Re: [Freeipa-users] NetworkError : invalid continuation byte with utf8 codec

2015-12-22 Thread Fraser Tweedale
On Tue, Dec 22, 2015 at 08:39:09AM +0100, Gmail wrote: > Here are the files you ask for: > Thank you. I see Tomcat is running in an fr_FR locale. Could you also provide contents of `/etc/locale.conf'? Cheers, Fraser > > > Le 22 décembre 2015 à 02:30:06, Fraser Tweedale (ftwee...@redhat.com) a

Re: [Freeipa-users] Two Factor = SSHKeys + OTP or Password

2015-12-22 Thread Sumit Bose
On Tue, Dec 22, 2015 at 06:51:25PM +0530, Yogesh Sharma wrote: > Hi List, > > Did not see any options for SSH Keys + OTP or Password, However would like > to know if it is possible with FreeIPA user. > > With Generic SSH , We can use use AuthenticationMethods, but not sure where > to check in Fre

Re: [Freeipa-users] Want faster user-add

2015-12-22 Thread Simo Sorce
On Tue, 2015-12-22 at 10:24 +0100, thierry bordaz wrote: > On 12/21/2015 05:55 PM, Daryl Fonseca-Holt wrote: > > Hi all, > > > > Environment: RHEL6 with IPA 3.0 at current RedHat level. 64-core > > 256-GB RAM Oracle x4470 M2. > > > > During our migration from NIS on Solaris 140,000+ accounts will

[Freeipa-users] Two Factor = SSHKeys + OTP or Password

2015-12-22 Thread Yogesh Sharma
Hi List, Did not see any options for SSH Keys + OTP or Password, However would like to know if it is possible with FreeIPA user. With Generic SSH , We can use use AuthenticationMethods, but not sure where to check in FreeIPA. *Best Regards,* *__* *Yog

Re: [Freeipa-users] Want faster user-add

2015-12-22 Thread Daryl Fonseca-Holt
On 12/22/15 08:09, Petr Vobornik wrote: On 12/22/2015 10:24 AM, thierry bordaz wrote: On 12/21/2015 05:55 PM, Daryl Fonseca-Holt wrote: Hi all, Environment: RHEL6 with IPA 3.0 at current RedHat level. 64-core 256-GB RAM Oracle x4470 M2. During our migration from NIS on Solaris 140,000+ acco

Re: [Freeipa-users] Want faster user-add

2015-12-22 Thread Daryl Fonseca-Holt
On 12/22/15 03:24, thierry bordaz wrote: On 12/21/2015 05:55 PM, Daryl Fonseca-Holt wrote: Hi all, Environment: RHEL6 with IPA 3.0 at current RedHat level. 64-core 256-GB RAM Oracle x4470 M2. During our migration from NIS on Solaris 140,000+ accounts will be added. After tuning per the gui

Re: [Freeipa-users] Want faster user-add

2015-12-22 Thread Petr Vobornik
On 12/22/2015 10:24 AM, thierry bordaz wrote: On 12/21/2015 05:55 PM, Daryl Fonseca-Holt wrote: Hi all, Environment: RHEL6 with IPA 3.0 at current RedHat level. 64-core 256-GB RAM Oracle x4470 M2. During our migration from NIS on Solaris 140,000+ accounts will be added. After tuning per the gu

Re: [Freeipa-users] Purge old entries in /var/lib/dirsrv/slapd-xxx/cldb/xxx.db4 file

2015-12-22 Thread Ludwig Krispenz
Hi, On 12/22/2015 11:43 AM, David Goudet wrote: Hi, I have multimaster replication environment. On each replica, folder /var/lib/dirsrv/slapd-/cldb/ has big size (3~GB) and old entries in /var/lib/dirsrv/slapd-xxx/cldb/xxx.db4 have three month year old: sudo dbscan -f /var/lib/dirsrv/sl

[Freeipa-users] Queries on migrating nis netgroups

2015-12-22 Thread Roderick Johnstone
Hi I'm migrating our nis environment to freeipa 4.2.0 on Redhat 7. I need to have the netgroups set up in freeipa before migrating systems to be freeipa clients. At this point I'm trying to understand the relationship between hostgroups and netgroups and whether I should just be using ipa n

Re: [Freeipa-users] ipa-replica-prepare error: Profile caIPAserviceCert Not Found

2015-12-22 Thread Fraser Tweedale
On Tue, Dec 22, 2015 at 10:06:55AM +0100, Karl Forner wrote: > Hi Fraser, > The ipa-replica-prepare ran in a adelton/freeipa-server:lastest-systemd > docker, which I think is based on fedora 23 and contains freeIPA v 4.2.3. > I can try to patch it, but I'm really not used to fedora, and moreover >

[Freeipa-users] Purge old entries in /var/lib/dirsrv/slapd-xxx/cldb/xxx.db4 file

2015-12-22 Thread David Goudet
Hi, I have multimaster replication environment. On each replica, folder /var/lib/dirsrv/slapd-/cldb/ has big size (3~GB) and old entries in /var/lib/dirsrv/slapd-xxx/cldb/xxx.db4 have three month year old: sudo dbscan -f /var/lib/dirsrv/slapd-/cldb/ef155b03-dda611e2-a156db20-90xxx06_51

Re: [Freeipa-users] ipa-replica-prepare error: Profile caIPAserviceCert Not Found

2015-12-22 Thread Karl Forner
Hi Fraser, The ipa-replica-prepare ran in a adelton/freeipa-server:lastest-systemd docker, which I think is based on fedora 23 and contains freeIPA v 4.2.3. I can try to patch it, but I'm really not used to fedora, and moreover there's a debian/docker bug that prevents me from building the docker i

Re: [Freeipa-users] Want faster user-add

2015-12-22 Thread thierry bordaz
On 12/21/2015 05:55 PM, Daryl Fonseca-Holt wrote: Hi all, Environment: RHEL6 with IPA 3.0 at current RedHat level. 64-core 256-GB RAM Oracle x4470 M2. During our migration from NIS on Solaris 140,000+ accounts will be added. After tuning per the guides dbmon.sh shows no roevicts and we get

Re: [Freeipa-users] Issues with 'A replication agreement for the host already exists', when it very much doesn't

2015-12-22 Thread Ludwig Krispenz
On 12/21/2015 05:49 PM, Alex Williams wrote: I began installing a new ipa4 replica this morning and it all went wrong. The ipa-replica-install script got all the way to restarting ipa with systemctl at the very end, having set up replication and then fell over, because systemctl couldn't find

Re: [Freeipa-users] OS X Yosemite unable to authenticate

2015-12-22 Thread John Obaterspok
Hi, Are you only having problems to login to login to OSX with the IPA user now? If that is the case then check the DNS settings you are using and make sure the IPA server is listed first and that it has full name. Exactly the same problem occurred for me with the slow logins to OSX which was due