Re: [Freeipa-users] Screensaver unlock with expired password

2012-04-16 Thread Dmitri Pal
On 04/14/2012 08:20 AM, Sigbjorn Lie wrote: Hi, I ran into a issue with unlocking the screensaver when an users password has expired. These results are from RHEL 5. When running KDE and unlocking a screensaver with an expired password, an error message is displayed advising that the

Re: [Freeipa-users] routing requests to local servers - DNS SRV + view?

2012-04-16 Thread Jakub Hrozek
On Mon, Apr 16, 2012 at 09:40:16AM -0400, Dmitri Pal wrote: On 04/13/2012 11:00 PM, Brian Cook wrote: Yes, this is exactly what I am trying to accomplish. I've already been looking in to the BIND views clause and would like to hear if anyone has any feedback as to how well

Re: [Freeipa-users] multiple domains/realms?

2012-04-16 Thread Dmitri Pal
On 04/13/2012 03:23 AM, Christoph Kaminski wrote: Hi I have multiple domains her but I want to use one user/group etc. database. How can I do it? Options: 1. Different realm for each domain, but how to share the user/group etc infos betwen different ipa servers? 2. One realm for al domains.

Re: [Freeipa-users] routing requests to local servers - DNS SRV + view?

2012-04-16 Thread Dmitri Pal
On 04/16/2012 09:46 AM, Jakub Hrozek wrote: On Mon, Apr 16, 2012 at 09:40:16AM -0400, Dmitri Pal wrote: On 04/13/2012 11:00 PM, Brian Cook wrote: Yes, this is exactly what I am trying to accomplish. I've already been looking in to the BIND views clause and would like to hear if

Re: [Freeipa-users] Unable to login where previously OK

2012-04-16 Thread Jakub Hrozek
On Thu, Apr 12, 2012 at 09:23:03PM +, Steven Jones wrote: sssd log at lvl6 regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 Which SSSD version is this? Are the clients that work OK the same version? Can you also

[Freeipa-users] Disaster Recovery Best Practices?

2012-04-16 Thread KodaK
Hi, I have googled around a bit, but I still have a couple of questions: 1) is it possible to get getent shadow to return shadow entries from the ipa server? This is so we can do a DR test on some server or set of servers without also having to restore the IPA server first. I can do a getent

Re: [Freeipa-users] Disaster Recovery Best Practices?

2012-04-16 Thread Dmitri Pal
On 04/16/2012 03:13 PM, KodaK wrote: Hi, I have googled around a bit, but I still have a couple of questions: 1) is it possible to get getent shadow to return shadow entries from the ipa server? This is so we can do a DR test on some server or set of servers without also having to restore

Re: [Freeipa-users] Disaster Recovery Best Practices?

2012-04-16 Thread Simo Sorce
On Mon, 2012-04-16 at 14:13 -0500, KodaK wrote: Hi, I have googled around a bit, but I still have a couple of questions: 1) is it possible to get getent shadow to return shadow entries from the ipa server? No, we do not have any shadow map in ipa, enforcement of password and account

Re: [Freeipa-users] Screensaver unlock with expired password

2012-04-16 Thread Sigbjorn Lie
On 04/16/2012 03:33 PM, Dmitri Pal wrote: On 04/14/2012 08:20 AM, Sigbjorn Lie wrote: Hi, I ran into a issue with unlocking the screensaver when an users password has expired. These results are from RHEL 5. When running KDE and unlocking a screensaver with an expired password, an error

Re: [Freeipa-users] Screensaver unlock with expired password

2012-04-16 Thread Nalin Dahyabhai
On Mon, Apr 16, 2012 at 11:17:35PM +0200, Sigbjorn Lie wrote: The clients use nss_ldap+pam_krb5, SSSD was crashing for us on RHEL 5. The server is the IPA server provided in RHEL 6.2. When I check the logs on the client it states that authentication succeeded, and that the password has

[Freeipa-users] Problem creating replica file

2012-04-16 Thread Jorge Argibay Molina
Hi, I'm in the testing phase of the deployment of FreeIPA in my network. So far I've been able to configure the server, and several clients. What I've been unable to do, and seems very easy going thru the documentation, is generate the replica. Whenever I do: ipa-replica-prepare

Re: [Freeipa-users] Problem creating replica file

2012-04-16 Thread Dmitri Pal
On 04/16/2012 05:14 PM, Jorge Argibay Molina wrote: Hi, I'm in the testing phase of the deployment of FreeIPA in my network. So far I've been able to configure the server, and several clients. What I've been unable to do, and seems very easy going thru the documentation, is generate the