Re: [Freeipa-users] ipa replica failure

2015-06-22 Thread Rob Crittenden
Andrew E. Bruno wrote: On Mon, Jun 22, 2015 at 10:02:59AM -0400, Rob Crittenden wrote: Andrew E. Bruno wrote: On Fri, Jun 19, 2015 at 03:18:50PM -0400, Rob Crittenden wrote: Rich Megginson wrote: On 06/19/2015 12:22 PM, Andrew E. Bruno wrote: Questions: 0. Is it likely that after running

Re: [Freeipa-users] ipa replica failure

2015-06-22 Thread Andrew E. Bruno
On Mon, Jun 22, 2015 at 10:02:59AM -0400, Rob Crittenden wrote: Andrew E. Bruno wrote: On Fri, Jun 19, 2015 at 03:18:50PM -0400, Rob Crittenden wrote: Rich Megginson wrote: On 06/19/2015 12:22 PM, Andrew E. Bruno wrote: Questions: 0. Is it likely that after running out of file

Re: [Freeipa-users] blank user screen? (web UI)

2015-06-22 Thread Petr Vobornik
On 06/22/2015 04:15 PM, Janelle wrote: On 6/22/15 5:15 AM, Petr Vobornik wrote: On 06/21/2015 08:35 AM, Janelle wrote: Hi, Sure. Just login as a normal user to the WEB UI. screen is blank: Of course, if you click on Actions - you will see those and you can click on them, but you can't do

Re: [Freeipa-users] blank user screen? (web UI)

2015-06-22 Thread Petr Vobornik
On 06/22/2015 06:39 PM, Janelle wrote: On 6/22/15 9:25 AM, Petr Vobornik wrote: On 06/22/2015 04:15 PM, Janelle wrote: On 6/22/15 5:15 AM, Petr Vobornik wrote: On 06/21/2015 08:35 AM, Janelle wrote: Hi, Sure. Just login as a normal user to the WEB UI. screen is blank: Of course, if you

Re: [Freeipa-users] blank user screen? (web UI)

2015-06-22 Thread Janelle
On 6/22/15 9:25 AM, Petr Vobornik wrote: On 06/22/2015 04:15 PM, Janelle wrote: On 6/22/15 5:15 AM, Petr Vobornik wrote: On 06/21/2015 08:35 AM, Janelle wrote: Hi, Sure. Just login as a normal user to the WEB UI. screen is blank: Of course, if you click on Actions - you will see those and

Re: [Freeipa-users] WG: Re: Haunted servers?

2015-06-22 Thread Ludwig Krispenz
Hi, I have one scenario where I can show the comeback of the ghost rids. but it requires a server where the rids have successfully cleaned and it is killed or crashes. In that case, if the ghost rids have not yet been trimmed from the changelog they can be recreated from information in the

Re: [Freeipa-users] Migrate from 3.0 (CentOS 6.6) to 4.1 (CentOS 7.1)

2015-06-22 Thread Matt .
OK, I'm on the go here but I have some issue. When I install the replica server I get this error on the new replica: ipa : CRITICAL CA DS schema check failed. Make sure the PKI service on the remote master is operational. When I restart IPA on the old master I get this:

Re: [Freeipa-users] WG: Re: Haunted servers?

2015-06-22 Thread Christoph Kaminski
from an earlier post it looks like they are from the o=ipaca backend, did you clean the ruvs there ? we have only done a 'normal' cleanruv... How can I clean them there? to know which are the correct current rids for this backend you could do on each active server a search for ... -b

Re: [Freeipa-users] WG: Re: Haunted servers?

2015-06-22 Thread Ludwig Krispenz
Hi, On 06/22/2015 09:48 AM, Christoph Kaminski wrote: from an earlier post it looks like they are from the o=ipaca backend, did you clean the ruvs there ? we have only done a 'normal' cleanruv... How can I clean them there? either you try the cleanallruv: # ldapmodify -D cn=directory

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp
On 06/19/2015 11:12 AM, Christoph Kaminski wrote: for this problem you can see the thread Haunted servers? here on ml. There is a solution from me for this but it doesnt work 100% :/ I would rather rerun the replication. we have a Ticket @Red Hat for this problem,

Re: [Freeipa-users] question on Active Directory and FreeIPA

2015-06-22 Thread Jakub Hrozek
On Fri, Jun 19, 2015 at 08:15:37PM +, David Fitzgerald wrote: -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Jakub Hrozek Sent: Friday, June 19, 2015 3:15 PM To: freeipa-users@redhat.com Subject: Re:

Re: [Freeipa-users] question on Active Directory and FreeIPA

2015-06-22 Thread Jakub Hrozek
On Mon, Jun 22, 2015 at 09:36:49AM +, Alexander Frolushkin wrote: Hello, Jakub! Could you please tell, what about sssd package in RHEL 6, when we can expect the fixes in official updates? Especially with our sensitive fixes (parentheses in AD groups names)? Hi, in RHEL-6, only the

[Freeipa-users] Migrate from 3.0 (CentOS 6.6) to 4.1 (CentOS 7.1)

2015-06-22 Thread Matt .
Hi Guys, I found some good information about migrating from 3.3 to 4.x using replica's. It's not 100% clear what I can do on a CentOS 6.6 install with 3.0 as CentOS doesn't provide 3.3. Some other question is that my hostnames are now like ipa-01 and ipa-02 where I make one replica ipa-01-1 and

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Christoph Kaminski
Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1).

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp
On 06/22/2015 10:49 AM, Christoph Kaminski wrote: In my particular case I'm interested, whether it can crash servers. Does it for you? I don't see it in that thread. tamas yes... we has had a really often a crash on virtual machines installations. On bare metal we had 2-3x a crash.

[Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Christoph Kaminski
In my particular case I'm interested, whether it can crash servers. Does it for you? I don't see it in that thread. tamas yes... we has had a really often a crash on virtual machines installations. On bare metal we had 2-3x a crash. That was the reason for us to destroy all IPA VM's.

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp
On 06/22/2015 10:31 AM, Christoph Kaminski wrote: Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Alexander Frolushkin
Hello everyone. I can confirm this on VMWare, recently we have the similar issue when enabled dirsrv debug on 4 of our 19 IPA servers :( WBR, Alexander Frolushkin Cell +79232508764 Work +79232507764 From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp
Fascinating. Can you Red Hat guys reproduce this in you test environment? Thanks, tamas On 06/22/2015 11:42 AM, Alexander Frolushkin wrote: Hello everyone. I can confirm this on VMWare, recently we have the similar issue when enabled dirsrv debug on 4 of our 19 IPA servers L WBR,

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread thierry bordaz
On 06/22/2015 10:22 AM, Tamas Papp wrote: On 06/19/2015 11:12 AM, Christoph Kaminski wrote: for this problem you can see the thread Haunted servers? here on ml. There is a solution from me for this but it doesnt work 100% :/ I would rather rerun the replication. we have a Ticket @Red Hat

Re: [Freeipa-users] question on Active Directory and FreeIPA

2015-06-22 Thread Alexander Frolushkin
Hello, Jakub! Could you please tell, what about sssd package in RHEL 6, when we can expect the fixes in official updates? Especially with our sensitive fixes (parentheses in AD groups names)? WBR, Alexander Frolushkin Cell +79232508764 Work +79232507764 -Original Message- From:

Re: [Freeipa-users] invalid 'permission': cannot add permission System: Read HBAC Rules with bindtype all to a privilege

2015-06-22 Thread Nathan Peters
-Original Message- From: Rob Crittenden Sent: Saturday, June 20, 2015 1:17 PM To: Nathan Peters Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] invalid 'permission': cannot add permission System: Read HBAC Rules with bindtype all to a privilege Nathan Peters wrote:

Re: [Freeipa-users] invalid 'permission': cannot add permission System: Read HBAC Rules with bindtype all to a privilege

2015-06-22 Thread Rob Crittenden
Nathan Peters wrote: -Original Message- From: Rob Crittenden Sent: Saturday, June 20, 2015 1:17 PM To: Nathan Peters Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] invalid 'permission': cannot add permission System: Read HBAC Rules with bindtype all to a privilege Nathan

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Alexander Frolushkin
Hello. We have 19 RHEL 7.1 IPA (ipa-server-4.1.0-18.el7_1.3.x86_64) servers. Debug level was changed this way on 4 of them: dn: cn=config changetype: modify replace: nsslapd-errorlog-level nsslapd-errorlog-level:24576 - replace: nsslapd-accesslog-level nsslapd-accesslog-level:256 EOF After this,

Re: [Freeipa-users] blank user screen? (web UI)

2015-06-22 Thread Petr Vobornik
On 06/21/2015 08:35 AM, Janelle wrote: Hi, Sure. Just login as a normal user to the WEB UI. screen is blank: Of course, if you click on Actions - you will see those and you can click on them, but you can't do anything else. This is a vanilla server install, nothing fancy. Oh and there is no

Re: [Freeipa-users] FreeIPA groups not shown on client

2015-06-22 Thread Nikola Kržalić
Just in case somebody is still struggling with this... On ubuntu 14.04 I had to set enumerate option to true in sssd.conf to make this work. On Fri, May 22, 2015 at 6:28 PM, Christoph Kaminski christoph.kamin...@biotronik.com wrote: freeipa-users-boun...@redhat.com schrieb am 22.05.2015

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp
On 06/22/2015 02:20 PM, thierry bordaz wrote: On 06/22/2015 11:50 AM, Tamas Papp wrote: Fascinating. Can you Red Hat guys reproduce this in you test environment? Most of my tests are on RHEV with RHEL 7.1, I have not seen a crash of DS. About the test case, you installed a server+replicas

Re: [Freeipa-users] Changing the SSL certificate for the WebUI

2015-06-22 Thread Rob Crittenden
Prashant Bapat wrote: Hi Rob, Thanks for the reply. The ipa-server-certinstalldid require that I have the cert and the CA cert in PEM file and the key in another PEM file. And the command went thru successfully. But afterwards the HTTP service stopped working. Only way I could get it to start

Re: [Freeipa-users] [SSSD-users] Announcing SSSD 1.13 Alpha

2015-06-22 Thread Dmitri Pal
On 06/22/2015 08:03 AM, Michael Ströder wrote: HI! I'd be glad if this RFE could make it into 1.13.x: https://fedorahosted.org/sssd/ticket/2411 Ciao, Michael. It was and is not planned for 1.13. It is targeting 1.14 but patches are always welcome. -- Thank you, Dmitri Pal Director of

Re: [Freeipa-users] FreeIPA groups not shown on client

2015-06-22 Thread Jakub Hrozek
On Sat, Jun 20, 2015 at 08:35:24PM +0200, Nikola Kržalić wrote: Just in case somebody is still struggling with this... On ubuntu 14.04 I had to set enumerate option to true in sssd.conf to make this work. While I'm glad it fixes your setup for you, enabling enumeration is really a suboptimal

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread thierry bordaz
On 06/22/2015 11:50 AM, Tamas Papp wrote: Fascinating. Can you Red Hat guys reproduce this in you test environment? Most of my tests are on RHEV with RHEL 7.1, I have not seen a crash of DS. About the test case, you installed a server+replicas (version ?), then turn on errorlog-level (do you

Re: [Freeipa-users] [SSSD-users] Announcing SSSD 1.13 Alpha

2015-06-22 Thread Michael Ströder
HI! I'd be glad if this RFE could make it into 1.13.x: https://fedorahosted.org/sssd/ticket/2411 Ciao, Michael. smime.p7s Description: S/MIME Cryptographic Signature -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to

Re: [Freeipa-users] Antwort: Re: Antwort: clean-run doesn't work

2015-06-22 Thread thierry bordaz
On 06/22/2015 02:39 PM, Tamas Papp wrote: On 06/22/2015 02:20 PM, thierry bordaz wrote: On 06/22/2015 11:50 AM, Tamas Papp wrote: Fascinating. Can you Red Hat guys reproduce this in you test environment? Most of my tests are on RHEV with RHEL 7.1, I have not seen a crash of DS. About the

Re: [Freeipa-users] blank user screen? (web UI)

2015-06-22 Thread Janelle
On 6/22/15 5:15 AM, Petr Vobornik wrote: On 06/21/2015 08:35 AM, Janelle wrote: Hi, Sure. Just login as a normal user to the WEB UI. screen is blank: Of course, if you click on Actions - you will see those and you can click on them, but you can't do anything else. This is a vanilla server

[Freeipa-users] Announcing FreeIPA 4.2.0 Alpha 1

2015-06-22 Thread Petr Vobornik
The FreeIPA team is proud to announce FreeIPA v4.2.0 Alpha 1 release! It can be downloaded from http://www.freeipa.org/page/Downloads. The builds for Fedora 22 and Fedora Rawhide is available in the official COPR repository https://copr.fedoraproject.org/coprs/mkosek/freeipa-4.2/. This

Re: [Freeipa-users] Crazy Cert problem?

2015-06-22 Thread Rob Crittenden
Janelle wrote: On 6/17/15 2:00 PM, Rob Crittenden wrote: Janelle wrote: On 6/17/15 6:21 AM, Rob Crittenden wrote: Janelle wrote: On 6/17/15 6:14 AM, Rob Crittenden wrote: Janelle wrote: Hi, Had a server - named ipa001.example.com -- it was a replica. It died. It was re-installed. However,

Re: [Freeipa-users] Migrate from 3.0 (CentOS 6.6) to 4.1 (CentOS 7.1)

2015-06-22 Thread Hendrik Frenzel
Am 22.06.2015 12:10, schrieb Matt .: Hi Guys, Hi Matt, I found some good information about migrating from 3.3 to 4.x using replica's. It's not 100% clear what I can do on a CentOS 6.6 install with 3.0 as CentOS doesn't provide 3.3. Could you please share an URL or something? Currently

Re: [Freeipa-users] Crazy Cert problem?

2015-06-22 Thread Janelle
On 6/17/15 2:00 PM, Rob Crittenden wrote: Janelle wrote: On 6/17/15 6:21 AM, Rob Crittenden wrote: Janelle wrote: On 6/17/15 6:14 AM, Rob Crittenden wrote: Janelle wrote: Hi, Had a server - named ipa001.example.com -- it was a replica. It died. It was re-installed. However, prior to the

Re: [Freeipa-users] Migrate from 3.0 (CentOS 6.6) to 4.1 (CentOS 7.1)

2015-06-22 Thread Rob Crittenden
Matt . wrote: Hi Guys, I found some good information about migrating from 3.3 to 4.x using replica's. It's not 100% clear what I can do on a CentOS 6.6 install with 3.0 as CentOS doesn't provide 3.3.

Re: [Freeipa-users] ipa replica failure

2015-06-22 Thread Rob Crittenden
Andrew E. Bruno wrote: On Fri, Jun 19, 2015 at 03:18:50PM -0400, Rob Crittenden wrote: Rich Megginson wrote: On 06/19/2015 12:22 PM, Andrew E. Bruno wrote: Questions: 0. Is it likely that after running out of file descriptors the dirsrv slapd database on rep2 was corrupted? That would