Re: [Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Fraser Tweedale
On Mon, Jan 11, 2016 at 12:55:52PM +0100, Martin Kosek wrote: > On 01/11/2016 12:51 PM, Arthur Fayzullin wrote: > > Bingo!!! > > that it is!!! > > dm password contains % - symbol! > > > > I am not sure but with previous versions that have not caused any problem. > > Good :-) > > Still, it would

[Freeipa-users] Upgrade to FreeIPA 4.2.0 broke Katello/Foreman realm proxy

2016-01-11 Thread nathan
I'm not sure which mailing list is the best for this because it involves 2 products, but I think the fault here is with FreeIPA. Basically I have a Katello server running as a realm proxy. It is joined as a client to the FreeIPA domain. I have provisioned 20 hosts last week using its Foreman

[Freeipa-users] Documentation on Testing page

2016-01-11 Thread Anthony Cheng
Hi all, I have been looking at the documentation, specifically the test page: http://www.freeipa.org/page/Testing It looks like it has missing info on the Build section, specifically I don't see reference to a makefile or where to run make to build the testing utility. Thanks, Anthony --

Re: [Freeipa-users] IPA Users enable to run Cron

2016-01-11 Thread Jakub Hrozek
On Mon, Jan 11, 2016 at 02:06:01PM +0530, Yogesh Sharma wrote: > Team, > > None of the ipa-users are able to execute crons on any servers. If we > create local user then we are able to do. > > There is no cron.allow and we do not have any user listed in cron.deny. > > Is there something from

Re: [Freeipa-users] FreeIPA and project Atomic

2016-01-11 Thread Lukas Slebodnik
On (09/01/16 18:41), Marc Boorshtein wrote: >I'm moving an environment from one that uses all separate VMs to one using >project Atomic and Docker images. A couple of questions: > >1. Are there any known issues joining an atomic host to a FreeIPA domain? > (Or has anyone tried it?) I think the

Re: [Freeipa-users] FreeIPA and project Atomic

2016-01-11 Thread Jan Pazdziora
On Sat, Jan 09, 2016 at 06:41:53PM -0500, Marc Boorshtein wrote: > I'm moving an environment from one that uses all separate VMs to one using > project Atomic and Docker images. A couple of questions: > > 1. Are there any known issues joining an atomic host to a FreeIPA domain? > (Or has

[Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Arthur Fayzullin
Good day, Colleagues! And Happy New Year! I have tried to install test stend with ipa v4.2 and 2 master-master servers. files /etc/hosts on both servers contain: 127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 ::1 localhost localhost.localdomain localhost6

[Freeipa-users] IPA Users enable to run Cron

2016-01-11 Thread Yogesh Sharma
Team, None of the ipa-users are able to execute crons on any servers. If we create local user then we are able to do. There is no cron.allow and we do not have any user listed in cron.deny. Is there something from FreeIPA end which is blocking. Just a confirmation, as we continue to

Re: [Freeipa-users] Upgrade to FreeIPA 4.2.0 broke Katello/Foreman realm proxy

2016-01-11 Thread Jan Pazdziora
On Mon, Jan 11, 2016 at 03:01:40PM -0800, nat...@nathanpeters.com wrote: > > Basically I have a Katello server running as a realm proxy. It is joined > as a client to the FreeIPA domain. I have provisioned 20 hosts last week > using its Foreman realm proxy feature and they all worked fine. > >

Re: [Freeipa-users] IPA users not visible in NIS passwd map

2016-01-11 Thread Prasun Gera
This is the output of the command: ldapsearch -LLL -H $(cat /etc/ipa/default.conf | grep ldap_uri|cut -d= -f2) -b cn=config '(nis-domain=*)' dn CreateTimestamp ModifyTimestamp SASL/EXTERNAL authentication started SASL username: gidNumber=0+uidNumber=0,cn=peercred,cn=external,cn=auth SASL SSF: 0

Re: [Freeipa-users] Documentation on Testing page

2016-01-11 Thread Rob Crittenden
Anthony Cheng wrote: > Hi all, > > I have been looking at the documentation, specifically the test page: > http://www.freeipa.org/page/Testing > > It looks like it has missing info on the Build section, specifically I > don't see reference to a makefile or where to run make to build the >

[Freeipa-users] Replication failing on FreeIPA 4.2.0

2016-01-11 Thread nathan
I have 3 FreeIPA 4.2.0 servers running on CentOS 7.2 I am getting replication errors that I cannot seem to figure out. Here is the setup : (I refer to master and slave because apparently your CA is the only one who can create replica certs so it is the 'master') dc1 : master, been running for a

[Freeipa-users] IPA users not visible in NIS passwd map

2016-01-11 Thread Prasun Gera
I upgraded ipa to 4.2 on my rhel 7.2 servers a few weeks ago. One of the users reported that he is not able to log in to certain systems any more. It turns out that there is some change in behaviour w.r.t NIS clients after this upgrade. I see that his username is not visible in "ypcat passwd" on

Re: [Freeipa-users] IPA users not visible in NIS passwd map

2016-01-11 Thread Alexander Bokovoy
On Mon, 11 Jan 2016, Prasun Gera wrote: I upgraded ipa to 4.2 on my rhel 7.2 servers a few weeks ago. One of the users reported that he is not able to log in to certain systems any more. It turns out that there is some change in behaviour w.r.t NIS clients after this upgrade. I see that his

[Freeipa-users] 4.2 (or 4.3) clients on 4.1.4 server?

2016-01-11 Thread Janelle
Good day, Just wondering if anyone knows of any reason a 4.2 client running on RHEL 7.2 would have any issues talking to 4.1.4 server on RHEL 7.1? The reason I ask is the process of upgrading. In this case we have to do clients first. Thank you ~Janelle -- Manage your subscription for the

Re: [Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Arthur Fayzullin
Bingo!!! that it is!!! dm password contains % - symbol! I am not sure but with previous versions that have not caused any problem. Thanks a lot! 11.01.2016 16:48, Martin Kosek пишет: > On 01/11/2016 12:01 PM, Arthur Fayzullin wrote: >> Good day, Colleagues! >> >> And Happy New Year! >> >> I

Re: [Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Martin Kosek
On 01/11/2016 12:51 PM, Arthur Fayzullin wrote: > Bingo!!! > that it is!!! > dm password contains % - symbol! > > I am not sure but with previous versions that have not caused any problem. Good :-) Still, it would be nice to fix Dogtag installation procedures to not parse passwords that way.

Re: [Freeipa-users] IPA Users enable to run Cron

2016-01-11 Thread Yogesh Sharma
HBAC has "Any Service" enabled, However, while doing HBAC Test, I am getting Access Denied. Checking it. Thanks for the suggestion. Any further suggestion would be helpful. *Best Regards,* *__* *Yogesh Sharma* *Email: yks0...@gmail.com

Re: [Freeipa-users] error while installin ipa-replica with ca

2016-01-11 Thread Martin Kosek
On 01/11/2016 12:01 PM, Arthur Fayzullin wrote: > Good day, Colleagues! > > And Happy New Year! > > I have tried to install test stend with ipa v4.2 and 2 master-master > servers. > > files /etc/hosts on both servers contain: > 127.0.0.1 localhost localhost.localdomain localhost4 >

Re: [Freeipa-users] FreeIPA and project Atomic

2016-01-11 Thread Lukas Slebodnik
On (11/01/16 11:35), Jan Pazdziora wrote: >On Sat, Jan 09, 2016 at 06:41:53PM -0500, Marc Boorshtein wrote: >> I'm moving an environment from one that uses all separate VMs to one using >> project Atomic and Docker images. A couple of questions: >> >> 1. Are there any known issues joining an

Re: [Freeipa-users] FreeIPA 4.x + CentOS 6.4

2016-01-11 Thread fvende.ext
Hi, Ok, it's enough clear for me. Thanks a lot for all your responses ! Best regards, Fx -Message d'origine- De : Rob Crittenden [mailto:rcrit...@redhat.com] Envoyé : mardi 5 janvier 2016 15:37 À : freeipa-users@redhat.com; bahan w Cc : VENDE Francois Xavier Ext DTSI/DSI Objet : Re:

Re: [Freeipa-users] Cross Domain Trust

2016-01-11 Thread Zoske, Fabian
I looked deeper into the problem and tested it with ubuntu 16.04 Alpha which includes SSSD 1-13-3. Now I have the same problem on Ubuntu. On Ubuntu 14.04 I have installed the shipped SSSD-1.11.5 and everything works. Best regards, Fabian -Ursprüngliche Nachricht- Von: Sumit Bose

[Freeipa-users] The -e skip_version_check=1 with 4.2 client against 6.4-based server

2016-01-11 Thread Jan Pazdziora
Hello, we have IPA client on [root@centos72-20160110 ~]# cat /etc/redhat-release CentOS Linux release 7.2.1511 (Core) with the following packages: [root@centos72-20160110 ~]# rpm -qf /usr/lib/python2.7/site-packages/ipapython/version.py

Re: [Freeipa-users] Cross Domain Trust

2016-01-11 Thread Lukas Slebodnik
On (11/01/16 14:56), Zoske, Fabian wrote: >I looked deeper into the problem and tested it with ubuntu 16.04 Alpha which >includes SSSD 1-13-3. >Now I have the same problem on Ubuntu. >On Ubuntu 14.04 I have installed the shipped SSSD-1.11.5 and everything works. > It might be issue on ipa server.

Re: [Freeipa-users] The -e skip_version_check=1 with 4.2 client against 6.4-based server

2016-01-11 Thread Jan Pazdziora
On Mon, Jan 11, 2016 at 07:05:16PM +0100, Martin Basti wrote: > On 11.01.2016 16:57, Jan Pazdziora wrote: > > > >We try to call the ipa commands against old FreeIPA server version, > >taking advantage of the > > > > -e skip_version_check=1 > > > >option added by > > > >

Re: [Freeipa-users] The -e skip_version_check=1 with 4.2 client against 6.4-based server

2016-01-11 Thread Martin Basti
On 11.01.2016 16:57, Jan Pazdziora wrote: Hello, we have IPA client on [root@centos72-20160110 ~]# cat /etc/redhat-release CentOS Linux release 7.2.1511 (Core) with the following packages: [root@centos72-20160110 ~]# rpm -qf