Re: [Freeipa-users] ipactl services running, but auth not working

2017-02-04 Thread Sullivan, Daniel [CRI]
I understand that there are reports from the client being unable to authenticate but what do the actual sssd logs say from the client, and from the server? When the problem occurs just point a client to the DC directly (instead of using _srv_ for example). Have you looked in /var/log/messages

[Freeipa-users] VERSION: 4.4.0, IPA Replica DOES NOT Work

2017-02-04 Thread deepak dimri
I am wondering Does IPA Replica as standalone without IPA Master being up works for you guys? Mine and my collogue IPA setup in our own Dev environment with VERSION: 4.2 works perfectly fine. but now when we are moving to staging env we are getting IPA version VERSION: 4.4.0, API_VERSION: 2.213

Re: [Freeipa-users] Can too many group memberships for an AD user cause SSSD or IPA problems?

2017-02-04 Thread Jakub Hrozek
On Fri, Feb 03, 2017 at 09:54:01AM -0500, Chris Dagdigian wrote: > > I've got a case where "id @AD-DOMAIN" hangs forever after partially > resolving and I think it may because they are in way too many AD groups? I don't think id should hang totally (at the very least, there is a NSS timeout that

[Freeipa-users] IPA replica setup for version 4.4

2017-02-04 Thread deepak dimri
I am trying to install ipa replica but getting below error when running ipa-replica-install i am following below link for ipa 4.4: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/creating-the-replica.html Run