Re: [Freeipa-users] syncing custom attributes from AD
Hi Rich, On 21/06/11 17:13, Rich Megginson wrote: Can you enable REPL and PLUGIN error logging level and reproduce the problem? I would like to see the errors log. See http://directory.fedoraproject.org/wiki/FAQ#Troubleshooting for more information. I enabled REPL || PLUGIN, the problem was reproducible. Sending logs in private. Thanks, Attila ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users
Re: [Freeipa-users] ipa-winsync account disable
Hi, On 21/06/11 17:20, Rich Megginson wrote: What version of Windows? 32-bit or 64-bit? Windows Server 2008 R2 Standard 64-bit. Can you run with the REPL and PLUGIN log levels on? That may reveal some useful clue. http://directory.fedoraproject.org/wiki/FAQ#Troubleshooting Sending logs in private... Thanks, Attila ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users
Re: [Freeipa-users] ipa-client-install errors via kickstart
Hi, 2.0 or 1.2? Also ppl who know way more than me always seem to want the logs. ;] regards Steven From: freeipa-users-boun...@redhat.com [freeipa-users-boun...@redhat.com] on behalf of Charlie Derwent [shelltoesupers...@gmail.com] Sent: Wednesday, 22 June 2011 9:44 p.m. To: freeipa-users@redhat.com Subject: [Freeipa-users] ipa-client-install errors via kickstart Hi I'm running FreeIPA server on F14 and connecting to a F14 client. When I run ipa-client-install (via kickstart or after the client has installed) I'm getting the following error message. root: DEBUG root: ERRORLDAP Error: Connect error: Start TLS request accepted. Server willing to negotiate SSL Failed to verify that ipa.test.nethttp://ipa.test.net is an IPA server This may mean that the remote server is not up or is not reachable due to network or firewall settings The ipa server is definately up and running, it's still authenticating other servers in the network and when I rebuild the client with rhel or centos it can enroll (almost) without issue (see below). The second issue was this certmonger related bug where certmonger fails to start on new install (https://bugzilla.redhat.com/show_bug.cgi?id=636894) was it resolved in Red Hat 5 as I think i'm expering the issue with my RH5u6 clients? Thanks Charlie ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users
Re: [Freeipa-users] ipa-client-install errors via kickstart
Charlie Derwent wrote: Hi I'm running FreeIPA server on F14 and connecting to a F14 client. When I run ipa-client-install (via kickstart or after the client has installed) I'm getting the following error message. root: DEBUG root: ERRORLDAP Error: Connect error: Start TLS request accepted. Server willing to negotiate SSL Failed to verify that ipa.test.net http://ipa.test.net is an IPA server This may mean that the remote server is not up or is not reachable due to network or firewall settings What version of IPA are you running on the client and server? Can you check the 389-ds access log to see if you can see the connection and any errors reported with it? The ipa server is definately up and running, it's still authenticating other servers in the network and when I rebuild the client with rhel or centos it can enroll (almost) without issue (see below). The second issue was this certmonger related bug where certmonger fails to start on new install (https://bugzilla.redhat.com/show_bug.cgi?id=636894) was it resolved in Red Hat 5 as I think i'm expering the issue with my RH5u6 clients? Looks like it wasn't fixed in RHEL 5.x. IIRC the simple fix is to restart messagebus after installing certmonger. Should be easy to do in a kickstart. rob ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users