Re: [Freeipa-users] 2FA Host based?

2016-03-30 Thread Rob Crittenden
William Graboyes wrote: Hi All, I have done some searching around, and I am wondering if there is a way to require OTP for certain hosts, and not for others. Example: Lets say that I want foo.example.com to force using 2FA because it is an entry point into the network. However bar.example.com

[Freeipa-users] 2FA Host based?

2016-03-30 Thread William Graboyes
Hi All, I have done some searching around, and I am wondering if there is a way to require OTP for certain hosts, and not for others. Example: Lets say that I want foo.example.com to force using 2FA because it is an entry point into the network. However bar.example.com is only used internally,

Re: [Freeipa-users] IPA 4.2: pki-tomcatd in terrible shape

2016-03-30 Thread Thorsten Scherf
On [Tue, 29.03.2016 20:53], Timothy Geier wrote: On Mar 29, 2016, at 2:00 AM, Thorsten Scherf wrote: On [Mon, 28.03.2016 18:18], Timothy Geier wrote: On Mar 28, 2016, at 12:53 PM, Thorsten Scherf wrote: On [Sat, 26.03.2016 03:26], Timothy Geier

Re: [Freeipa-users] IPA users central Home Directories

2016-03-30 Thread Prasun Gera
NFS and ipa are sort of orthogonal unless you mix nfsv4 with kerberos. If you aren't using kerberos, and don't need kerberos, then the nfs home setup is pretty straightforward. ipa just controls authentication. If you have a simple enough environment, you can just add your nfs mounts in the fstab