Re: [Freeipa-users] How grant access to userPassword for System Accounts

2015-10-27 Thread John Duino
Hmmm seems I have been misinformed, then. And then why does it have a field for 'mapping' the password? Well, I think that's off-topic for the list. I'll dig more later today. -- John Duino - Original Message - From: "Alexander Bokovoy" <aboko...@redhat.com> To: &

[Freeipa-users] How grant access to userPassword for System Accounts

2015-10-26 Thread John Duino
I am trying to hook our VoIP solution (sipxecs-based openUC) to our FreeIPA. But it appears that it wants to read-in the userPassword rather than just auth against the ldap. I know Directory Manager is the only account that has the ability to read userPassword, but is there a way to grant that

[Freeipa-users] How to add multivalued attribute to UI

2015-09-16 Thread John Duino
Greetings! I am wanting to add a multivalued attribute (mailAlternateAddress, from objectClass:MailRecipient) to the User UI. We are running IPA 4.1.0-18.el7.centos.4.x86_64, on CentOS7. Adding it to the CLI was fairly straightforward. I have a plugin at

Re: [Freeipa-users] How to add multivalued attribute to UI

2015-09-16 Thread John Duino
Oh, okay. I didn't realize the ipalib plugin affected the UI. Sure, I can share it. So in /usr/lib/python2.7/site-packages/ipalib/plugins/altemail.py is the following. I have also (at one point) had a validation function and a precallback (both currently not used when trying to simplify/test).

Re: [Freeipa-users] How to add multivalued attribute to UI

2015-09-16 Thread John Duino
temail_pre_op); return altemail_plugin; }); - Original Message - From: "John Duino" <jdu...@oblong.com> To: "freeipa-users" <freeipa-users@redhat.com> Sent: Wednesday, September 16, 2015 1:16:13 PM Subject: Re: [Freeipa-users] How to add multivalued attribute to UI

Re: [Freeipa-users] How to add multivalued attribute to UI

2015-09-16 Thread John Duino
You shot right past me there, Rob. Forgive my ignorance but I'm not sure what you are referring to when saying "this configured", or what you are calling metadata. What I included was the user plugin. The UI loads it without error. But it only supplies a single field (which is correct) that

[Freeipa-users] How to determine cause/source of user lockout?

2016-05-17 Thread John Duino
Is there a (relatively easy) way to determine what is causing a user account to be locked out? The admin account on our 'primary' ipa host is locked out frequently, but somewhat randomly; sometimes it will be less than 5 minutes it is available, and other times several hours. ipa user-status