Re: [Freeipa-users] FreeIPA, Windows and Kerberos

2015-10-24 Thread Fujisan
Have you tried with /setdomain? ksetup /setdomain CHEM.BYU.EDU I've done like this on windows 8.1 and windows 10. I had trouble doing it on one windows 7 desktop so I upgraded to windows 10. ​These are the only steps I did to authenticate a windows desktop via kerberos,

[Freeipa-users] What is the recommended procedure for upgrading clients and servers to F23?

2015-10-31 Thread Fujisan
Hi there, F23 is coming out very soon and I'm wondering what machine I should upgrade first, the spa clients or the ipa servers? In other words, can the ipa system work with ipa client upgraded to 4.2 and the servers still at 4.1.4? Or do I have to upgrade the servers first? And should I upgrade

[Freeipa-users] Why are some user's information not stored in the LDAP database?

2015-10-16 Thread Fujisan
Hello, When I enter the email address, the phone number or the mailing address of ipa user 'smith' in the web ui "Identity/Users/smith", it does not appears in the output of ldapsearch. Sendmail can look into the ldap database and get the email address of a user and send mail to that user. Is it

Re: [Freeipa-users] Why are some user's information not stored in the LDAP database?

2015-10-16 Thread Fujisan
com> wrote: > On 16/10/15 15:26, Fujisan wrote: > >> Hello, >> >> When I enter the email address, the phone number or the mailing address of >> ipa user 'smith' in the web ui "Identity/Users/smith", it does not appears >> in the output of ldapsearch.

[Freeipa-users] User removed from IPA but still present in LDAP, so cannot him again in IPA web UI

2015-10-01 Thread Fujisan
Hello, I want to add user 'user1' with the freeipa web UI. It is not present in the list of users in the web UI but when I click "add", it says 'user with name "user1" already exists'. ldapsearch shows 'user1' is there: --- $

Re: [Freeipa-users] User removed from IPA but still present in LDAP, so cannot him again in IPA web UI

2015-10-01 Thread Fujisan
I get this: - $ ldapsearch -D cn=directory\ manager -W -b cn=accounts,dc=mydomain '(uid=user1*)' Enter LDAP Password: # extended LDIF # # LDAPv3 # base

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-05 Thread Fujisan
Good morning, ​ Any suggestion what I should do?​ ​I still have ​$ ipa user-show admin ipa: ERROR: cannot connect to 'https://zaira2.opera/ipa/json': Unauthorized Regards. On Fri, Oct 2, 2015 at 5:04 PM, Fujisan <fujisa...@gmail.com> wrote: > I only have this: > > $ keyctl

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-02 Thread Fujisan
[4991]]]: Failed to initialize credentials using keytab [MEMORY:/etc/krb5.keytab]: Decrypt integrity check failed. Unable to create GSSAPI-encrypted LDAP connection. On Fri, Oct 2, 2015 at 2:26 PM, Fujisan <fujisa...@gmail.com> wrote: > Hello, > > I cannot login to the

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-02 Thread Fujisan
3 HTTP/zaira2.opera@OPERA On Fri, Oct 2, 2015 at 3:45 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Fri, 02 Oct 2015, Fujisan wrote: > >> More info: >> >> I can initiate a ticket: >> $ kdestroy >> $ kinit admin >> >> but cannot v

[Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-02 Thread Fujisan
Hello, I cannot login to the web UI anymore. The password or username you entered is incorrect. Log says: Oct 02 14:22:57 zaira2.opera krb5kdc[3225](info): AS_REQ (9 etypes {18 17 16 23 25 26 1 3 2}) 10.0.21.18: NEEDED_PREAUTH: HTTP/zaira2.opera@OPERA for krbtgt/OPERA@OPERA, Additional

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-02 Thread Fujisan
I forgot to mention that $ ipa user-show admin ipa: ERROR: cannot connect to 'https://zaira2.opera/ipa/json': Unauthorized On Fri, Oct 2, 2015 at 4:44 PM, Fujisan <fujisa...@gmail.com> wrote: > I still cannot login to the web UI. > > Here is what I did: > >1. mv /etc/

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-02 Thread Fujisan
}) 10.0.21.18: NEEDED_PREAUTH: HTTP/zaira2.opera@OPERA for krbtgt/OPERA@OPERA, Additional pre-authentication required On Fri, Oct 2, 2015 at 4:25 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Fri, 02 Oct 2015, Fujisan wrote: > >> Well, I think I messed up when trying to config

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-05 Thread Fujisan
not connect to 'https://zaira2.opera/ipa/json': Unauthorized On Mon, Oct 5, 2015 at 12:13 PM, Fujisan <fujisa...@gmail.com> wrote: > I uninstalled the ipa server and reinstalled it. Then restored the backup. > And then the following: > > $ keyctl list @s > 3 keys in keyring:

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-05 Thread Fujisan
It is actually on the ipa server that ipa commands are not working. On ipa clients, I do not have errors. On Mon, Oct 5, 2015 at 12:27 PM, Fujisan <fujisa...@gmail.com> wrote: > I just noticed I can log in to the web UI with user admin and his password. > > But when I try to co

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-05 Thread Fujisan
0 user: ipa_session_cookie:host/zaira2.opera@OPERA 286806445: ---lswrv 0 65534 keyring: _persistent.0 ​It doesn't seem to purge or to reap.​ On Mon, Oct 5, 2015 at 9:17 AM, Fujisan <fujisa...@gmail.com> wrote: > Good morning, > ​ > Any suggestion what I should do?​ &g

Re: [Freeipa-users] Cannot connect to FreeIPA web UI anymore

2015-10-05 Thread Fujisan
the server on the new kernel (4.1.8-200.fc22.x86_64). On Mon, Oct 5, 2015 at 4:07 PM, Petr Vobornik <pvobo...@redhat.com> wrote: > On 10/05/2015 12:55 PM, Fujisan wrote: > >> It is actually on the ipa server that ipa commands are not working. On ipa >> clien

[Freeipa-users] Cannot start freeipa after reboot of server

2016-02-05 Thread Fujisan
Hello, I have a big problem here I have rebooted my freeipa server and noticed that no login screen appeared after the reboot making it impossible to log in, even through an ssh session from my desktop. I also rebooted the replica and got the same problem. I rebooted again the replica in rescue

Re: [Freeipa-users] Cannot start freeipa after reboot of server

2016-02-06 Thread Fujisan
: /var/spool/abrt/oops-2016-02-05-15:35:10-1606-4 Reported: cannot be reported Regards, F. On Sat, Feb 6, 2016 at 12:32 PM, Martin Basti <mba...@redhat.com> wrote: > > > On 05.02.2016 16:52, Fujisan wrote: > > Hello, > > I have a big problem here > I h

Re: [Freeipa-users] Freeipa not working after upgrade to F24

2016-09-07 Thread Fujisan
Ok I just tried and you are right. It works! Pfiuuu! You saved my a$$. Thanks. On Wed, Sep 7, 2016 at 2:58 PM, Fujisan <fujisa...@gmail.com> wrote: > Selinux is disabled on my server. > Do I still need to run 'pki-server-upgrade -v'? > > Regards, > F. > > On

Re: [Freeipa-users] Freeipa not working after upgrade to F24

2016-09-07 Thread Fujisan
Selinux is disabled on my server. Do I still need to run 'pki-server-upgrade -v'? Regards, F. On Wed, Sep 7, 2016 at 2:53 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Wed, 07 Sep 2016, Fujisan wrote: > >> Hello, >> >> I just upgraded my server

Re: [Freeipa-users] Freeipa not working after upgrade to F24

2016-09-07 Thread Fujisan
Is this issue documented somewhere? On Wed, Sep 7, 2016 at 3:03 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Wed, 07 Sep 2016, Fujisan wrote: > >> Selinux is disabled on my server. >> Do I still need to run 'pki-server-upgrade -v'? >> > You

Re: [Freeipa-users] The Web UI is not loading

2016-09-12 Thread Fujisan
Ok I installed the missing package and restarted ipa but it is still not woking. On Mon, Sep 12, 2016 at 11:13 AM, Fujisan <fujisa...@gmail.com> wrote: > No it is missing! > > On Mon, Sep 12, 2016 at 10:55 AM, Alexander Bokovoy <aboko...@redhat.com> > wrote: > >

Re: [Freeipa-users] The Web UI is not loading

2016-09-12 Thread Fujisan
No it is missing! On Mon, Sep 12, 2016 at 10:55 AM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Mon, 12 Sep 2016, Fujisan wrote: > >> Hello, >> >> This morning I noticed I could not reload the Freeipa web ui. Its was >> working well friday but somethin

Re: [Freeipa-users] The Web UI is not loading

2016-09-12 Thread Fujisan
Yes. I had to restart the browser. Now everything is working again. Thank you. On Mon, Sep 12, 2016 at 12:07 PM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On Mon, 12 Sep 2016, Fujisan wrote: > >> Here is what i get when restarting ipa: >> >> # systemctl rest

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Fujisan
And with Firefox 50.0.2. F. On Wed, Dec 7, 2016 at 11:46 AM, Fujisan <fujisa...@gmail.com> wrote: > I have the same issue with version 4.4.2 > > $ rpm -qa|grep freeipa > freeipa-server-4.4.2-1.fc25.x86_64 > freeipa-python-compat-4.4.2-1.fc25.noarch > freeipa-server-co

Re: [Freeipa-users] Services missing in web-ui

2016-12-07 Thread Fujisan
I have the same issue with version 4.4.2 $ rpm -qa|grep freeipa freeipa-server-4.4.2-1.fc25.x86_64 freeipa-python-compat-4.4.2-1.fc25.noarch freeipa-server-common-4.4.2-1.fc25.noarch freeipa-common-4.4.2-1.fc25.noarch freeipa-server-trust-ad-4.4.2-1.fc25.x86_64 freeipa-client-4.4.2-1.fc25.x86_64

Re: [Freeipa-users] cannot access to freeipa client's linux share from windows

2016-12-02 Thread Fujisan
ot NTLMSSP neg_flags=0x62088215 NTLMSSP Sign/Seal - Initialising with flags: Got NTLMSSP neg_flags=0x62088215 SPNEGO login failed: Logon failure session setup failed: NT_STATUS_LOGON_FAILURE On Fri, Dec 2, 2016 at 10:57 AM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On pe, 02 joulu 2016,

Re: [Freeipa-users] cannot access to freeipa client's linux share from windows

2016-12-02 Thread Fujisan
Ok so why is it still not working? Any suggestion? On Fri, Dec 2, 2016 at 11:20 AM, Alexander Bokovoy <aboko...@redhat.com> wrote: > On pe, 02 joulu 2016, Fujisan wrote: > >> I'm not sure my problem is linked to this 'dedicated keytab file' with >> FILE: before the path

Re: [Freeipa-users] cannot access to freeipa client's linux share from windows

2016-12-02 Thread Fujisan
oko...@redhat.com> wrote: > On to, 01 joulu 2016, Fujisan wrote: > >> Hello, >> >> I have upgraded a client and a freeipa server from Fedora 24 to 25 >> recently. >> And I *cannot* access linux shares located on the F25 freeipa client from >> a >> win