Re: [Freeipa-users] ID Mapping

2017-02-26 Thread Jakub Hrozek
On Sun, Feb 26, 2017 at 12:12:23PM -0800, Hanoz Elavia wrote: > Hey guys, > > Is it possible to disable ID mapping for AD users in a FreeIPA AD trust > setup? > > The version report is as follows: > > AD: Windows 2008 R2 > FreeIPA Server: 4.4.0-14 > FreeIPA Client: 4.4.0-14 > SSSD: 1.14.0-43 >

[Freeipa-users] ID Mapping

2017-02-26 Thread Hanoz Elavia
Hey guys, Is it possible to disable ID mapping for AD users in a FreeIPA AD trust setup? The version report is as follows: AD: Windows 2008 R2 FreeIPA Server: 4.4.0-14 FreeIPA Client: 4.4.0-14 SSSD: 1.14.0-43 Linux version: CentOS 7.3 x64_86 I've tried setting ldap_id_mapping = False in

Re: [Freeipa-users] authenticating with dns

2017-02-26 Thread Aaron Young
learned some things in the last few days I believe one of the root problems I have, if not THE root problem, is that I cannot start pki-tomcatd on my nyc01ipa02 machine. I now believe that if I could get that machine to work correctly, I could get all the others So, I get this in my logs from

Re: [Freeipa-users] CentOS 6 -> 7 migration

2017-02-26 Thread Rob Verduijn
Sounds feasable, however I'm not sure which solution entails the most work. In step 3 you loose all the extra functionalities( cups/squid/ntp ) as well, while these stay preserved by a p2v including a nice backup. You do need a backup of all the functions before proceeding with step3. Rob

Re: [Freeipa-users] CentOS 6 -> 7 migration

2017-02-26 Thread Ian Pilcher
On 02/26/2017 05:08 AM, Rob Verduijn wrote: You should consider setting up a temporary vm to migrate from. On one of your client systems, I assume you got at least 1 ipa client Try looking at http://libguestfs.org/virt-p2v.1.html to migrate your current system to a vm (side effect : instant

Re: [Freeipa-users] CentOS 6 -> 7 migration

2017-02-26 Thread Rob Verduijn
Upgrading centos6 to 7 is not a smart thing, unless you like to suffer a lot of issues. Then there are many comaptibility issues regarding the upgrade from ipa3.3 to 4.4 You should consider setting up a temporary vm to migrate from. On one of your client systems, I assume you got at least 1 ipa

[Freeipa-users] unable to decode: {replica

2017-02-26 Thread lejeczek
hi everyone I first time see: unable to decode: {replica 60} 586eaffd000a003c 586eaffd000a003c Replica Update Vectors: on all four servers. What would be a correct troubleshooting and fixing this problem? many thanks, L. -- Manage your subscription for the Freeipa-users