect or for the less what is the sequence it follows. This does not seem to be a port issue (below windows):

Re: [Freeipa-users] indirect automount offsets

2015-04-15 Thread Rob Crittenden
Rob Verduijn wrote: Hello, I'm trying to figure out how to use automounts in freeipa with offsets. currently I have this: the default location containing 3 maps auto.direct auto.home auto.master auto.direct is empty auto.home contains: key : * mount information : -rw

Re: [Freeipa-users] CRON: Authentication service cannot retrieve authentication info

2015-04-15 Thread Dmitri Pal
On 04/15/2015 10:17 PM, Thomas Lau wrote: Hi, I just checked with developer, there is no authentication related code in the program, we could treat it as normal cron job. is that possible to make sssd less contact with FreeIPA? for example, refresh all user info every 5 minutes, else use cache

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread Rob Crittenden
Rich Megginson wrote: On 04/15/2015 02:58 PM, James James wrote: Nothing on the replica .. maybye a process on the master. How can I check that ? I have no idea. But it seems highly unlikely that a process on the master is able to shutdown a process on the replica . . . I would say that

Re: [Freeipa-users] Replication seems to begin but failed after 127 seconds ...

2015-04-15 Thread James James
Nothing on the replica .. maybye a process on the master. How can I check that ? 2015-04-15 21:37 GMT+02:00 Rich Megginson rmegg...@redhat.com: On 04/15/2015 12:43 PM, James James wrote: Here the log 2015-04-15 18:58 GMT+02:00 Rich Megginson rmegg...@redhat.com: On 04/15/2015 09:46 AM,

Re: [Freeipa-users] ipa-getcert Problem ?

2015-04-15 Thread Günther J . Niederwimmer
Hello, Am Dienstag, 14. April 2015, 14:29:58 schrieb Nalin Dahyabhai: On Tue, Apr 14, 2015 at 08:18:38PM +0200, Günther J. Niederwimmer wrote: Hello I mean I have a Problem with the ipa-getcert script. system CentOS 7 (1503) and IPA 4.1.x can any help or declare my mistake or is

Re: [Freeipa-users] Slow user logon with IPA

2015-04-15 Thread Jakub Hrozek
On Tue, Apr 14, 2015 at 05:36:16PM +0200, Mateusz Malek wrote: On Fri, Apr 10, 2015 at 08:48 PM, Jakub Hrozek wrote: On Fri, Apr 10, 2015 at 12:39:20PM -0400, Dmitri Pal wrote: On 04/10/2015 08:13 AM, Mateusz Malek wrote: I'm about to migrate my OpenLDAP-based environment to FreeIPA,

Re: [Freeipa-users] multihome - single interface?

2015-04-15 Thread Janne Blomqvist
On 2015-04-14 10:17, Petr Spacek wrote: On 13.4.2015 16:07, Janne Blomqvist wrote: On 2015-04-10 12:05, Petr Spacek wrote: On 10.4.2015 10:52, Janne Blomqvist wrote: On 2015-04-07 14:29, Martin Kosek wrote: On 04/05/2015 08:03 PM, Dmitri Pal wrote: On 04/05/2015 12:51 PM, Janelle wrote:

Re: [Freeipa-users] ipa-replica-prepare failing

2015-04-15 Thread David Dejaeghere
Hi Honza, That gave me the exact same output. Any ideas? Regards, D 2015-04-15 7:33 GMT+02:00 Jan Cholasta jchol...@redhat.com: Hi, Dne 14.4.2015 v 19:47 Rob Crittenden napsal(a): David Dejaeghere wrote: Hi Rob, So you want to output of the command using pk12 with server cert and

Re: [Freeipa-users] EXTERNAL: Re: Can't delete group because it states it's not found

2015-04-15 Thread Joseph, Matthew (EXP)
I was able to get the group modified and deleted with your commands Rob. Thank you very much for the help. Matt -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: Tuesday, April 14, 2015 3:16 PM To: Joseph, Matthew (EXP); freeipa-users@redhat.com Subject: Re: