Re: [Freeipa-users] Logging: IPA to Rsyslog to Logstash

2015-01-05 Thread Innes, Duncan
-Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Dmitri Pal Sent: 20 December 2014 03:37 To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] Logging: IPA to Rsyslog to Logstash On 12/19/2014 11:35 AM, Innes,

Re: [Freeipa-users] Integration with Solaris 10

2015-01-05 Thread Ben .T.George
HI sorry that was a misunderstand happened from his side, actually i was strugglling to set it up for solaris \ regards, ben On Mon, Jan 5, 2015 at 11:51 AM, Petr Spacek pspa...@redhat.com wrote: On 2.1.2015 22:11, Dmitri Pal wrote: Would you mind creating a wiki page with the solution on

Re: [Freeipa-users] Logging: IPA to Rsyslog to Logstash

2015-01-05 Thread Petr Spacek
Hello Duncan, thank you for doing this! Could you transform this post to http://www.freeipa.org/page/HowTos#Working_with_FreeIPA article, please? I think that other people could use that too. Thank you very much. Petr^2 Spacek On 19.12.2014 17:35, Innes, Duncan wrote: Earlier this year I said

Re: [Freeipa-users] Integration with Solaris 10

2015-01-05 Thread Petr Spacek
On 2.1.2015 22:11, Dmitri Pal wrote: Would you mind creating a wiki page with the solution on the wiki? Maybe you could check modify http://www.freeipa.org/page/ConfiguringUnixClients ... Normal Fedora Account will allow you to edit the page. -- Petr^2 Spacek -- Manage your subscription for

Re: [Freeipa-users] KDC has no support for encryption type

2015-01-05 Thread Petr Spacek
On 29.12.2014 23:31, Matt . wrote: But should an IPA install not add them by default ? Maybe this is some I'm not sure that I understand what you mean, but DES is disabled on purpose because it is completely insecure nowadays. Maybe you should try to rule it out from your deployment. According

Re: [Freeipa-users] bind-dyndb-ldap and ddns updates from dhcp

2015-01-05 Thread Petr Spacek
On 31.12.2014 22:40, Jan Pazdziora wrote: On Wed, Dec 31, 2014 at 10:34:37PM +0100, Jan Pazdziora wrote: endpoints, or their users, should not be trusted to make updates to DNS zones. TSIG signed updates from servers are still preferred over authenticated updates from endpoints or users.

Re: [Freeipa-users] Client configuration to point to Replica server once master service failed

2015-01-05 Thread Petr Spacek
On 1.1.2015 07:25, Prashant Bapat wrote: You could use DNS based failover for this. Configure DNS with a low TTL value like 60 secs. When the primary fails, update the dns with the secondary. This should not be necessary for FreeIPA because we use DNS SRV records and clients are supposed to

Re: [Freeipa-users] how to configure Linux Cent Os as ipa client manual installation

2015-01-05 Thread Martin Kosek
On 12/29/2014 09:54 PM, Dmitri Pal wrote: On 12/20/2014 05:02 AM, Ben .T.George wrote: Hi I was trying to configure centos as ipa client and got failed with that,. anyone please help me to configure centos as ipa client through manual configuration. Regards, Ben Sorry for a delayed

Re: [Freeipa-users] sudo !requiretty !authenticate

2015-01-05 Thread Martin Kosek
On 01/02/2015 07:47 PM, Craig White wrote: Subject pretty much says it all. Starting to play around with rundeck and was thinking it would be nice if I could create a user that had the ability to sudo, without password, a public key and the ability to run commands. But the use of 'sudo'

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-05 Thread Martin Kosek
On 01/04/2015 12:29 AM, Anthony Messina wrote: I was hoping to migrate from F20 to F21 using: http://www.freeipa.org/page/Howto/Migration http://www.freeipa.org/page/Howto/Promote_CA_to_Renewal_and_CRL_Master The migration procedure is only needed if you run FreeIPA server with PKI based on

Re: [Freeipa-users] Logging: IPA to Rsyslog to Logstash

2015-01-05 Thread Martin Kosek
Thanks, I just changed it to follow Mediawiki syntax and renamed it to http://www.freeipa.org/page/Howto/Centralised_Logging_with_Logstash/ElasticSearch/Kibana to keep current Howto structure. Please feel free encouraged to fill up any more details as you go with your adventures that the

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-05 Thread Martin Kosek
On 01/05/2015 02:05 PM, Anthony Messina wrote: Quoting Martin Kosek mko...@redhat.com: On 01/04/2015 12:29 AM, Anthony Messina wrote: I was hoping to migrate from F20 to F21 using: http://www.freeipa.org/page/Howto/Migration

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-05 Thread Anthony Messina
Quoting Martin Kosek mko...@redhat.com: On 01/04/2015 12:29 AM, Anthony Messina wrote: I was hoping to migrate from F20 to F21 using: http://www.freeipa.org/page/Howto/Migration http://www.freeipa.org/page/Howto/Promote_CA_to_Renewal_and_CRL_Master The migration procedure is only needed if

Re: [Freeipa-users] how to configure Linux Cent Os as ipa client manual installation

2015-01-05 Thread Janelle
Hi everyone, Happy New Year. Was following this thread and wondering about those of us with a couple of 2000-3000 servers to run ipa-client-install on? Any suggestions? Was looking around for even the basics of puppet or chef configs, but nothing exists. Any suggestions? One of the

Re: [Freeipa-users] Integration with Solaris 10

2015-01-05 Thread Rob Crittenden
Ben .T.George wrote: HI sorry that was a misunderstand happened from his side, actually i was strugglling to set it up for solaris \ We simply lack the expertise to help much further beyond the documentation you've already seen. Another IPA user contributed a significant amount of

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-05 Thread Anthony Messina
On Monday, January 05, 2015 10:40:08 PM Endi Sukma Dewata wrote: On 1/5/2015 8:53 PM, Martin Kosek wrote: On 01/05/2015 02:05 PM, Anthony Messina wrote: I was hoping to migrate from F20 to F21 using: http://www.freeipa.org/page/Howto/Migration

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-05 Thread Ben .T.George
HI IRC is like totally dead. i have waited one whole day to anyone responding. not even to my replay. i didn't see any messages at all. Regards, Ben On Mon, Jan 5, 2015 at 11:49 PM, Dmitri Pal d...@redhat.com wrote: On 01/05/2015 01:31 PM, Ben .T.George wrote: HI Thanks for the

[Freeipa-users] How to check IPA -- AD trust from command line

2015-01-05 Thread Ben .T.George
Hi LIst, how to check IPA - Active directory trust relationship . i just want to confirm my ipa server is working fine. Regards, Ben -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on

Re: [Freeipa-users] sudo !requiretty !authenticate

2015-01-05 Thread Craig White
Hi - reply at bottom -Original Message- From: Martin Kosek [mailto:mko...@redhat.com] Sent: Monday, January 05, 2015 4:33 AM To: Craig White; freeipa-users@redhat.com; Pavel Brezina Subject: Re: [Freeipa-users] sudo !requiretty !authenticate On 01/02/2015 07:47 PM, Craig White wrote:

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-05 Thread Ben .T.George
HI Thanks for the information. When i run ipa-advise, i am getting below output, which advice i need to choose. all of them are pointing to linux based [root@kwtpocpbis01 ~]# ipa-advise -- List of available advices

Re: [Freeipa-users] how to configure Linux Cent Os as ipa client manual installation

2015-01-05 Thread Martin Kosek
On 01/05/2015 03:24 PM, Janelle wrote: Hi everyone, Happy New Year. Was following this thread and wondering about those of us with a couple of 2000-3000 servers to run ipa-client-install on? Any suggestions? Was looking around for even the basics of puppet or chef configs, but nothing

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-05 Thread Dmitri Pal
On 01/04/2015 10:30 PM, Ben .T.George wrote: HI yes you are right. Linux clients working and IPA is in trust relationship with AD. currently i am using 3.3.3 i guess i didn't tryed ipa-advice tool yet. I am not aware about this tool. can you please give right directions regarding this

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-05 Thread Dmitri Pal
On 01/05/2015 10:51 AM, Dmitri Pal wrote: On 01/04/2015 10:30 PM, Ben .T.George wrote: HI yes you are right. Linux clients working and IPA is in trust relationship with AD. currently i am using 3.3.3 i guess i didn't tryed ipa-advice tool yet. I am not aware about this tool. can you please

Re: [Freeipa-users] dirsrv password incorrect on replicas?

2015-01-05 Thread Rich Megginson
On 12/19/2014 09:59 AM, Janelle wrote: I am the only one who has access to these systems, so unless I did it in my sleep.. :-) Ok. Please file a ticket and provide steps to reproduce the issue. ~J On 12/19/14 12:14 AM, Ludwig Krispenz wrote: On 12/18/2014 08:16 PM, Rich Megginson wrote:

Re: [Freeipa-users] how to configure Linux Cent Os as ipa client manual installation

2015-01-05 Thread Rob Crittenden
Janelle wrote: Hi everyone, Happy New Year. Was following this thread and wondering about those of us with a couple of 2000-3000 servers to run ipa-client-install on? Any suggestions? Was looking around for even the basics of puppet or chef configs, but nothing exists. Any suggestions?

Re: [Freeipa-users] Trouble installing F21 4.1.2 replica from F20 3.3.5 master

2015-01-05 Thread Anthony Messina
Quoting Martin Kosek mko...@redhat.com: On 01/05/2015 02:05 PM, Anthony Messina wrote: Quoting Martin Kosek mko...@redhat.com: On 01/04/2015 12:29 AM, Anthony Messina wrote: I was hoping to migrate from F20 to F21 using: http://www.freeipa.org/page/Howto/Migration

Re: [Freeipa-users] how to configure Linux Cent Os as ipa client manual installation

2015-01-05 Thread Dmitri Pal
On 01/05/2015 10:26 AM, Rob Crittenden wrote: Janelle wrote: Hi everyone, Happy New Year. Was following this thread and wondering about those of us with a couple of 2000-3000 servers to run ipa-client-install on? Any suggestions? Was looking around for even the basics of puppet or chef

Re: [Freeipa-users] how can i configure solaris 10 sparc and x86 as ipa clients

2015-01-05 Thread Dmitri Pal
On 01/05/2015 01:31 PM, Ben .T.George wrote: HI Thanks for the information. When i run ipa-advise, i am getting below output, which advice i need to choose. all of them are pointing to linux based [root@kwtpocpbis01 ~]# ipa-advise