[Freeipa-users] Using CNAME to point to different domain name

2015-05-06 Thread Andrey Ptashnik
Hello Team, We are hosting a few servers at Amazon and using their Elastic Load Balancing service that gives us a link to a load balancer in the following format: webserver-1234567890.us-east-1.elb.amazonaws.com I was looking for a ways to implement a shorter alias using CNAME like:

Re: [Freeipa-users] FreeIPA 4.1.4 DNS notifications not being sent to slaves

2015-05-05 Thread Andrey Ptashnik
I did notice the same behavior. This is my setup: [root@ipa-idm]# yum list installed ipa-* Installed Packages ipa-admintools.x86_64 4.1.0-18.el7_1.3

Re: [Freeipa-users] Using CNAME to point to different domain name

2015-05-07 Thread Andrey Ptashnik
Hi Martin, Thank you for a catch! I just noticed that I was missing the dot you mentioned! Regards, Andrey From: Martin Basti mba...@redhat.commailto:mba...@redhat.com Date: Thursday, May 7, 2015 at 2:37 AM To: Andrey Ptashnik aptash...@cccis.commailto:aptash...@cccis.com, freeipa-users

[Freeipa-users] Allow user or group to switch user without password and not becoming root

2015-05-12 Thread Andrey Ptashnik
Hello Team, We have RHEL 7.1 and IPA server 4.1.0 in our environment as well as stack of Oracle software that require existence of local passwordless users like weblogic and oracle. Users log in to servers via domain accounts at IPA server. I’m trying to configure Sudo policy in IPA server

Re: [Freeipa-users] Allow user or group to switch user without password and not becoming root

2015-05-13 Thread Andrey Ptashnik
entry `NOPASSWD:' Last login: Tue May 12 15:00:31 CDT 2015 on pts/1 Last failed login: Wed May 13 10:46:52 CDT 2015 on pts/0 There were 7 failed login attempts since the last successful login. [oracle@webserver ~]$ Regards, Andrey Ptashnik From: Gould, Joshua joshua.go

[Freeipa-users] Two way trust vs one way trust and IPA features

2015-04-07 Thread Andrey Ptashnik
Hello, I’m wondering if establishing two way trust or one way trust in upcoming 4.2 release somehow is going to affect FreeIPA feature set, like ability to add windows groups to external groups or anything else I may not think of right now? Our Windows security team is expressing concerns

[Freeipa-users] Private key management

2015-04-08 Thread Andrey Ptashnik
Hello Team, I know that FreeIPA server supports management of public keys for each user and it is a very convenient feature. Are there any possible way to manage private keys as well including features like re-issuing the key pair if it gets compromised? Regards, Andrey -- Manage your

Re: [Freeipa-users] Private key management

2015-04-08 Thread Andrey Ptashnik
It looks like Vault is the functionality I was looking for. Thank you Rob and Dmitri for your responses. Regards, Andrey On 4/8/15, 5:59 PM, Rob Crittenden rcrit...@redhat.com wrote: Andrey Ptashnik wrote: Hello Team, I know that FreeIPA server supports management of public keys

[Freeipa-users] Steps to rebuild a master node in IPA cluster

2015-10-21 Thread Andrey Ptashnik
. We wanted to rebuild the Master node. What are the correct steps to move master functions to the replica, retire the old master and rebuild it? Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go

[Freeipa-users] Minimal compatibility with REHL / CentOS 5.5

2015-11-14 Thread Andrey Ptashnik
Hello IPA team, I’m wondering if there is any compatibility that can be established with legacy RHEL CentOS 5.5 machines. Is there any easy way to setup minimal feature set like central authentication and maybe something else? Regards, Andrey Ptashnik -- Manage your subscription

Re: [Freeipa-users] Minimal compatibility with REHL / CentOS 5.5

2015-11-16 Thread Andrey Ptashnik
Thank you, Rob and Martin! I was under impression that that v.5 was not supported at all, because "yum search ipa” did not return any search results in main or EPEL repository. Andrey Ptashnik On 11/16/15, 3:24 AM, "Martin Kosek" <mko...@redhat.com> wrote: >On

[Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-12 Thread Andrey Ptashnik
-upgradeconfig But I have a feeling that there might be some prerequisites that is a common knowledge that was not mentioned and I’m not aware of… Are there any steps that needs to be completed before I execute above commands? Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-12 Thread Andrey Ptashnik
Also I don’t see IPA server 4.2.1 in RHEL repository, is it already available? [root@sever]# yum list ipa-server ipa-server.x86_64 4.1.0-18.el7_1.4 @rhui-REGION-rhel-server-releases [root@server]# Regards, Andrey Ptashnik From: <freeipa-users-boun...@redhat.com<mailto:freeipa

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-12 Thread Andrey Ptashnik
I see that RHEL 7.2 relase date is still “TBA”. Are there any plans to make newer versions of IPA sever sooner than RHEL 7.2? Regards, Andrey Ptashnik On 10/12/15, 1:26 PM, "Alexander Bokovoy" <aboko...@redhat.com> wrote: >On Mon, 12 Oct 2015, Andrey Ptashnik wrote:

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-12 Thread Andrey Ptashnik
I we have a production environment, is it a safe move to upgrade to 7.2 Beta? And then still question remains what are correct steps to go from 4.1.0 to 4.2.0? Regards, Andrey Ptashnik On 10/12/15, 1:44 PM, "Rob Crittenden" <rcrit...@redhat.com> wrote: >Andrey Ptashn

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-12 Thread Andrey Ptashnik
I see, so your best advice is to wait for official release of 7.2 and upgrade all at once even if I need just a few simple fixes like “search for non-admin users” and etc…? Are there any approximate timeline for 7.2 release? Regards, Andrey Ptashnik On 10/12/15, 2:10 PM, "Alex

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-13 Thread Andrey Ptashnik
I usually try not to. On the other side I see that many important fixes are coming with major/minor releases, and trying to figure out my course of actions until fixes and/or release become available. Regards, Andrey Ptashnik On 10/12/15, 7:46 PM, "freeipa-users-boun...@redha

[Freeipa-users] Red Hat 5 and 6 with IPA Client v. 4

2015-09-16 Thread Andrey Ptashnik
some functionality is missing from client package 3 vs 4, like automatic update of both forward and reverse DNS records. Is it possible to install IPA client v. 4 on Red Hat 5 and 6 without much breaking dependencies in OS? Regards, Andrey Ptashnik | Network Architect CCC Information Services Inc

Re: [Freeipa-users] Red Hat 5 and 6 with IPA Client v. 4

2015-09-16 Thread Andrey Ptashnik
/openldap/ldap.conf NTP enabled Configured /etc/ssh/ssh_config Configured /etc/ssh/sshd_config Client configuration complete. Regards, Andrey Ptashnik On 9/16/15, 8:43 AM, "Alexander Bokovoy" <aboko...@redhat.com> wrote: >On Wed, 16 Sep 2015, Andrey Ptashnik wrote: >>De

Re: [Freeipa-users] Red Hat 5 and 6 with IPA Client v. 4

2015-09-17 Thread Andrey Ptashnik
Any ideas on that? Regards, Andrey Ptashnik | Network Architect CCC Information Services Inc. 222 Merchandise Mart Plaza, Suite 900 Chicago, IL 60654 Office: +1-312-229-2533 | Cell : +1-773-315-0200 | aptash...@cccis.com On 9/16/15, 11:30 AM, "freeipa-users-boun...@redhat.com on b

Re: [Freeipa-users] Red Hat 5 and 6 with IPA Client v. 4

2015-09-18 Thread Andrey Ptashnik
.in-addr.arpa. --allow-sync-ptr=TRUE --dynamic-update=TRUE Ultimately I think bringing all nodes to SSSD 1.12.4 version solved the problem. Thank you, IPA team, for your support! Regards, Andrey Ptashnik On 9/17/15, 10:32 AM, "Rob Crittenden" <rcrit...@redhat.com> wrote: >An

[Freeipa-users] "DNS resource record not found" error when searching or deleting records

2015-12-07 Thread Andrey Ptashnik
ecord not found” error message. Are there any ways to forcefully delete such stalled records or find out the root cause of this error message? Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to ht

Re: [Freeipa-users] "DNS resource record not found" error when searching or deleting records

2015-12-07 Thread Andrey Ptashnik
dNSTTL: 1200 objectClass: idnsRecord objectClass: top Number of entries returned 1 [root@ipa-idm]# Regards, Andrey Ptashnik From: Martin Basti <mba...@redhat.com<mailto:mba...@redhat.com>> Date: Monday, December 7, 2015

Re: [Freeipa-users] "DNS resource record not found" error when searching or deleting records

2015-12-07 Thread Andrey Ptashnik
Martin, For my education, how did you identify that from my output? Regards, Andrey Ptashnik From: Martin Basti <mba...@redhat.com<mailto:mba...@redhat.com>> Date: Monday, December 7, 2015 at 1:24 PM To: Andrey Ptashnik <aptash...@cccis.com<mailto:aptash...@cccis.com&

[Freeipa-users] Clean up DNS Host Cert and other records from IPA

2015-12-11 Thread Andrey Ptashnik
– is a perfect example). Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

[Freeipa-users] Clean up DNS, Host, Cert and other records from IPA / IDM

2015-12-13 Thread Andrey Ptashnik
– is a perfect example). Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Clean up DNS, Host, Cert and other records from IPA / IDM

2015-12-14 Thread Andrey Ptashnik
etely. Additionally if I can expect the same behavior on client versions lower than CentOS/RHEL 7.1 + IPA 4.1 Regards, Andrey Ptashnik On 12/14/15, 4:21 AM, "Alexander Bokovoy" <aboko...@redhat.com> wrote: >On Fri, 11 Dec 2015, Andrey Ptashnik wrote: >>Hello T

[Freeipa-users] FreeIPA Read Only Replica

2017-02-27 Thread Andrey Ptashnik
Team, Is it possible to setup read only replica for use in DMZ for example? Regards, Andrey -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

[Freeipa-users] IPA to IPA trust

2016-08-23 Thread Andrey Ptashnik
Hello IPA team, Is there a way to implement IPA to IPA trust between different domains? We are thinking of using more than one domain, however we will need users to cross login from one domain to another. Regards, Andrey -- Manage your subscription for the Freeipa-users mailing list:

[Freeipa-users] IPA server as a domain controller for more than one domain

2016-09-16 Thread Andrey Ptashnik
Hi IPA team, Can I use the same FreeIPA server to be a domain controller for more than one domain? Regards, Andrey Ptashnik -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info

[Freeipa-users] Higher client versions joining 4.2.0 IPA cluster

2016-09-07 Thread Andrey Ptashnik
Hello FreeIPA team, Our FreeIPA server cluster is at version 4.2.0 and expecting Ubuntu 16 machines with FreeIPA client software 4.3.1 soon to join our IPA domain. Are there any compatibility issues that we may encounter? Regards, Andrey -- Manage your subscription for the Freeipa-users

[Freeipa-users] Higher client versions joining 4.2.0 IPA cluster

2016-09-07 Thread Andrey Ptashnik
Hello FreeIPA team, Our FreeIPA server cluster is at version 4.2.0 and expecting Ubuntu 16 machines with FreeIPA client software 4.3.1 soon to join our IPA domain. Are there any compatibility issues that we may encounter? Regards, Andrey -- Manage your subscription for the Freeipa-users

[Freeipa-users] Upgrade from IPA 4.2

2017-04-03 Thread Andrey Ptashnik
Hello, We have Centos 7.2 and IPA 4.2 version. I remember that in previous versions in order to upgrade to the latest one I had to run IPA upgrade scripts that would separately upgrade LDAP database. Is that the same procedure if I need to upgrade from version 4.2? Regards, Andrey -- Manage

Re: [Freeipa-users] Upgrade from IPA 4.2

2017-04-06 Thread Andrey Ptashnik
lan Musicman <data...@gmail.com<mailto:data...@gmail.com>>, Andrey Ptashnik <aptash...@cccis.com<mailto:aptash...@cccis.com>> Cc: "freeipa-users@redhat.com<mailto:freeipa-users@redhat.com>" <freeipa-users@redhat.com<mailto:freeipa-users@redhat.com>&g