Re: [Freeipa-users] Fw: Web ui error “Your session has expired. Please re-login.” from a browser on a remote client.

2015-04-28 Thread Christopher Lamb
Hi Martin That is great. However you may wish to qualify what significant is. In the case of the original clock-skew problems (between the IPA LDAP Server and sssd clients on other servers), a skew in the order of 5 minutes was enough to prevent us sshing into our servers with an ldap user. You

Re: [Freeipa-users] How to renew an expired admin certificate

2015-04-28 Thread Niranjan M.R
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/28/2015 11:20 AM, Kamal Perera wrote: Dear All, I'm in the process of regaining one of the old CA systems which was not being used for a long time. In the root CA, administrator certificate is expired and cannot access the agent

Re: [Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Dmitri Pal
On 04/28/2015 07:35 AM, Alexander Frolushkin wrote: Hello. We were also planned relatively large deployment (8 sites, 19 IPA servers), and for now our experience told us that Red Hat official support is a must-have option for IPA in mission-critical environment. IPA is still a very fresh

Re: [Freeipa-users] How to renew an expired admin certificate

2015-04-28 Thread Dmitri Pal
On 04/28/2015 02:56 AM, Niranjan M.R wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 04/28/2015 11:20 AM, Kamal Perera wrote: Dear All, I'm in the process of regaining one of the old CA systems which was not being used for a long time. In the root CA, administrator certificate is

Re: [Freeipa-users] 4.1.4 and OTP

2015-04-28 Thread Nathaniel McCallum
On Fri, 2015-04-17 at 20:21 -0700, Janelle wrote: On 4/17/15 5:59 PM, Dmitri Pal wrote: On 04/17/2015 08:07 PM, Janelle wrote: On Apr 17, 2015, at 16:36, Dmitri Pal d...@redhat.com wrote: On 04/17/2015 04:52 PM, Janelle wrote: On 4/17/15 1:19 PM, Dmitri Pal

Re: [Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Alexander Frolushkin
Hello. We were also planned relatively large deployment (8 sites, 19 IPA servers), and for now our experience told us that Red Hat official support is a must-have option for IPA in mission-critical environment. IPA is still a very fresh solution and it have some issues you may face. WBR,

Re: [Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Арсений Черняков
Thank you for quick response. So, did I got it right, that this limitation is affecting only RedHat support agreement, and not the technical side of configuration? We're considering the CentOS 7 deployment, and we don't have Red Hat support agreement. Maybe it's a stupid question, but since we

Re: [Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Alexander Bokovoy
On Tue, 28 Apr 2015, Арсений Черняков wrote: Thank you for quick response. So, did I got it right, that this limitation is affecting only RedHat support agreement, and not the technical side of configuration? We're considering the CentOS 7 deployment, and we don't have Red Hat support agreement.

Re: [Freeipa-users] Fw: Web ui error “Your session has expired. Please re-login.” from a browser on a remote client.

2015-04-28 Thread Martin Kosek
On 04/27/2015 06:09 PM, Christopher Lamb wrote: Hi All I may have found a possible cause of our instance of the Your session has expired Web UI error on our new FreeIPA 4.1.0 Server By chance I checked the date on the server hosting FreeIPA 4.1.0. To my surprise, despite running ntpd

Re: [Freeipa-users] 4.1.4 and OTP

2015-04-28 Thread Janelle
On 4/28/15 6:44 AM, Nathaniel McCallum wrote: On Fri, 2015-04-17 at 20:21 -0700, Janelle wrote: On 4/17/15 5:59 PM, Dmitri Pal wrote: On 04/17/2015 08:07 PM, Janelle wrote: On Apr 17, 2015, at 16:36, Dmitri Pal d...@redhat.com wrote: On 04/17/2015 04:52 PM, Janelle wrote: On 4/17/15

[Freeipa-users] FreeIPA and sambaPwdLastSet

2015-04-28 Thread Christopher Lamb
Hi All I wish to pick your brains on the attribute sambaPwdLastSet We have a newly setup FreeIPA 4.1.0, with users and groups migrated from an old 3.0.0 instance. We are also running Samba to share files to Windows and OSX users. This means that all the FreeIPA user accounts have the attribute

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-28 Thread Roderick Johnstone
Siggi Thanks for the reminder. I did see these a while ago - I've seen so much in so many places and became rapidly confused, because I don't have much ldap or ipa experience. I'll review your instructions and see how they fit with the Solaris 11 instructions from the mailing list that I

Re: [Freeipa-users] FreeIPA WebUI Logout logs back in

2015-04-28 Thread Christopher Lamb
HI All I have just tested with the FreeIPA Web UI public demo https://ipa.demo1.freeipa.org/ipa/ui/ Using the public demo, when I log out, I get returned to the login screen, as expected. This allows me to log in with a different user. With our own installation FreeIPA, from exactly the same

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-28 Thread Rob Crittenden
Roderick Johnstone wrote: On 28/04/2015 19:23, Dmitri Pal wrote: On 04/28/2015 02:12 PM, Roderick Johnstone wrote: On 23/04/15 14:14, Rob Crittenden wrote: Roderick Johnstone wrote: On 23/04/15 04:25, Rob Crittenden wrote: Roderick Johnstone wrote: On 22/04/15 14:30, Dmitri Pal wrote: On

Re: [Freeipa-users] FreeIPA WebUI Logout logs back in

2015-04-28 Thread Rob Crittenden
Dmitri Pal wrote: On 04/28/2015 05:11 PM, Christopher Lamb wrote: HI All I have just tested with the FreeIPA Web UI public demo https://ipa.demo1.freeipa.org/ipa/ui/ Using the public demo, when I log out, I get returned to the login screen, as expected. This allows me to log in with a

Re: [Freeipa-users] FreeIPA WebUI Logout logs back in

2015-04-28 Thread Dmitri Pal
On 04/28/2015 05:11 PM, Christopher Lamb wrote: HI All I have just tested with the FreeIPA Web UI public demo https://ipa.demo1.freeipa.org/ipa/ui/ Using the public demo, when I log out, I get returned to the login screen, as expected. This allows me to log in with a different user. With our

Re: [Freeipa-users] FreeIPA WebUI Logout logs back in

2015-04-28 Thread Dmitri Pal
On 04/28/2015 05:39 PM, Rob Crittenden wrote: Dmitri Pal wrote: On 04/28/2015 05:11 PM, Christopher Lamb wrote: HI All I have just tested with the FreeIPA Web UI public demo https://ipa.demo1.freeipa.org/ipa/ui/ Using the public demo, when I log out, I get returned to the login screen, as

Re: [Freeipa-users] FreeIPA WebUI Logout logs back in

2015-04-28 Thread Mauricio Tavares
On Apr 28, 2015 11:33 PM, Dmitri Pal d...@redhat.com wrote: On 04/28/2015 05:11 PM, Christopher Lamb wrote: HI All I have just tested with the FreeIPA Web UI public demo https://ipa.demo1.freeipa.org/ipa/ui/ Using the public demo, when I log out, I get returned to the login screen, as

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-04-28 Thread Dmitri Pal
On 04/28/2015 12:17 PM, Christopher Lamb wrote: Hi All I wish to pick your brains on the attribute sambaPwdLastSet We have a newly setup FreeIPA 4.1.0, with users and groups migrated from an old 3.0.0 instance. We are also running Samba to share files to Windows and OSX users. This means that

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-04-28 Thread Alexander Bokovoy
On Tue, 28 Apr 2015, Dmitri Pal wrote: On 04/28/2015 12:17 PM, Christopher Lamb wrote: Hi All I wish to pick your brains on the attribute sambaPwdLastSet We have a newly setup FreeIPA 4.1.0, with users and groups migrated from an old 3.0.0 instance. We are also running Samba to share files

Re: [Freeipa-users] FreeIPA and sambaPwdLastSet

2015-04-28 Thread Alexander Bokovoy
Resending it to the right list. :) Not my evening. On Tue, 28 Apr 2015, Alexander Bokovoy wrote: On Tue, 28 Apr 2015, Christopher Lamb wrote: Hi All I wish to pick your brains on the attribute sambaPwdLastSet We have a newly setup FreeIPA 4.1.0, with users and groups migrated from an old

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-28 Thread Roderick Johnstone
On 23/04/15 14:14, Rob Crittenden wrote: Roderick Johnstone wrote: On 23/04/15 04:25, Rob Crittenden wrote: Roderick Johnstone wrote: On 22/04/15 14:30, Dmitri Pal wrote: On 04/21/2015 01:13 PM, Roderick Johnstone wrote: Hi I also need to integrate Solaris 10 clients with freeipa servers.

Re: [Freeipa-users] how can i create home directories automatically on solaris while IPA user login

2015-04-28 Thread Sigbjorn Lie
Hi, You may download the profile from bugzilla, here’s a direct link to the attachement: https://bugzilla.redhat.com/attachment.cgi?id=579657 https://bugzilla.redhat.com/attachment.cgi?id=579657 Modify the server names and baseDN to match your environment. Use ldapadd to add the dua profile

Re: [Freeipa-users] FreeIPA SAML and Google Apps

2015-04-28 Thread Martin Basti
On 28/04/15 08:53, Andrew Holway wrote: Hi, Is it yet possible to use FreeIPA as an identity provider to Google Apps via SAML. I understand there was some project afoot Thanks, Andrew Maybe this would help. https://fedorahosted.org/ipsilon/ -- Martin Basti -- Manage your

[Freeipa-users] FreeIPA restarts when changing run-levels

2015-04-28 Thread Tiaan Wessels
Hi, Is it correct behavior that FreeIPA restarts when changing run-levels between 3 and 5 ? I would have hoped that if it was already running, that changing the run-level between two run-levels for which IPA has both been configured to run, will have no effect if already running (using

Re: [Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Alexander Bokovoy
On Tue, 28 Apr 2015, Арсений Черняков wrote: - Hi all. I've got a rather big domain environment with 10 distributed locations, and I'm considering using FreeIPA as an id manager for linux users and servers, alongside with existing AD, using trusts. In every location, there are 2 DCs

[Freeipa-users] freeIPA and AD in multi-homed environment

2015-04-28 Thread Арсений Черняков
- Hi all. I've got a rather big domain environment with 10 distributed locations, and I'm considering using FreeIPA as an id manager for linux users and servers, alongside with existing AD, using trusts. In every location, there are 2 DCs for windows environment, and I'm thinking

[Freeipa-users] FreeIPA SAML and Google Apps

2015-04-28 Thread Andrew Holway
Hi, Is it yet possible to use FreeIPA as an identity provider to Google Apps via SAML. I understand there was some project afoot Thanks, Andrew -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for