Re: [Freeipa-users] RHEL 7 Upgrade experience so far

2014-08-28 Thread Nicklas Björk
I have been following this thread with great interest, as I have encountered similar problems with our migration from 3.0.0-37 on CentOS 6.5 to 3.3.3-28 on CentOS 7. I have been able to solve a few of them with manual patching, but there is still something going on that will make the CA

[Freeipa-users] ipa-server (v3.3.3) with sssd (v1.11.2) config

2014-08-28 Thread Gerardo Padierna
Hi, In a setup where FreeIPA + sssd act as an authentication for AD users (taking advantage of sssd's ability to act as an authentication client for AD users), why do we need to establish a (two-way) trust relationship? Ins't there a workaround for this, given that sssd is already able to

Re: [Freeipa-users] ipa-server (v3.3.3) with sssd (v1.11.2) config

2014-08-28 Thread Dmitri Pal
On 08/28/2014 12:08 PM, Gerardo Padierna wrote: Hi, In a setup where FreeIPA + sssd act as an authentication for AD users (taking advantage of sssd's ability to act as an authentication client for AD users), why do we need to establish a (two-way) trust relationship? Ins't there a

[Freeipa-users] How to use sudo rules on ubuntu

2014-08-28 Thread Tevfik Ceydeliler
Hi, I try to apply sudo policies on ubuntu client. Is there any examples how to apply it? Regards... -- br img src=http://www.yasar.com.tr/banner/yhbanner.jpg; /img brbr Bu elektronik postada bulunan tum fikir ve gorusler ve ekindeki dosyalar sadece adres sahip/sahiplerine ait olup, Yasar

Re: [Freeipa-users] How to use sudo rules on ubuntu

2014-08-28 Thread Jakub Hrozek
On Thu, Aug 28, 2014 at 02:15:43PM +0300, Tevfik Ceydeliler wrote: Hi, I try to apply sudo policies on ubuntu client. Is there any examples how to apply it? Regards... Depends on your sssd and sudo versions but in general I don't think there are any Ubuntu-specific issues. As long as you

[Freeipa-users] Password expiration dates are different when being resetted by the (primary) admin and a different admin

2014-08-28 Thread Zip Ly
Hi, I'm trying to change a user password without reset. If I use the (primary) admin to change the password then it doesn't need a password reset, because the expire lifetime is 90 days. But if I create a second admin, then every password change made by the second admin needs a password reset,

Re: [Freeipa-users] Password expiration dates are different when being resetted by the (primary) admin and a different admin

2014-08-28 Thread Martin Kosek
On 08/28/2014 04:18 PM, Zip Ly wrote: Hi, I'm trying to change a user password without reset. If I use the (primary) admin to change the password then it doesn't need a password reset, because the expire lifetime is 90 days. This is strange. Did you by any chance added this admin's

Re: [Freeipa-users] Password expiration dates are different when being resetted by the (primary) admin and a different admin

2014-08-28 Thread Will Sheldon
1a) has come up before: https://www.redhat.com/archives/freeipa-users/2014-February/msg00313.html 1b) We handled this by setting the expire lifetime to a very large value (20 years) for members of a certain group. 2) I’m not sure. Kind regards, Will Sheldon +1.778-689-1244 On August 28,

[Freeipa-users] Disable Password Policy?

2014-08-28 Thread Chris Whittle
We are going to use a SSO provider like OneLogin to enforce a password policy how can we disable FreeIPA from doing it also? -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project

Re: [Freeipa-users] Disable Password Policy?

2014-08-28 Thread Dmitri Pal
On 08/28/2014 04:56 PM, Chris Whittle wrote: We are going to use a SSO provider like OneLogin to enforce a password policy how can we disable FreeIPA from doing it also? I do not think you can. You can make IPA policy less restrictive then it would just not apply. -- Thank you, Dmitri Pal

Re: [Freeipa-users] Password expiration dates are different when being resetted by the (primary) admin and a different admin

2014-08-28 Thread Dmitri Pal
On 08/28/2014 04:18 PM, Zip Ly wrote: Hi, I'm trying to change a user password without reset. If I use the (primary) admin to change the password then it doesn't need a password reset, because the expire lifetime is 90 days. But if I create a second admin, then every password change made by the