Re: [Freeipa-users] IPA and DNS reverse subnets

2017-01-30 Thread lejeczek
On 30/01/17 19:32, Tomasz Torcz wrote: On Mon, Jan 30, 2017 at 07:12:10PM +, lejeczek wrote: On 30/01/17 18:28, Tomasz Torcz wrote: On Mon, Jan 30, 2017 at 06:01:03PM +, lejeczek wrote: hi everybody I'm having trouble trying to figure out, or in other words make this to work: I'm

Re: [Freeipa-users] IPA and DNS reverse subnets

2017-01-30 Thread Tomasz Torcz
On Mon, Jan 30, 2017 at 07:12:10PM +, lejeczek wrote: > > > On 30/01/17 18:28, Tomasz Torcz wrote: > > On Mon, Jan 30, 2017 at 06:01:03PM +, lejeczek wrote: > > > hi everybody > > > > > > I'm having trouble trying to figure out, or in other words make this to > > > work: > > > > > >

Re: [Freeipa-users] IPA and DNS reverse subnets

2017-01-30 Thread lejeczek
On 30/01/17 18:28, Tomasz Torcz wrote: On Mon, Jan 30, 2017 at 06:01:03PM +, lejeczek wrote: hi everybody I'm having trouble trying to figure out, or in other words make this to work: I'm setting up a domain in a subnet like this: 10.5.10.48/28 but not sure it I got it right. Host

Re: [Freeipa-users] IPA and DNS reverse subnets

2017-01-30 Thread Tomasz Torcz
On Mon, Jan 30, 2017 at 06:01:03PM +, lejeczek wrote: > hi everybody > > I'm having trouble trying to figure out, or in other words make this to > work: > > I'm setting up a domain in a subnet like this: 10.5.10.48/28 but not sure it > I got it right. > Host reverse resoling does not seem to

[Freeipa-users] IPA and DNS reverse subnets

2017-01-30 Thread lejeczek
hi everybody I'm having trouble trying to figure out, or in other words make this to work: I'm setting up a domain in a subnet like this: 10.5.10.48/28 but not sure it I got it right. Host reverse resoling does not seem to right. I have: Zone name: whale.private. Active zone: TRUE

Re: [Freeipa-users] Needs help understand this timeout issue

2017-01-30 Thread Sullivan, Daniel [CRI]
I have had to deal with the symptoms you describe, never with 730 groups though. Based on my experience doing a lookup for a user in an AD trusted domain is a resource intensive process on the server. I’d first start by taking a look at your logs to see if the lookup is failing on the server

[Freeipa-users] caching of lookups / performance problem

2017-01-30 Thread Sullivan, Daniel [CRI]
Hi, I have another question about sssd performance. I’m having a difficult time doing a regularly performant ‘ls -l’ operation against /home, a mounted NFS share of all of our users home directories. There are 667 entries in this folder, and all of them have IDs that are resolvable via

[Freeipa-users] Needs help understand this timeout issue

2017-01-30 Thread Troels Hansen
Hi there I'm trying to debug on a strange IPA timeout issue. Its SSSD 1.14, IPA 4.4, RHEL 7.3. 2 IPA servers in AD trust. Besides being a bit slow on groups membership lookups on users with a moderate number of Groups, there are some users with a HUGE amount of nested groups. A server

Re: [Freeipa-users] sudo sometimes doesn't work

2017-01-30 Thread Jakub Hrozek
On Fri, Jan 27, 2017 at 02:15:16PM -0700, Orion Poplawski wrote: > EL7.3 > Users are in active directory via AD trust with IPA server > > sudo is configured via files - users in our default "nwra" group can run > certain sudo commands, e.g.: > > Cmnd_Alias WAKEUP = /sbin/ether-wake * >

Re: [Freeipa-users] be_pam_handler_callback Backend returned: (3, 4, ) [Internal Error (System error)]

2017-01-30 Thread thierry bordaz
On 01/27/2017 12:51 PM, Harald Dunkel wrote: Hi Thierry, On 01/26/17 16:55, thierry bordaz wrote: Those entries are managed entries and it is not possible to delete them from direct ldap command. A solution proposed by Ludwig is not first make them unmanaged: