Re: [Freeipa-users] Account Expiration

2013-02-13 Thread Petr Spacek
On 12.2.2013 20:21, John Dennis wrote: On 02/12/2013 01:40 PM, Rob Crittenden wrote: Is it possible to ipa to send a email to user when his account is about to expire (the current date is near krbprincipalexpiration date) ? Not currently. In 3.0+ we will provide a notice when one logs into

[Freeipa-users] Announcing FreeIPA 2.2.2

2013-02-13 Thread Martin Kosek
The FreeIPA team is proud to announce version FreeIPA v2.2.2 This release contains Security Updates. It can be downloaded from http://www.freeipa.org/page/Downloads. A build is currently on the way to updates-testing for Fedora 17. == Highlights == This release contains a Security Advisory:

Re: [Freeipa-users] Restricting other User's Details to be visible to a user

2013-02-13 Thread Petr Spacek
On 13.2.2013 11:38, Rajnesh Kumar Siwal wrote: It has been found that any user can see the details of other users through the IPA Web Interface (even ldapsearch with anonymous user). It would be great if we could hide the details of the other users from the current user (including emai, phone

Re: [Freeipa-users] Restricting other User's Details to be visible to a user

2013-02-13 Thread Rajnesh Kumar Siwal
Yes. We would still like to restrict the Visibility of the users. We could implement the ACL's in 389-ds. However, I was concerned whether it breaks the IPA. -- Regards, Rajnesh Kumar Siwal ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread James James
It's a good idea. I will try that. 2013/2/13 Petr Spacek pspa...@redhat.com On 12.2.2013 20:21, John Dennis wrote: On 02/12/2013 01:40 PM, Rob Crittenden wrote: Is it possible to ipa to send a email to user when his account is about to expire (the current date is near

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread Rob Crittenden
Petr Spacek wrote: On 12.2.2013 20:21, John Dennis wrote: On 02/12/2013 01:40 PM, Rob Crittenden wrote: Is it possible to ipa to send a email to user when his account is about to expire (the current date is near krbprincipalexpiration date) ? Not currently. In 3.0+ we will provide a notice

Re: [Freeipa-users] Restricting other User's Details to be visible to a user

2013-02-13 Thread Rob Crittenden
Rajnesh Kumar Siwal wrote: Yes. We would still like to restrict the Visibility of the users. We could implement the ACL's in 389-ds. However, I was concerned whether it breaks the IPA. To disable anonymous you need to set nsslapd-allow-anonymous-access to off in cn=config (bind as Directory

Re: [Freeipa-users] Python Client

2013-02-13 Thread Dmitri Pal
On 02/13/2013 12:47 AM, It Meme wrote: Thank you for your reply. Could there be anyway that accounts can be provisioned to IPA, via LDAP, from existing IAM system? The newly provisioned accounts can be temporarily stored in IPA's 389 Directory Server, and subsequently an automated task can

Re: [Freeipa-users] Python Client

2013-02-13 Thread Rob Crittenden
It Meme wrote: Thank you for your reply. Could there be anyway that accounts can be provisioned to IPA, via LDAP, from existing IAM system? The newly provisioned accounts can be temporarily stored in IPA's 389 Directory Server, and subsequently an automated task can IPA-ize the accounts (i.e.

[Freeipa-users] FreeIPA installation bug on F18 while requesting RA certificate from CA

2013-02-13 Thread Robert M. Albrecht
Hi, Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to start on boot [4/4]: starting ntpd Done configuring NTP daemon (ntpd). Configuring directory server (dirsrv): Estimated time 1 minute [1/36]: creating directory server user

Re: [Freeipa-users] FreeIPA installation bug on F18 while requesting RA certificate from CA

2013-02-13 Thread Rob Crittenden
Robert M. Albrecht wrote: Hi, Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to start on boot [4/4]: starting ntpd Done configuring NTP daemon (ntpd). Configuring directory server (dirsrv): Estimated time 1 minute [1/36]:

[Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Dag Wieers
Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be limited to a subset. Since we would like to only synchronize

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Rob Crittenden
Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be limited to a subset. Since we would like to only

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Rich Megginson
On 02/13/2013 08:10 AM, Rob Crittenden wrote: Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Steven Jones
Hi, You can specify a --winsubtree, provided all the users you want are in that, I think that will work. For filters, Ive suggested that, we have so much garbage in our AD that its cluttering IPA badly. eg we have hundred templates, so I'd like to block those from being transferred. regards

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread Steven Jones
Hi, Isnt Postfix the RHEL default now? So is it that hard to do a Postfix-ipa-config.rpm? Its something we want as well, so I'll do a RFE, RH support will love me more I'm sure ;] regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463

Re: [Freeipa-users] FreeIPA installation bug on F18 while requesting RA certificate from CA

2013-02-13 Thread Robert M. Albrecht
Hi Rob, yes, worked after downgrading nss* and xulrunner firefox because of deps. Thanks. cu romal Am 13.02.13 15:48, schrieb Rob Crittenden: Robert M. Albrecht wrote: Hi, Configuring NTP daemon (ntpd) [1/4]: stopping ntpd [2/4]: writing configuration [3/4]: configuring ntpd to

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread James James
What is the IIRC docs ? 2013/2/13 Rob Crittenden rcrit...@redhat.com Petr Spacek wrote: On 12.2.2013 20:21, John Dennis wrote: On 02/12/2013 01:40 PM, Rob Crittenden wrote: Is it possible to ipa to send a email to user when his account is about to expire (the current date is near

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread James James
thanks for your code. :) 2013/2/13 Jan-Frode Myklebust janfr...@tanso.net On Wed, Feb 13, 2013 at 09:29:42AM +0100, Petr Spacek wrote: Yeah, I don't think we want to be in the business of installing and configuring an MTA. However, we should be able to detect if one is available and

Re: [Freeipa-users] Account Expiration

2013-02-13 Thread Rob Crittenden
James James wrote: What is the IIRC docs ? IIRC == If I Recall Correctly. https://access.redhat.com/knowledge/docs/en-US/Red_Hat_Enterprise_Linux/6-Beta/html-single/Identity_Management_Guide/index.html#pwd-expiration rob 2013/2/13 Rob Crittenden rcrit...@redhat.com

Re: [Freeipa-users] Unable to enrol servers with principal

2013-02-13 Thread Charlie Derwent
On Sun, Feb 10, 2013 at 1:48 AM, Rob Crittenden rcrit...@redhat.com wrote: Charlie Derwent wrote: Hi Whenever I attempt an unattended installation with a principal and password. The installation fails. I'm using the following syntax for my command ipa-client-install --domain=example.com

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Dmitri Pal
On 02/13/2013 09:58 AM, Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be limited to a subset.

Re: [Freeipa-users] Unable to enrol servers with principal

2013-02-13 Thread Dmitri Pal
On 02/13/2013 04:57 PM, Charlie Derwent wrote: On Sun, Feb 10, 2013 at 1:48 AM, Rob Crittenden rcrit...@redhat.com mailto:rcrit...@redhat.com wrote: Charlie Derwent wrote: Hi Whenever I attempt an unattended installation with a principal and password. The

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Steven Jones
Hi, However trusts open a whole nest of vipers... The advantage of using winsync is you can control what happens in IPA, so if AD say gets hacked anything in IPA probably will survive. The reverse is of course also true ;] regards Steven Jones Technical Specialist - Linux RHCE