[Freeipa-users] DNS lookups after replica(master) added

2015-04-22 Thread Cory Carlton
Hey all, I for some reason do not ever get responses from doing DNS lookups to my new servers that have been stood up and replicated as Masters with CA, and DNS options entered at command line. Is there any trick or configuration to allow anonymous for my servers without IPA Client installed to

[Freeipa-users] IdM Replica Install SSH failure.

2015-04-22 Thread Jesse Johnson
ALL, I'm attempting to complete a replica install and the system is bombing out on the gssapi portion of the SSH key configuration. I can ssh and selinux is permissive. Could not SSH into remote host. Error output: OpenSSH_6.6.1, OpenSSL 1.0.1e-fips 11 Feb 2013 debug1: Reading

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-22 Thread Roderick Johnstone
On 22/04/15 14:30, Dmitri Pal wrote: On 04/21/2015 01:13 PM, Roderick Johnstone wrote: Hi I also need to integrate Solaris 10 clients with freeipa servers. I've been round many resources, eg freeipa wiki, Fedora and Red Hat manuals, various bug trackers and the freeipa-users mailing list. It

Re: [Freeipa-users] External group membership

2015-04-22 Thread Benjamen Keroack
Hi Dmitri, I'd be happy to test sssd 1.13 alpha. Is there any easy was to install on Ubuntu, or do I need to pull and compile from source? Thanks, On Fri, Apr 17, 2015 at 9:07 PM, Dmitri Pal d...@redhat.com wrote: On 04/17/2015 09:12 PM, Benjamen Keroack wrote: Hi, We have a number of

Re: [Freeipa-users] DNS lookups after replica(master) added

2015-04-22 Thread Martin Basti
On 22/04/15 18:40, Cory Carlton wrote: Hey all, I for some reason do not ever get responses from doing DNS lookups to my new servers that have been stood up and replicated as Masters with CA, and DNS options entered at command line. Is there any trick or configuration to allow anonymous for

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-22 Thread Rob Crittenden
Roderick Johnstone wrote: On 22/04/15 14:30, Dmitri Pal wrote: On 04/21/2015 01:13 PM, Roderick Johnstone wrote: Hi I also need to integrate Solaris 10 clients with freeipa servers. I've been round many resources, eg freeipa wiki, Fedora and Red Hat manuals, various bug trackers and the

[Freeipa-users] kadmin.local to manage FreeIPA Kerberos

2015-04-22 Thread Shaik M
Hi, We have recently deployed FreeIPA for our Hadoop environment. Recently, Ambari community released 2.0, where this version supports MIT kerberos. Which means Ambri create the all service principals using with kadmin.local. As I know, kadmin.local wont work for FreeIPA kerberos to create the

Re: [Freeipa-users] ipa-replica-prepare failing

2015-04-22 Thread Jan Cholasta
Hi, yes, you can definitely use a different certificate in the meantime, although it can't be self-signed. Honza Dne 20.4.2015 v 14:17 David Dejaeghere napsal(a): Hi, Let me know how I can assist. In the meantime could I setup a replica using a different certificate? Self signed or

Re: [Freeipa-users] kadmin.local to manage FreeIPA Kerberos

2015-04-22 Thread Alexander Bokovoy
On Thu, 23 Apr 2015, Shaik M wrote: Hi, We have recently deployed FreeIPA for our Hadoop environment. Recently, Ambari community released 2.0, where this version supports MIT kerberos. Which means Ambri create the all service principals using with kadmin.local. As I know, kadmin.local wont

Re: [Freeipa-users] Also attempting to integrate Solaris 10 clients with freeipa

2015-04-22 Thread Dmitri Pal
On 04/21/2015 01:13 PM, Roderick Johnstone wrote: Hi I also need to integrate Solaris 10 clients with freeipa servers. I've been round many resources, eg freeipa wiki, Fedora and Red Hat manuals, various bug trackers and the freeipa-users mailing list. It looks to me as if this:

Re: [Freeipa-users] Stuck getting sudo working with Ubuntu client

2015-04-22 Thread Timo Aaltonen
On 21.04.2015 22:45, Lukas Slebodnik wrote: On (20/04/15 17:54), Andrew Sacamano wrote: Thanks again, Lukas! I was wondering if the overlaps of names was a problem, so I redid parts of my IPA setup to rename them - thanks for pointing out the ticket! Also, your suggestion to use

Re: [Freeipa-users] Slow user logon with IPA

2015-04-22 Thread Jakub Hrozek
On Wed, Apr 22, 2015 at 12:43:47AM +0200, Mateusz Malek wrote: On 15.04.2015 at 15:08, Lukas Slebodnik wrote: On 04/10/2015 08:13 AM, Mateusz Malek wrote: I'm about to migrate my OpenLDAP-based environment to FreeIPA, however I've hit some weird performance problems. When I'm using IPA, it

[Freeipa-users] Users home directory with 755 permission instead of 700

2015-04-22 Thread Sanju A
Dear All, Permission of all users in our 300 + machines are created with 755 instead of 700. I have checked the same in forums and got the one. http://stackoverflow.com/questions/23040225/incorrect-permissions-when-home-directory-is-automatically-created-in-freeipa Let me know whether I have