Re: [Freeipa-users] Do clients have to be in teh same DNS zone / FQDN as the IPA servers / Kerberos Realm?

2012-06-21 Thread James Hogarth
but Im getting hammered by my management for instant answers...they asked last night and expect an answer this morning.and I'm expected to catch up and deploy several important solutions/projects all hinging on IPA ASAP... 2.2 isnt in RHEL6.3 though? Are you using fedora, centos

[Freeipa-users] Joining realm failed: Host is already joined

2012-06-21 Thread george he
Hello all, When I do ipa-client-install on a client with previous unsuccessful installation, I get this error message: Joining realm failed: Host is already joined. Installation failed. Rolling back changes. IPA client is not configured on this system. How do I clean up the machine for a

Re: [Freeipa-users] groups migration

2012-06-21 Thread Maciej Sawicki
On Tue, Jun 19, 2012 at 3:19 PM, Rob Crittenden rcrit...@redhat.com wrote: Pass in --schema=RFC2307 to the migrate-ds command to migrate these groups. Thank you Rob. I tried this option and it didn't helped, my groups in ipa are steel empty :(. regards, Maciej Sawicki

Re: [Freeipa-users] Joining realm failed: Host is already joined

2012-06-21 Thread george he
Hello Rob, Here is what I get by running the commands: # klist -kt /etc/krb5.keytab Keytab name: FILE:/etc/krb5.keytab KVNO Timestamp Principal - # ipa-rmkeytab -k /etc/krb5.keytab -r MYREALM realm not found #

[Freeipa-users] ipa user-add

2012-06-21 Thread george he
Hello all, After the server and the client are installed, I run ipa user-add myname to add users. The users are added successfully, but each user get his own GID, which is the same as his UID, even though ipa config-show --all shows   Default users group: ipausers How do I put all new

Re: [Freeipa-users] groups migration

2012-06-21 Thread Rob Crittenden
Maciej Sawicki wrote: On Tue, Jun 19, 2012 at 3:19 PM, Rob Crittendenrcrit...@redhat.com wrote: Pass in --schema=RFC2307 to the migrate-ds command to migrate these groups. Thank you Rob. I tried this option and it didn't helped, my groups in ipa are steel empty :(. regards, Maciej Sawicki

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread Rob Crittenden
Rich Megginson wrote: On 06/21/2012 12:25 PM, george he wrote: Hello all, After the server and the client are installed, I run ipa user-add myname to add users. The users are added successfully, but each user get his own GID, which is the same as his UID, even though ipa config-show --all

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread george he
it's x86_64  2.2.0-1.fc17. Thanks, George From: Rob Crittenden rcrit...@redhat.com To: Rich Megginson rmegg...@redhat.com Cc: george he george_...@yahoo.com; freeipa-users@redhat.com freeipa-users@redhat.com Sent: Thursday, June 21, 2012 2:54 PM Subject:

Re: [Freeipa-users] Joining realm failed: Host is already joined

2012-06-21 Thread Dmitri Pal
On 06/21/2012 11:43 AM, george he wrote: Hello Rob, Here is what I get by running the commands: # klist -kt /etc/krb5.keytab Keytab name: FILE:/etc/krb5.keytab KVNO Timestamp Principal - # ipa-rmkeytab

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread Dmitri Pal
On 06/21/2012 03:10 PM, george he wrote: it's x86_64 2.2.0-1.fc17. Thanks, George You are looking at the private group feature. By default IPA encorages you to take advantage of the user private groups - the groups that have only current user in them. The value of this is that the files on

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread george he
Hello Dmitri, OK, I can accept the good practice of using private groups, then I need to delete the left over group. The instructions in the document failed as stated in my original email. Any suggestions how to delete the private group whose user has been deleted? Thanks, George

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread Rob Crittenden
george he wrote: Hello Dmitri, OK, I can accept the good practice of using private groups, then I need to delete the left over group. The instructions in the document failed as stated in my original email. Any suggestions how to delete the private group whose user has been deleted? You first

[Freeipa-users] replica installation clean up

2012-06-21 Thread george he
Hi, after ipa-replica-install and ipa-replica-install --uninstall, now I get [root@myreplica ~]# ipa-replica-install --setup-ca /var/lib/ipa/replica-info.gpg . . . Connection check OK The host myreplica already exists on the master server. Depending on your configuration, you may perform the

Re: [Freeipa-users] replica installation clean up

2012-06-21 Thread Rob Crittenden
george he wrote: Hi, after ipa-replica-install and ipa-replica-install --uninstall, now I get [root@myreplica ~]# ipa-replica-install --setup-ca /var/lib/ipa/replica-info.gpg . . . Connection check OK The host myreplica already exists on the master server. Depending on your configuration, you

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread Rich Megginson
On 06/21/2012 01:10 PM, george he wrote: it's x86_64 2.2.0-1.fc17. rpm -qi 389-ds-base Thanks, George *From:* Rob Crittenden rcrit...@redhat.com *To:* Rich Megginson rmegg...@redhat.com *Cc:* george he

[Freeipa-users] Add attributes to default user schema

2012-06-21 Thread James James
Hi everybody, Is it possible to have a procedure to add new attributes like mailAlternateAddress in the default user schema ? Regards ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Add attributes to default user schema

2012-06-21 Thread Dmitri Pal
On 06/21/2012 05:06 PM, James James wrote: Hi everybody, Is it possible to have a procedure to add new attributes like mailAlternateAddress in the default user schema ? Any specific reason for this specific attribute. See some old DS discussion here

Re: [Freeipa-users] Add attributes to default user schema

2012-06-21 Thread Stephen Ingram
On Thu, Jun 21, 2012 at 2:06 PM, James James jre...@gmail.com wrote: Hi everybody, Is it possible to have a procedure to add new attributes like mailAlternateAddress in the default user schema ? That particular attribute is included in the schema (objectclass=mailRecipient) so it is easy to

Re: [Freeipa-users] Add attributes to default user schema

2012-06-21 Thread Dmitri Pal
On 06/21/2012 05:44 PM, Stephen Ingram wrote: On Thu, Jun 21, 2012 at 2:06 PM, James James jre...@gmail.com wrote: Hi everybody, Is it possible to have a procedure to add new attributes like mailAlternateAddress in the default user schema ? That particular attribute is included in the

Re: [Freeipa-users] replica installation clean up

2012-06-21 Thread george he
Hello, I used --force to delete myreplica from mymaster. And then runipa-replica-install on the myreplica again. This time everything seems ok until it comes to the end: Applying LDAP updates Restarting the directory server Restarting the KDC Restarting the web server creation of replica

Re: [Freeipa-users] ipa user-add

2012-06-21 Thread george he
Hello Rich, Thanks for the help. This does remove the group so I can add the user back. But when I try to ssh, as that user, to the machines that the user logged on before ipa user-del, I get permission denied. I removed the user's home directory because it still belongs to the deleted UID:GID.