Re: [Freeipa-users] Limiting group/user visibility

2011-12-08 Thread Rob Crittenden
Lassi Pölönen wrote: On 7.12.2011 21:28, Dmitri Pal wrote: I think I found at least one solution, that probably isn't the most elegant one. On the other hand I don't think with the current limitations of FreeIPA it is even possible to do much better. Any comments/suggestions are of course

[Freeipa-users] CA replication

2011-12-08 Thread Dan Scott
Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It proceeds to configure the directory server for the CA, but fails when 'configuring certificate server': Configuring certificate server: Estimated time 3 minutes 30 seconds

Re: [Freeipa-users] CA replication

2011-12-08 Thread Rob Crittenden
Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It proceeds to configure the directory server for the CA, but fails when 'configuring certificate server': Configuring certificate server: Estimated time 3

[Freeipa-users] admin

2011-12-08 Thread Steven Jones
Is this user blocked from logging into a IPA client? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] admin

2011-12-08 Thread Jakub Hrozek
On Thu, Dec 08, 2011 at 08:49:06PM +, Steven Jones wrote: Is this user blocked from logging into a IPA client? It is not blocked, I often use admin as a test dummy for SSSD testing. ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] admin

2011-12-08 Thread Rob Crittenden
Steven Jones wrote: Is this user blocked from logging into a IPA client? No, it is more or less a normal user. rob ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] admin

2011-12-08 Thread Steven Jones
Hi, yeah Im having issues with IPAgroups dont work and new HBAC rules dont either. Hopefully its because its 6.2beta.but I cant update my sat server from RH so I cant patch it.im getting 1.2kbps ... :/ regards Steven Jones Technical Specialist - Linux RHCE Victoria University,

Re: [Freeipa-users] synchronizing with AD

2011-12-08 Thread Jimmy
I had a few weeks away from this configuration and finally getting back to it. I'm uncertain of the correct path forward. I don't seem to be able to find the documentation on how to install the cert into the Passsync NSS database. I have been following this document:

Re: [Freeipa-users] synchronizing with AD

2011-12-08 Thread Sigbjorn Lie
Hi Jimmy, I believe this is the documentation for the old IPA 1 version. You'll find the updated guide at the link below. I used this guide for configuring IPA - AD sync. http://docs.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/index.html Regards, Siggi

Re: [Freeipa-users] synchronizing with AD

2011-12-08 Thread Rich Megginson
On 12/08/2011 02:31 PM, Jimmy wrote: I had a few weeks away from this configuration and finally getting back to it. I'm uncertain of the correct path forward. I don't seem to be able to find the documentation on how to install the cert into the Passsync NSS database. I have been following this

Re: [Freeipa-users] CA replication

2011-12-08 Thread Dan Scott
Hi, On Thu, Dec 8, 2011 at 13:29, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It proceeds to configure the directory server for the CA, but fails when

[Freeipa-users] converting users to ldap command line

2011-12-08 Thread Steven Jones
I Created a user storage-admin I have a domain unux.vuw.ac.nz in terms of ou's and dc's what would that look like? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 ___ Freeipa-users

Re: [Freeipa-users] dns delegated zone issue

2011-12-08 Thread Simo Sorce
On Wed, 2011-12-07 at 23:00 +0100, Natxo Asenjo wrote: hi, for 'historical' reasons, I have a working dns zone in my lan, say example.com. In this zone, I have delegated an ipa.example.com zone for ipa. I have setup freeipa (homelab, SL 6.1 with version ipa-server-2.0.0-23.el6.i686) and