Re: [Freeipa-users] FreeIPA 3.3 performance issues with many hosts

2015-10-28 Thread Sven Kieske
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, On 21/10/15 17:03, Ludwig Krispenz wrote: > It looks like it is accessing memory, which was freed in a > pre-bind plugin, this could be the issue tracked in > https://fedorahosted.org/389/ticket/48188 are you sure that we hit this bug or might

Re: [Freeipa-users] Sync IPA and AD while using external CA

2015-10-28 Thread Rob Crittenden
mitra dehghan wrote: > hello, > I want to implement and IPA server and Sync it with my 2012 ms ad. While > things go well using an internal CA in each server, I came across kind > of problem when I want integrate solution with my PKI which is already > serving the AD server. > I can install IPA

Re: [Freeipa-users] Wrong time / constantly expired passwords

2015-10-28 Thread Rob Crittenden
urgrue wrote: > Didn't realize it was GMT, so OK that's not the issue. Any suggestions > on how to debug it? Everything looks OK, but passwords are just > perma-expired at all times. Need more info on what you're seeing and how the passwords are being changed. rob > > > On Tue, Oct 27, 2015,

Re: [Freeipa-users] Cockpit with (Free)IPA admin users

2015-10-28 Thread Jakub Hrozek
On Tue, Oct 27, 2015 at 09:08:30PM +0100, Martin Štefany wrote: > On St, 2015-10-21 at 09:32 +0200, Jakub Hrozek wrote: > > On Tue, Oct 20, 2015 at 11:25:56PM +0200, Martin Štefany wrote: > > > Hello, > > > > > > did anybody manage to get FreeIPA admin user (member of admins > > > group, > > >

[Freeipa-users] Sync IPA and AD while using external CA

2015-10-28 Thread mitra dehghan
hello, I want to implement and IPA server and Sync it with my 2012 ms ad. While things go well using an internal CA in each server, I came across kind of problem when I want integrate solution with my PKI which is already serving the AD server. I can install IPA with --external-ca switch. but when

Re: [Freeipa-users] rest api

2015-10-28 Thread Alexander Bokovoy
On Wed, 28 Oct 2015, Winfried de Heiden wrote: Hi all, In order for an external application to communicate with IPA and/or modify on (free)Ipa, we want to use the JSON API. Where can I find documentation how to use this API? Read my blog post:

Re: [Freeipa-users] IPA with external CA signed certs

2015-10-28 Thread James Masson
On 26/10/15 16:11, Martin Kosek wrote: On 10/26/2015 04:05 PM, James Masson wrote: On 19/10/15 21:06, Rob Crittenden wrote: James Masson wrote: Hi list, I successfully have IPA working with CA certs signed by an upstream Dogtag. Now I'm trying to use a CA cert signed by a different

Re: [Freeipa-users] rest api

2015-10-28 Thread Rob Crittenden
Winfried de Heiden wrote: > Hi all, > > In order for an external application to communicate with IPA and/or > modify on (free)Ipa, we want to use the JSON API. > > Where can I find documentation how to use this API? > > Thankz! > > Winny > > IPA doesn't use REST. You can get an idea about

[Freeipa-users] rest api

2015-10-28 Thread Winfried de Heiden
Hi all, In order for an external application to communicate with IPA and/or modify on (free)Ipa, we want to use the JSON API. Where can I find documentation how to use this API? Thankz! Winny -- Manage your subscription for the Freeipa-users mailing list:

Re: [Freeipa-users] Wrong time / constantly expired passwords

2015-10-28 Thread urgrue
Here are some examples: [root@mule ~]# ipa user-status freddie --- Account disabled: False --- Server: mule.bulb Failed logins: 0 Last successful authentication: 2015-10-28T09:03:48Z Last failed authentication: 2015-10-28T09:03:40Z Time now:

Re: [Freeipa-users] anonymous LDAP attributes with IPA ipa-server-4.1

2015-10-28 Thread craig . linux
Thanks it worked! For those also intersted in the settings; Permission: ldap_anonymous Bind Type Rule: anonymous Granted Rights: (I used) "read","search","compare" Subtree: cn=users,cn=accounts,dc=example,dc=com Extra target filter: (&(objectclass=Person)(|(uid=*)(givenName=*))) Target DN: