Re: [Freeipa-users] sec_error_reused_issuer_and_serial

2015-09-22 Thread Fraser Tweedale
On Wed, Sep 23, 2015 at 02:54:29AM +, Les Stott wrote: > > > > -Original Message- > > From: Fraser Tweedale [mailto:ftwee...@redhat.com] > > Sent: Wednesday, 23 September 2015 10:59 AM > > To: Les Stott > > Cc: Winfried de Heiden; freeipa-users@redhat.com > > Subject: Re: [Freeipa-use

Re: [Freeipa-users] sec_error_reused_issuer_and_serial

2015-09-22 Thread Les Stott
> -Original Message- > From: Fraser Tweedale [mailto:ftwee...@redhat.com] > Sent: Wednesday, 23 September 2015 10:59 AM > To: Les Stott > Cc: Winfried de Heiden; freeipa-users@redhat.com > Subject: Re: [Freeipa-users] sec_error_reused_issuer_and_serial > > On Tue, Sep 22, 2015 at 09:52:3

Re: [Freeipa-users] sec_error_reused_issuer_and_serial

2015-09-22 Thread Fraser Tweedale
On Tue, Sep 22, 2015 at 09:52:38PM +, Les Stott wrote: > The only way to get around it, because you are using the same > domain name, is to use different browsers to visit each site. > Firefox for sitea, chrome for siteb. > It is not the only way; you can flush your browser cache / offline dat

Re: [Freeipa-users] sec_error_reused_issuer_and_serial

2015-09-22 Thread Les Stott
The only way to get around it, because you are using the same domain name, is to use different browsers to visit each site. Firefox for sitea, chrome for siteb. It's got to do with the fact that the Parent certificate name (generated automatically during install) is the same on both and because

Re: [Freeipa-users] otp issue: can't log in with password+otp

2015-09-22 Thread Alexander Bokovoy
On Tue, 22 Sep 2015, Duncan McNaught wrote: I realize that, thanks. That's currently the only problem for us - getting 2FA to work. Given that we rely on socket activation for ipa-otpd, you would need to make a wrapper that would listen a unix domain socket and forward the data between ipa-otpd

Re: [Freeipa-users] otp issue: can't log in with password+otp

2015-09-22 Thread Duncan McNaught
I realize that, thanks. That's currently the only problem for us - getting 2FA to work. Thanks --Duncan Duncan McNaught Infrastructure Engineer Technologies | www.bitnet.io +1 720 240 6575 On Tue, Sep 22, 2015 at 12:12 PM, Nathaniel McCallum wrote: > Running IPA i

Re: [Freeipa-users] otp issue: can't log in with password+otp

2015-09-22 Thread Nathaniel McCallum
Running IPA in a container is very bleading edge. I would not be surprised at all if you run into lots of problems. On Tue, 2015-09-22 at 12:10 -0600, Duncan McNaught wrote: > Thanks Nathaniel, > I am running with Jan's Centos-7 container and I'd like to have > Multi-factor Authentication/2FA en

Re: [Freeipa-users] otp issue: can't log in with password+otp

2015-09-22 Thread Duncan McNaught
Thanks Nathaniel, I am running with Jan's Centos-7 container and I'd like to have Multi-factor Authentication/2FA enabled. He mentioned that systemd is not running in the container, so I guess that explains why 2FA is failing. I wonder if I can get systemd running there. --Duncan Thanks --Dunca

[Freeipa-users] Automatic IPA CA cert generation

2015-09-22 Thread James Masson
Hi, we're building IPAs in an automated fashion, for environments that get created and destroyed a lot. At the moment, the CA certs used inside these IPAs are self-signed, as part of the normal "ipa-server-install" setup process. We would like to switch to issuing signed intermediate CA cer

[Freeipa-users] [Import existing CA Cert]

2015-09-22 Thread Michael Anderson
Hi All, we're evaluation freeipa/dogtag as a pki management service and hoping to replace our existing menagerie of bash/openssl scripts. I'm trying to establish a migration path for our existing pki solution and have a few questions: * how can I import and use our existing CA signing cert?

Re: [Freeipa-users] otp issue: can't log in with password+otp

2015-09-22 Thread Nathaniel McCallum
On Mon, 2015-09-21 at 16:49 -0600, Duncan McNaught wrote: > Dear freeipa-users, > > I'm having an issue with otp in freeipa. I can set up the service as > described in the blog post for TOTP or HOTP, and sync the token fine. > When I try to login to the admin tools or an ipa-managed client > (with

[Freeipa-users] sec_error_reused_issuer_and_serial

2015-09-22 Thread Winfried de Heiden
Hi all, Playing around with freeipa on Fedora 22 after installing I cannot access the UI. Firefox will tell "sec_error_reused_issuer_and_serial". I allready have an Freeipa (Fedora 21 based) and somewhere there seems to be a conflict in the cer

Re: [Freeipa-users] user delete command hangs kdc and ldap stop responding

2015-09-22 Thread thierry bordaz
Hi, If it hangs again, could you get a pstack of the slapd process And also dump the db info 'db_stat -h /var/lib/dirsrv/slapd-/db -N -CA'. This would help to know which thread holds the lock that that blocks those operations ? thanks thierry On 09/18/2015 09:20 PM, HECTOR LOPEZ

Re: [Freeipa-users] Another CentOS 6.x to CentOS 7.1 migration question

2015-09-22 Thread Alexander Bokovoy
On Tue, 22 Sep 2015, Martin Kosek wrote: On 09/22/2015 05:06 AM, Robert Story wrote: I've followed the migration document https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/migrating-ipa-proc.html almost to the end.