Re: [Freeipa-users] Replication problems with having more than one replica?

2012-06-14 Thread Steven Jones
I have the forward zone (ods.vuw.ac.nz) setup in IPA but the reverse zone(s) is meant to be slaved back to the MS AD masters (vuw.ac.nz) and 10/8 and (130.195./16). What should the reverse/ PTR zone setup look like? ie if I had a flat file aka bind and named.conf its straightforward I can just

Re: [Freeipa-users] groups migration

2012-06-14 Thread Simo Sorce
On Thu, 2012-06-14 at 15:34 +0200, Maciej Sawicki wrote: > bump > > On Mon, Jun 11, 2012 at 2:11 PM, Maciej Sawicki > wrote: > > Hi, > > I (almost) managed to migrate groups from my previous server. That is > > groups names migrated perfectly, unfortunately when I login to web > > panel all group

Re: [Freeipa-users] Password pass-through to an existing LDAP server?

2012-06-14 Thread Simo Sorce
On Thu, 2012-06-14 at 09:54 -0400, Jason Riedy wrote: > And Dmitri Pal writes: > > Can you explain what is the reason of having local accounts > > other than system ones? > > Sorry, I didn't explain well enough. I mean local to the > *subnet*, not the host. I don't want them in /etc/passwd. > No

Re: [Freeipa-users] eJabberd authentication with FreeIPA via LDAP with Group member validation

2012-06-14 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 14/06/12 18:24, Natxo Asenjo wrote: > On Thu, Jun 14, 2012 at 12:54 PM, Dale Macartney mailto:d...@themacartneyclan.com>> wrote: > > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I've just placed another wiki article for adding Jabber serv

Re: [Freeipa-users] eJabberd authentication with FreeIPA via LDAP with Group member validation

2012-06-14 Thread Natxo Asenjo
On Thu, Jun 14, 2012 at 12:54 PM, Dale Macartney wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I've just placed another wiki article for adding Jabber services to IPA. > This is a work in progress as I'm aiming for SSO ability, but thought > someone might find it useful in the int

Re: [Freeipa-users] Password pass-through to an existing LDAP server?

2012-06-14 Thread Jason Riedy
And Dmitri Pal writes: > Can you explain what is the reason of having local accounts > other than system ones? Sorry, I didn't explain well enough. I mean local to the *subnet*, not the host. I don't want them in /etc/passwd. Nor do I want all global users defined by default, although that's les

Re: [Freeipa-users] groups migration

2012-06-14 Thread Maciej Sawicki
bump On Mon, Jun 11, 2012 at 2:11 PM, Maciej Sawicki wrote: > Hi, > I (almost) managed to migrate groups from my previous server. That is > groups names migrated perfectly, unfortunately when I login to web > panel all groups are empty. > > I used following command: > ipa migrate-ds ldap://192.16

Re: [Freeipa-users] Replication problems with having more than one replica?

2012-06-14 Thread Simo Sorce
On Thu, 2012-06-14 at 03:00 +, Steven Jones wrote: > Hi, > > 3 log sets from /var/log/dirsrv/slapd Looking at the first server's error log it looks like one of your replicas has a wrong PTR record and GSSAPI cannot therefore find the right ticket. Make sure your DNS is properly set up (or /e

[Freeipa-users] eJabberd authentication with FreeIPA via LDAP with Group member validation

2012-06-14 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Morning all I have to say I am a little disappointed with myself to be honest as I thought I published this a while ago. I've just placed another wiki article for adding Jabber services to IPA. This is a work in progress as I'm aiming for SSO abilit