Re: [Freeipa-users] vsftpd PAM setup problem

2014-10-30 Thread Thomas Lau
Thanks, all good now. On Fri, Oct 31, 2014 at 1:40 PM, Alexander Bokovoy wrote: > On Fri, 31 Oct 2014, Thomas Lau wrote: > >> Hi All, >> >> I am using vsftpd and auth against PAM (eventually to sss), but I can't >> login even using admin account, anyone could provide some hints on how to >> make

Re: [Freeipa-users] vsftpd PAM setup problem

2014-10-30 Thread Alexander Bokovoy
On Fri, 31 Oct 2014, Thomas Lau wrote: Hi All, I am using vsftpd and auth against PAM (eventually to sss), but I can't login even using admin account, anyone could provide some hints on how to make it work? here is the detail log on sssd_us.domain.com.log: You need to fix permissions of /tmp:

[Freeipa-users] Centos IPA Client fails after upgrade to 6.6

2014-10-30 Thread David Taylor
I just recently updated one of our test servers from CentOS 6.5 to CentOS 6.6, after which I noticed that IPA logons were no longer available. From what I can see the upgrade includes quite a few changes with regard to sssd. - NTP is up and synced on the Auth servers and the client. -

Re: [Freeipa-users] IPA Server 4.* error on Centos7

2014-10-30 Thread Dmitri Pal
On 10/30/2014 12:45 PM, Lucas Diedrich wrote: Hello for all, I'm trying to install the IPA Server version 4.* on CentOS 7 using the EPEL 7 and the MKOSEK FreeIPA Repo (for 4.* version). But this is giving me a package dependency error. After a search i found this Thread (https://www.redhat.

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-30 Thread Martin Basti
On 30/10/14 19:18, Michael Lasevich wrote: Makes sense. What is the solution here? I have the latest 389-ds installed but still getting "allowWeakCipher" error - how to I get around that? -M Sorry I don't know, I CCied Ludwig, he is DS guru. Martin^2 On 10/30/14, 11:12 AM, Martin Basti w

Re: [Freeipa-users] Woes adding a samba server to the ipa domain

2014-10-30 Thread Dmitri Pal
On 10/29/2014 11:38 PM, Loris Santamaria wrote: El mié, 29-10-2014 a las 20:49 -0400, Dmitri Pal escribió: On 10/29/2014 05:01 PM, Loris Santamaria wrote: El mié, 29-10-2014 a las 21:40 +0100, John Obaterspok escribió: Hello, I've tried this as well. My IPA is not connected to an AD. My smb

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-30 Thread Michael Lasevich
Makes sense. What is the solution here? I have the latest 389-ds installed but still getting "allowWeakCipher" error - how to I get around that? -M On 10/30/14, 11:12 AM, Martin Basti wrote: > On 24/10/14 05:17, Michael Lasevich wrote: >> While upgrading from 4.0.1. to 4.1 on fedora 20 got foll

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-30 Thread Martin Basti
On 24/10/14 05:17, Michael Lasevich wrote: While upgrading from 4.0.1. to 4.1 on fedora 20 got following on one of the two boxes: Upgrade failed with attribute "allowWeakCipher" not allowed IPA upgrade failed. Unexpected error DuplicateEntry: This entry already exists Named errors are caused

Re: [Freeipa-users] F20 Problem upgrading to 4.1

2014-10-30 Thread Michael Lasevich
*sigh* Feel like I am going around in circles "ipa-ldap-updater --upgrade" failed with: "Upgrade failed with attribute "allowWeakCipher" not allowed" I am running 1.3.3 from mkosek-freeipa copr: 389-ds-base-libs-1.3.3.5-1.fc20.x86_64 389-ds-base-1.3.3.5-1.fc20.x86_64 yum info 389-ds-base Loa

[Freeipa-users] IPA Server 4.* error on Centos7

2014-10-30 Thread Lucas Diedrich
Hello for all, I'm trying to install the IPA Server version 4.* on CentOS 7 using the EPEL 7 and the MKOSEK FreeIPA Repo (for 4.* version). But this is giving me a package dependency error. After a search i found this Thread ( https://www.redhat.com/archives/freeipa-users/2014-October/msg00200.ht

Re: [Freeipa-users] adding replication agreements

2014-10-30 Thread Rob Crittenden
Shashi Dahal wrote: > Hi, > > I have ipa master server: A > and I have 2 ipa replicas: B and C > > > replica B crashed, so it was deleted from A and recreated using > ipa-replica-parepare to generate the file and set it up from there. > > > in server A B and C, if I do ipa-replica-manage l

Re: [Freeipa-users] Errors upgrading 4.0.1 to 4.1

2014-10-30 Thread Ludwig Krispenz
On 10/24/2014 09:44 AM, Martin Kosek wrote: On 10/24/2014 05:17 AM, Michael Lasevich wrote: While upgrading from 4.0.1. to 4.1 on fedora 20 got following on one of the two boxes: Upgrade failed with attribute "allowWeakCipher" not allowed IPA upgrade failed. Unexpected error DuplicateEntry: T

[Freeipa-users] adding trust relationships

2014-10-30 Thread Shashi Dahal
Hi, I have ipa master server: A and I have 2 ipa replicas: B and C replica B crashed, so it was deleted from A and recreated using ipa-replica-parepare to generate the file and set it up from there. in server A B and C, if I do ipa-replica-manage list serverA lists A B and C as master serv

Re: [Freeipa-users] F20 Problem upgrading to 4.1

2014-10-30 Thread Martin Basti
On 30/10/14 06:09, Michael Lasevich wrote: Maybe I should not be doing this late at night, but I cannot find "cn=IPK11 Unique IDs,cn=IPA UUID,cn=plugins,cn=config " anywhere. -M IMO something bad happens during the ipa upgrade, can you remove ipk11UniqueId=autogenerate,cn=keys,cn=sec,cn=dns,