Re: [Freeipa-users] C5 freeipa clients?

2012-12-28 Thread Rob Crittenden
Nate Marks wrote: I have a freeipa server and some clients (Centos 6.3) that work great. My experience with CentOS 5 has been less positive. The freeipa-client package in the Centos Base doesn't seem to work with my server (server package versions below). i've tried downloading and building

Re: [Freeipa-users] getent netgroup users doesn't work on centos 6, but works on centos 5

2012-12-28 Thread Rob Crittenden
David Copperfield wrote: Hi howdy, I've migrated some NIS netgroups from my old openLDAP to IPA 2.2.0, it imported all the old data without prompting problems. But now the issues are at the client side: redhat 5.8 clients can see all host netgroups and user netgroups without problems.

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-28 Thread Johan Petersson
Hi, I am getting these messages in my log when setting all instances of pam_krb5.so.1 debug in /etc/pam.d/other, /etc/pam.d/login: Dec 28 12:59:12 solaris.example.com su: [ID 737709 auth.error] unable to open connection to ADMIN server (t_error 13) Dec 28 12:59:12 solaris2.example.com su: [ID

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-28 Thread Johan Petersson
Forgot to add the ports opened in my last message. :) 22 TCP 80 TCP 443 TCP 389 TCP 636 TCP 7389 TCP 88 TCP,UDP 464 TCP,UDP 53 TCP,UDP 123 TCP,UDP 111 TCP,UDP 2049 TCP,UDP Also tried 749,750 and everything kerberos related from Solaris /etc/services. Solaris.example.com and solaris2.example.com

Re: [Freeipa-users] delegation questions: how to reset password for subordinate?

2012-12-28 Thread Simo Sorce
On Wed, 2012-12-26 at 15:57 -0800, David Copperfield wrote: Hi all, What are the user attributes that A manager should be granted with readwrite permissions to reset passwords for subordinate employees? The typical implementation case: managers need to take care of password reset

Re: [Freeipa-users] Joining Fedora 18 (FreeIPA 3.1.0) to CentOS 6.3 (FreeIPA 2.1.90rc1)

2012-12-28 Thread Simo Sorce
On Thu, 2012-12-27 at 10:11 -0500, Michael B. Trausch wrote: On 12/26/2012 10:23 AM, Simo Sorce wrote: It's missing the sasl library's debug info. Could you install cyrus-sasl-debuginfo and regenerate the stack trace from the core file ? I do not have a centos box handy. Done;

Re: [Freeipa-users] Does Solaris 11 work as client to IPA server?

2012-12-28 Thread Sigbjorn Lie
How about enabling the firewall, and use tcpdump on the ipa server or snoop on the Solaris box to see where it stops and waits? Rgds Siggi Johan Petersson johan.peters...@sscspace.com wrote: Forgot to add the ports opened in my last message. :) 22 TCP 80 TCP 443 TCP 389 TCP 636 TCP 7389 TCP

Re: [Freeipa-users] Joining Fedora 18 (FreeIPA 3.1.0) to CentOS 6.3 (FreeIPA 2.1.90rc1)

2012-12-28 Thread Michael B. Trausch
On 12/28/2012 08:56 AM, Simo Sorce wrote: However re-reading the ticket made me wonder. Is this happening on the F18 machine or on the Centos 6.3 machine ? The sigsegv is happening on the Fedora 18 box, the one running FreeIPA 3.1.0. I am completely unable to install debug symbols for the

Re: [Freeipa-users] delegation questions: how to reset password for subordinate?

2012-12-28 Thread David Copperfield
Hi Simo,  That works perfectly. Thanks a lot. --David From: Simo Sorce s...@redhat.com To: David Copperfield cao2...@yahoo.com Cc: freeipa-users@redhat.com freeipa-users@redhat.com Sent: Friday, December 28, 2012 5:51 AM Subject: Re: [Freeipa-users]

[Freeipa-users] replication procedure and status check?

2012-12-28 Thread David Copperfield
Hi howdy,  Is there a nagios check for replication check among IPA servers and replicas? If not, is there a way to test the replica status through some files or underlying LDAP command outputs? I have one test environment with a IPA server on a Vmware instance, two IPA replicas created from