Re: [Freeipa-users] ipa-client-install fails on replica because of kinit cannot contact any KDC

2014-03-28 Thread Shree
Martin First of all thank you so much for your detailed analysis. I got a chance to finally take a look at it today. I tried your suggested changes to the /etc/krb5.conf and I now get the following response. [root@www ~]# kinit kinit: Cannot contact any KDC for realm 'MYDOMAIN.COM' while getting

Re: [Freeipa-users] change min and max lifetime of random password

2014-03-28 Thread Dmitri Pal
On 03/27/2014 11:33 PM, barry...@gmail.com wrote: Found a error today. when browse the cert serices ..is it realte to dog tag system ...how to restart ? Certificate operation cannot be completed: Unable to communicate with CMS (Not Found) ipactrl stop ipactrl start -- Thank you, Dmitri Pal Sr

Re: [Freeipa-users] Certificate Woes

2014-03-28 Thread Rob Crittenden
Matt Chesler wrote: Hi all, Our IPA instance started acting strangely earlier today. I restarted the IPA service on the primary node and things seemed to return to normal. Over the course of the day, we decided to add a third IPA server to our environment. When I attempted to perform the ipa-

[Freeipa-users] Certificate Woes

2014-03-28 Thread Matt Chesler
Hi all, Our IPA instance started acting strangely earlier today. I restarted the IPA service on the primary node and things seemed to return to normal. Over the course of the day, we decided to add a third IPA server to our environment. When I attempted to perform the ipa-replica-prepare, I rec

[Freeipa-users] Announcing FreeIPA 3.3.5

2014-03-28 Thread Martin Kosek
The FreeIPA team is proud to announce FreeIPA v3.3.5! It can be downloaded from http://www.freeipa.org/page/Downloads. Fedora 19 and Fedora 20 builds are already on their way to updates-testing repo. == Highlights in 3.3.5 == === Enhancements === * DNS classless support for reverse domains === B

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-28 Thread Alexander Bokovoy
On Fri, 28 Mar 2014, Genadi Postrilko wrote: Thank you for the answer. Is the communication between IPA Client and Server HTTPS based? not just SSL over TCP? Depends on the protocol being used. You really need to go and look per protocol. For example: HTTPS is used only when you are using IPA

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa: building ipasam.so on Ubuntu

2014-03-28 Thread Alexander Bokovoy
On Fri, 28 Mar 2014, Jason Woods wrote: Hi (Apologies - resending to the list - I'm so used to the Reply-To already set but it appears not to be here my bad.) On 28 Mar 2014, at 11:32, Petr Spacek wrote: Please let us know if it worked for you or not. I'm curious! :-) I'm pretty curious to

Re: [Freeipa-users] Any coomand can extract the private of the freeipa domain

2014-03-28 Thread Rob Crittenden
barry...@gmail.com wrote: i want to extract the private key of the self sign cert The CA's database is in either /var/lib/pki/pki-tomcat/alias or /var/lib/pki-ca/alias depending on your version and distro. I would not recommend doing anything with it directly. rob _

Re: [Freeipa-users] Understanding role of the certificate in client - server communication.

2014-03-28 Thread Genadi Postrilko
Thank you for the answer. Is the communication between IPA Client and Server HTTPS based? not just SSL over TCP? So is Kerberos? Does it have to be over HTTP? or its purely over TCP/UDP? 2014-03-19 10:56 GMT+02:00 Alexander Bokovoy : > On Wed, 19 Mar 2014, Genadi Postrilko wrote: > >> Thank you

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa: building ipasam.so on Ubuntu

2014-03-28 Thread Jason Woods
Hi (Apologies - resending to the list - I'm so used to the Reply-To already set but it appears not to be here my bad.) > On 28 Mar 2014, at 11:32, Petr Spacek wrote: > > Please let us know if it worked for you or not. I'm curious! :-) I'm pretty curious too. I have RHEL 6.5 with samba authent

Re: [Freeipa-users] cant authenticate using freeipa userid on ubuntu12.04

2014-03-28 Thread Rob Crittenden
Sabin Ranjit wrote: hi, i followed this page for the installation of freeipa client over the ubuntu 12.04 server. http://www.redhat.com/archives/freeipa-users/2013-June/msg00091.html everything seem to go as mentioned in the page. when i get at the freeipa server with the command ipa host-find i

[Freeipa-users] cant authenticate using freeipa userid on ubuntu12.04

2014-03-28 Thread Sabin Ranjit
hi, i followed this page for the installation of freeipa client over the ubuntu 12.04 server. http://www.redhat.com/archives/freeipa-users/2013-June/msg00091.html everything seem to go as mentioned in the page. when i get at the freeipa server with the command ipa host-find i can even see my u

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa: building ipasam.so on Ubuntu

2014-03-28 Thread Petr Spacek
On 28.3.2014 12:32, Petr Spacek wrote: On 28.3.2014 09:56, Sandor Juhasz wrote: Hello, i am ok to compile it myself, looking for source code. I hope that way i will be able to avoid messing around with the ldap tree. Any help/documentation is appreciated. Basically, documentation on http://ww

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa: building ipasam.so on Ubuntu

2014-03-28 Thread Petr Spacek
On 28.3.2014 09:56, Sandor Juhasz wrote: Hello, i am ok to compile it myself, looking for source code. I hope that way i will be able to avoid messing around with the ldap tree. Any help/documentation is appreciated. Basically, documentation on http://www.freeipa.org/page/Contribute/Code and

Re: [Freeipa-users] authenticate samba 3 or 4 with freeipa

2014-03-28 Thread Sandor Juhasz
Hello, i am ok to compile it myself, looking for source code. I hope that way i will be able to avoid messing around with the ldap tree. Any help/documentation is appreciated. Thanks. s - Original Message - From: "Petr Spacek" To: freeipa-users@redhat.com Sent: Thursday, Marc