Re: [Freeipa-users] Freeipa and FQDN requirement

2016-07-25 Thread Ilan Green
Thanks, 
The issue per customer is having loads of legacy applications programmed to use 
short host names - it will be cumbersome to fix it 

Ilan Green 
Senior Technical Account Manager - EMEA 
Red Hat 
Mobile (+972) 52 3403218 
email: igr...@redhat.com 

- Original Message -

> From: "Petr Spacek" <pspa...@redhat.com>
> To: freeipa-users@redhat.com
> Sent: Monday, July 25, 2016 4:01:39 PM
> Subject: Re: [Freeipa-users] Freeipa and FQDN requirement

> On 25.7.2016 14:49, Ilan Green wrote:
> > Hello,
> > Customer wants to switch between the IPA server FQDN and short name in
> > /etc/hosts (having the short name first) post IPA install?
> >
> > Can anyone please confirm that the suggestions & reservations listed by
> > Simo Sorce in the following thread still apply - i.e. no RFE was ever
> > applied yet?
> > https://www.redhat.com/archives/freeipa-users/2014-August/thread.html#00079
> >
> > mainly:
> > https://www.redhat.com/archives/freeipa-users/2014-August/thread.html#00104
> > https://www.redhat.com/archives/freeipa-users/2014-August/thread.html#00105

> This might or might not work, we do not test this scenario.

> In any case it goes directly against procedures in official docs:

> https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/installing-ipa.html#dns-reqs

> ... so do not be surprised if things break.

> In general we strongly recommend to use a dedicated machine for IdM server
> for
> security reasons. There should be no technical reason not to use FQDN
> hostname
> for a dedicated VM as the requirement for short names as hostname usually
> comes from crappy applications.

> --
> Petr^2 Spacek

> --
> Manage your subscription for the Freeipa-users mailing list:
> https://www.redhat.com/mailman/listinfo/freeipa-users
> Go to http://freeipa.org for more info on the project
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

[Freeipa-users] Freeradius, IPA network switch authentication authorization

2015-12-15 Thread Ilan Green
Has anyone ever set Freeradius & IPA for network devices like Cisco and 
Juniper. 
Having the need to provide the network device back with the authorization level 
e.g. for Cisco 1 to 15. 

This seems similar to some extent to the following: 
https://www.redhat.com/archives/freeipa-users/2013-September/msg00058.html 
Suggesting to implement it within the Freeradius. 

Question is whether anyone has gone beyond it and has an example for such an 
implementation? 

Thanks, 


Ilan Green 
Senior Technical Account Manager - EMEA 
Red Hat 
Mobile (+972) 52 3403218 
email: igr...@redhat.com 

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project