Re: [Freeipa-users] Split backup actions in stop - backup - start commands

2016-02-18 Thread David Kupka
On 17/02/16 10:47, Matt . wrote: Hi David, I have tested your way out and it seems to be OK. The reason why I need this was is so I can perform a stop and ipa-backup before I start my backup to my backupserver. (pre-command). If I use ipa-backup directly it errors between the stop of ipa and

[Freeipa-users] IPA 4.2.0 / CentOS 7: krb5kdc: Server error - while fetching master key K/M for realm

2016-02-18 Thread Torsten Harenberg
Dear all, we run a pair of IPA servers: a master running on FC 21 and a slave running on CentOS release 7.2.1511. krb5kdc: Server error - while fetching master key K/M for realm PLEIADES.UNI-WUPPERTAL.DE To handle CVE-2015-7547, we upgraded both systems (with a simple "yum update"). The master

Re: [Freeipa-users] IPA 4.2.0 / CentOS 7: krb5kdc: Server error - while fetching master key K/M for realm

2016-02-18 Thread Torsten Harenberg
Sorry for self-replying. I should have mentioned that we already went through: http://www.freeipa.org/page/Troubleshooting#Service_does_not_start But it turned out that a simple ipactl stop ipactl start helped. Surprisingly, the service does not start correctly at boot time, but starting it

Re: [Freeipa-users] ID Views without AD

2016-02-18 Thread Sumit Bose
On Tue, Feb 16, 2016 at 04:23:10PM +, Mike Kelly wrote: > >> Thanks. Here's what is hopefully the relevant lines: > > > > I'm sorry, but these logs only capture how the original entry was > searched, not the overrides. Can you capture the full logs since the sssd > startup? Also please make

[Freeipa-users] 14: No supported authentication methods available

2016-02-18 Thread Terry John
I have an AWS instance running Centos 6.7 correctly configured for freeipa but I needed to make a backup machine which would remain live. I created a clone of the machine and changed the host name and the settings in /etc/hosts. When I tried to run ipa-client-install it told me to run the

[Freeipa-users] freeipa permission denied for user

2016-02-18 Thread Rakesh Rajasekharan
I set up freeipa on our environment and its works perfectly for most of the hosts.. but on few I am getting a permission denied. [root@ipa-client-1c :~] ssh tempuser@localhost tempuser@localhost's password: Permission denied, please try again. tempuser@localhost's password: I checked the

Re: [Freeipa-users] freeipa permission denied for user

2016-02-18 Thread Martin Kosek
On 02/18/2016 02:11 PM, Rakesh Rajasekharan wrote: > I set up freeipa on our environment and its works perfectly for most of the > hosts.. but on few I am getting a permission denied. > > [root@ipa-client-1c :~] ssh tempuser@localhost > tempuser@localhost's password: > Permission denied, please

Re: [Freeipa-users] Split backup actions in stop - backup - start commands

2016-02-18 Thread Rob Crittenden
David Kupka wrote: > On 17/02/16 10:47, Matt . wrote: >> Hi David, >> >> I have tested your way out and it seems to be OK. >> >> The reason why I need this was is so I can perform a stop and >> ipa-backup before I start my backup to my backupserver. (pre-command). >> >> If I use ipa-backup

Re: [Freeipa-users] ID Views without AD

2016-02-18 Thread Sumit Bose
On Thu, Feb 18, 2016 at 11:26:58AM +0100, Sumit Bose wrote: > On Tue, Feb 16, 2016 at 04:23:10PM +, Mike Kelly wrote: > > >> Thanks. Here's what is hopefully the relevant lines: > > > > > > I'm sorry, but these logs only capture how the original entry was > > searched, not the overrides. Can

[Freeipa-users] About ipa passwd and kpasswd

2016-02-18 Thread bahan w
Hello everyone. I send you this mail because I have sometimes a problem when using ipa passwd to generate a One Time Password and then using kpasswd to set a strong random password using a password policy. When I perform the ipa passwd command and just after the kpasswd command, I got an error

Re: [Freeipa-users] freeipa permission denied for user

2016-02-18 Thread Rakesh Rajasekharan
The permission for /etc/krb5.conf was already set to 644. So, that aspect looks fine.. I think it might be something to do with the pam settings. here is my sssd.conf [root@ipa-client :/etc/sssd] cat sssd.con [domain/xyz.com] krb5_auth_timeout = 30 cache_credentials = True

[Freeipa-users] Wildcards in sudo external hostnames

2016-02-18 Thread Prashant Bapat
Hi, I'm using FreeIPA 4.1.4 with nss-pam-ldapd and the compat schema. I'm thinking of moving sudo rules to IPA and with *ou=sudoers* and sudo-ldap this works. In our setup we have lot of rules with wildcard matching for sudo hostnames. For ex webserver*, dbserver* etc. In the IPA UI, when I

Re: [Freeipa-users] freeipa permission denied for user

2016-02-18 Thread Lukas Slebodnik
On (18/02/16 18:41), Rakesh Rajasekharan wrote: >I set up freeipa on our environment and its works perfectly for most of the >hosts.. but on few I am getting a permission denied. > >[root@ipa-client-1c :~] ssh tempuser@localhost >tempuser@localhost's password: >Permission denied, please try again.