[Freeipa-users] Error deleting IPA host: SSL peer cannot verify your certificate

2017-04-04 Thread Chris Herdt
Although I had previously been using a self-signed certificate, I recently started using a cert signed by InCommon CA on my FreeIPA master (still on IPA 3.0.0 at this time). I added the certificate and intermediate certificates to /etc/ssl/certs and the certificate database in

Re: [Freeipa-users] Auto create kerberos/ldap SRV records on subdomain

2017-04-04 Thread Matt .
Hi Alexander, Superb, thanks a lot for this quick fix! Matt 2017-04-04 20:48 GMT+02:00 Alexander Bokovoy : > On ti, 04 huhti 2017, Matt . wrote: >> >> Hi guys, >> >> Is it possible to create in a simple way the SRV domains for kerberos >> on subdomains ? it's a pain to add

Re: [Freeipa-users] Auto create kerberos/ldap SRV records on subdomain

2017-04-04 Thread Alexander Bokovoy
On ti, 04 huhti 2017, Matt . wrote: Hi guys, Is it possible to create in a simple way the SRV domains for kerberos on subdomains ? it's a pain to add them all manually when you have a lot of subdomains. I hope someone has a solution. Create TXT record _kerberos.sub.domain.tld that contains

[Freeipa-users] Auto create kerberos/ldap SRV records on subdomain

2017-04-04 Thread Matt .
Hi guys, Is it possible to create in a simple way the SRV domains for kerberos on subdomains ? it's a pain to add them all manually when you have a lot of subdomains. I hope someone has a solution. Thanks! Matt -- Manage your subscription for the Freeipa-users mailing list:

Re: [Freeipa-users] SSSD hangs on IPA master

2017-04-04 Thread Jakub Hrozek
On Tue, Apr 04, 2017 at 09:51:04AM +0200, Ronald Wimmer wrote: > Hi, > > my IPA master has an AD trust (several thousand users). Since the trust has > been set up I am experiencing that I cannot login on the web interface. Even > connecting via SSH does not work or takes extremely long. When I

[Freeipa-users] SSSD hangs on IPA master

2017-04-04 Thread Ronald Wimmer
Hi, my IPA master has an AD trust (several thousand users). Since the trust has been set up I am experiencing that I cannot login on the web interface. Even connecting via SSH does not work or takes extremely long. When I managed to log in as root via SSH (after waiting and trying several

Re: [Freeipa-users] libsemanage updates fail due to AD user with space

2017-04-04 Thread Lukas Slebodnik
On (04/04/17 09:32), Lukas Slebodnik wrote: >On (04/04/17 10:13), Lachlan Musicman wrote: >>On 3 April 2017 at 19:11, Jakub Hrozek wrote: >> >>> On Mon, Apr 03, 2017 at 11:00:21AM +1000, Lachlan Musicman wrote: >>> > >>> > With SSSD/IPA in use, in a one way trust to AD, and AD

Re: [Freeipa-users] SSSD setting memcache_timeout on ipa master

2017-04-04 Thread Ronald Wimmer
On 2017-03-31 13:35, Lukas Slebodnik wrote: On (29/03/17 10:47), Ronald Wimmer wrote: Hi, yesterday I suddenly was unable to use the webinterface of my ipa master. SSH login (with root user) did not work also. When I uncommented the setting "memcache_timeout = 600" in the sssd config file of

Re: [Freeipa-users] libsemanage updates fail due to AD user with space

2017-04-04 Thread Lukas Slebodnik
On (04/04/17 10:13), Lachlan Musicman wrote: >On 3 April 2017 at 19:11, Jakub Hrozek wrote: > >> On Mon, Apr 03, 2017 at 11:00:21AM +1000, Lachlan Musicman wrote: >> > >> > With SSSD/IPA in use, in a one way trust to AD, and AD users have spaces >> in >> > their names,