Re: [Freeipa-users] sudo (sssd) hangs due to ipa install/uninstall scripts

2015-09-02 Thread Jakub Hrozek
On Wed, Sep 02, 2015 at 06:30:09PM -0700, Prasun Gera wrote: > FYI, I think the culprit (at least one of) is ipa-client-automount > --uninstall. This removes sss entirely from nssswitch, not just from the > automount section. Hmm, I haven't tested that but it sounds like a bug.. I would expect aut

[Freeipa-users] Ugrading IPA to dogtag? CA?

2015-09-02 Thread Steven Jones
It seems I built IPA with self signed certs so I need to upgrade? is this possible? and if so how on existing servers? regards Steven -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more in

Re: [Freeipa-users] sudo (sssd) hangs due to ipa install/uninstall scripts

2015-09-02 Thread Prasun Gera
FYI, I think the culprit (at least one of) is ipa-client-automount --uninstall. This removes sss entirely from nssswitch, not just from the automount section. On Tue, Sep 1, 2015 at 11:56 AM, Prasun Gera wrote: > So I've again spent a couple of hours debugging a very similar issue. > Client inst

Re: [Freeipa-users] ipa automountlocation-tofiles

2015-09-02 Thread Marc Wiatrowski
On Wed, Sep 2, 2015 at 3:46 PM, Rob Crittenden wrote: > Marc Wiatrowski wrote: > >> Hello, >> >> In trying to script some changes for automount locations. I've noticed >> 'ipa automountlocation-tofiles' doesn't seem to return everything. As >> an example: >> >> $ ipa automountlocation-tofiles o

Re: [Freeipa-users] ipa automountlocation-tofiles

2015-09-02 Thread Rob Crittenden
Marc Wiatrowski wrote: Hello, In trying to script some changes for automount locations. I've noticed 'ipa automountlocation-tofiles' doesn't seem to return everything. As an example: $ ipa automountlocation-tofiles office | grep abg returns nothing for abg. Yes, I have run this without the

[Freeipa-users] ipa automountlocation-tofiles

2015-09-02 Thread Marc Wiatrowski
Hello, In trying to script some changes for automount locations. I've noticed 'ipa automountlocation-tofiles' doesn't seem to return everything. As an example: $ ipa automountlocation-tofiles office | grep abg returns nothing for abg. Yes, I have run this without the grep and looked, piped ev

Re: [Freeipa-users] ipa-client on aws (amazon linux)

2015-09-02 Thread Gustavo Mateus
I think I'll go with ipa-advise for now since my main goal is to move away from openldap and allow AD users to ssh into my linux boxes. And eventually, when AWS decides to finally include ipa-client in amazon linux, I move to that approach. On Wed, Sep 2, 2015 at 12:36 AM, Lukas Slebodnik wrot

Re: [Freeipa-users] stubborn old replicas

2015-09-02 Thread Ludwig Krispenz
Hi Janelle, On 09/01/2015 06:17 PM, Janelle wrote: On 8/28/15 8:17 AM, Vaclav Adamec wrote: You could try this (RH recommended way). It works for me better than cleanallruv.pl as this sometimes leads to ldap freeze) unable to decode: {replica 30} 5548fa20001e

Re: [Freeipa-users] ipa-client on aws (amazon linux)

2015-09-02 Thread Lukas Slebodnik
On (02/09/15 12:58), Prashant Bapat wrote: >Lukas, > >ipa-client-install is part of the freeipa-client rpm. On Amazon Linux this >rpm cannot be installed. This is the basic issue. > Indeed. there is a strict requires for sssd Requires: sssd >= 1.12.3 #from fedora spec file Using ipa-advi

Re: [Freeipa-users] FreeIPA Sudo Error: Resource temporarily unavailable

2015-09-02 Thread Lukas Slebodnik
On (01/09/15 18:18), Yogesh Sharma wrote: >Hi, > >This is fixed. On digging more found that my resolv.conf was updated and it >was not able to find the domain. Fixing the resolv.conf with right >nameserver, fixed the issue. > I know it was solved but you would not miss important debug message with

Re: [Freeipa-users] ipa-client on aws (amazon linux)

2015-09-02 Thread Prashant Bapat
Lukas, ipa-client-install is part of the freeipa-client rpm. On Amazon Linux this rpm cannot be installed. This is the basic issue. Thanks. On 2 September 2015 at 12:43, Lukas Slebodnik wrote: > On (02/09/15 11:22), Prashant Bapat wrote: > >Hi, > > > >Running a freeipa-client on Amazon Linux i

Re: [Freeipa-users] User AD can not Login Client Linux

2015-09-02 Thread Lukas Slebodnik
On (28/08/15 08:44), Lukas Slebodnik wrote: >On (23/08/15 17:53), alireza baghery wrote: >>Hi i install Centos 7.1 (IDM Server) >>and integrate with Windows SERVER 2008 R2 Trust >>USER AD can not Login on client (OLE 6.6) but User create idm can login >> >>name IDM SERVER= ipasrv.l.infotechpsp.net

Re: [Freeipa-users] ipa-client on aws (amazon linux)

2015-09-02 Thread Lukas Slebodnik
On (02/09/15 11:22), Prashant Bapat wrote: >Hi, > >Running a freeipa-client on Amazon Linux is a huge challenge. This is >because the client depends on SSSD which in turn uses Samba libraries which >Amazon Linux does not support. sssd >= 1.11 can be compiled without samba libraries. But result is m