Re: [Freeipa-users] IPA Service Restart causes clients to stop working

2014-07-08 Thread John Moyer
manually. Hello Bruno, see my reply to John, if you can capture the sssd logs, that would be very welcome in tracking down the problem. - Mensagem original - De: John Moyer john.mo...@digitalreasoning.com Para: Jakub Hrozek jhro...@redhat.com, freeipa-users@redhat.com Enviadas

[Freeipa-users] IPA Service Restart causes clients to stop working

2014-07-07 Thread John Moyer
on. Any suggestions how to fix the rest without having to go to all of them to restart sssd? Thanks, John Moyer Director, IT Operations -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com

Re: [Freeipa-users] IPA Service Restart causes clients to stop working

2014-07-07 Thread John Moyer
: On Mon, Jul 07, 2014 at 11:36:26AM -0400, John Moyer wrote: Hello All, Some of the services in IPA stopped responding and I restarted the service (as I couldn't login to the website or via ssh to any registered hosts). After the restart I could login to the web app, but still no clients

Re: [Freeipa-users] Problem finding new users via command line

2014-06-18 Thread John Moyer
information. On 6/17/14, 11:26 AM, Rob Crittenden wrote: John Moyer wrote: Sorry forgot the second part of your question: rpm -qa | grep ipa libipa_hbac-1.9.2-129.el6_5.4.x86_64 ipa-server-3.0.0-37.el6.x86_64 ipa-pki-ca-theme-9.0.3-7.el6.noarch python-iniparse-0.3.1-2.1.el6.noarch libipa_hbac

Re: [Freeipa-users] Problem finding new users via command line

2014-06-17 Thread John Moyer
-3.0.0-37.el6.x86_64 ipa-admintools-3.0.0-37.el6.x86_64 ipa-pki-common-theme-9.0.3-7.el6.noarch ipa-server-selinux-3.0.0-37.el6.x86_64 John On 6/17/14, 8:30 AM, John Moyer wrote: I'm using ldapsearch. The command I was using was like the one below (edited to protect creds/users). ldapsearch -x -h

[Freeipa-users] Problem finding new users via command line

2014-06-16 Thread John Moyer
ldapsearch work on new users would be greatly appreciated! Thanks, John Moyer ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa

[Freeipa-users] IPA not Starting after crash

2014-02-13 Thread John Moyer
in LDAP: No master found because of error: {'matched': 'dc=digitalreasoning,dc=com', 'desc': 'No such object'} Thanks, _ John Moyer Director, IT Operations signature.asc Description: Message signed with OpenPGP using GPGMail

Re: [Freeipa-users] IPA not Starting after crash

2014-02-13 Thread John Moyer
-DIGITALREASONING-COM/ lrwxrwxrwx 1 root root 12 Aug 27 03:21 db - /dev/shm/db/ At this point I just want confirmation that my data is gone. I was doing backups, but of the disks not the RAM. Thanks, _ John Moyer Director, IT Operations On Feb

Re: [Freeipa-users] IPA Load Problems?

2013-09-04 Thread John Moyer
run circles around IPA even though it was on a smaller machine. LDAP would run at about 10% maybe 15% CPU when the JIRA sync ran. IF you need any other information let me know. Thanks, _ John Moyer Director, IT Operations On Sep 4

Re: [Freeipa-users] IPA Load Problems?

2013-09-04 Thread John Moyer
Sure, just let me know what needs to be run/applied. I've already rolled back to LDAP, so if the fix looks like it works I can then roll it out again. Thanks, _ John Moyer Director, IT Operations On Sep 4, 2013, at 9:12 AM, Dmitri Pal d

Re: [Freeipa-users] IPA Load Problems?

2013-09-04 Thread John Moyer
or so to do the sync. The logs didn't show but one search done that didn't have an index which is why we concluded it wasn't an index issue. Thanks, _ John Moyer Director, IT Operations On Sep 4, 2013, at 9:51 AM, Martin Kosek mko

Re: [Freeipa-users] IPA Load Problems?

2013-08-30 Thread John Moyer
((objectclass=inetorgperson)(uid=senior.developer.login)) 307 (objectclass=krbticketpolicyaux) 292 (uid=*) Thanks, _ John Moyer Director, IT Operations Digital Reasoning Systems, Inc. john.mo...@digitalreasoning.com Office

Re: [Freeipa-users] IPA Load Problems?

2013-08-30 Thread John Moyer
, _ John Moyer Director, IT Operations On Aug 30, 2013, at 3:41 PM, Rich Megginson rmegg...@redhat.com wrote: On 08/30/2013 01:31 PM, John Moyer wrote: Rob or anyone else, So while struggling along on this server I just grabbed the logs off it and ran that log program

Re: [Freeipa-users] IPA Load Problems?

2013-08-30 Thread John Moyer
I'm sorry that was my top unique filter list not my unindexed list. Please disregard my last email. Thanks, _ John Moyer Director, IT Operations Digital Reasoning Systems, Inc. john.mo...@digitalreasoning.com Office: 703.678.2311 Mobile

Re: [Freeipa-users] IPA Load Problems?

2013-08-28 Thread John Moyer
So this method of search logs is great, and it shows some indexes that would likely highly increase efficiency with my usage. So, are there instructions how to do that? or do you know off hand how to do that? Thanks, _ John Moyer

Re: [Freeipa-users] IPA Load Problems?

2013-08-27 Thread John Moyer
, _ John Moyer Director, IT Operations On Aug 7, 2013, at 4:08 PM, John Moyer john.mo...@digitalreasoning.com wrote: Thanks, _ John Moyer Director, IT Operations Digital Reasoning Systems

Re: [Freeipa-users] IPA Load Problems?

2013-08-27 Thread John Moyer
, _ John Moyer Director, IT Operations On Aug 27, 2013, at 10:14 AM, Rob Crittenden rcrit...@redhat.com wrote: John Moyer wrote: Ok, so we tried to implement this again, and as soon as we put on a server that authenticates heavily the IPA came

Re: [Freeipa-users] IPA Load Problems?

2013-08-27 Thread John Moyer
Is there any way to see what fields are index'ed? Thanks, _ John Moyer Director, IT Operations Digital Reasoning Systems, Inc. john.mo...@digitalreasoning.com Office: 703.678.2311 Mobile: 240.460.0023 Fax:703.678.2312

Re: [Freeipa-users] IPA Load Problems?

2013-08-27 Thread John Moyer
Binds:0 Failed SSL Client Binds: 0 SASL Binds: 1466 1458 GSSAPI 8 EXTERNAL Directory Manager Binds: 10 Anonymous Binds: 1476 Other Binds: 60657 Thanks, _ John Moyer

[Freeipa-users] IPA Load Problems?

2013-08-05 Thread John Moyer
is there an easy place to set log rotation settings? (If it's log rotate just let me know, I just don't want to step on an internal app rotate). Thanks, _ John Moyer Director, IT Operations signature.asc Description: Message signed with OpenPGP

Re: [Freeipa-users] exporting ldap certificate

2013-07-23 Thread John Moyer
Peter, Did you get this to work, I know this is an old thread, but where did you put those java parameters? I am trying to get GADS to work for my IPA server and think this is my problem. Thanks, _ John Moyer On May 7, 2013, at 4:37 AM

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-06-10 Thread John Moyer
be authenticated with known CA certificates Installation failed. Rolling back changes. IPA client is not configured on this system. Any additional suggestions? Thanks, _ John Moyer Director, IT Operations On May 29, 2013, at 2:09 PM, Rob Crittenden rcrit

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-06-10 Thread John Moyer
were wrong before all of them stemmed from putting in the Godaddy signed cert. Thanks, _ John Moyer Director, IT Operations On Jun 10, 2013, at 2:30 PM, Dmitri Pal d...@redhat.com wrote: On 06/10/2013 02:17 PM, John Moyer wrote: I don't

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-06-10 Thread John Moyer
, _ John Moyer Director, IT Operations Digital Reasoning Systems, Inc. john.mo...@digitalreasoning.com Office: 703.678.2311 Mobile: 240.460.0023 Fax:703.678.2312 www.digitalreasoning.com On Jun 10, 2013, at 4:19 PM, Rob Crittenden rcrit...@redhat.com wrote

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-29 Thread John Moyer
server failed: Local error May 29 13:16:15 ip- named[9076]: loading configuration: failure May 29 13:16:15 ip- named[9076]: exiting (due to fatal error) Thanks, _ John Moyer Director, IT Operations On May 29, 2013, at 4:11 AM, Petr Spacek pspa

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-29 Thread John Moyer
.,, MyIPACTu,Cu,u Thanks, _ John Moyer Director, IT Operations On May 29, 2013, at 8:36 AM, John Dennis jden...@redhat.com wrote: On 05/29/2013 01:42 AM, John Moyer wrote: Yea I replaced

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-29 Thread John Moyer
is not configured on this system. Thanks, _ John Moyer Director, IT Operations On May 29, 2013, at 12:20 PM, Rob Crittenden rcrit...@redhat.com wrote: John Moyer wrote: John, I see the following when I ran that first command

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-24 Thread John Moyer
error: Enter LDAP Password: modifying entry cn=cacert,cn=ipa,cn=etc,dc=digitalreasoning,dc=com ldap_modify: Object class violation (65) additional info: attribute cacert not allowed Anyone have any ideas? Thanks, _ John Moyer

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-24 Thread John Moyer
certificate cannot be authenticated with known CA certificates Installation failed. Rolling back changes. IPA client is not configured on this system. Thanks, _ John Moyer Director, IT Operations On May 24, 2013, at 3:11 PM, Rob Crittenden

Re: [Freeipa-users] Installing a Godaddy Cert with ipa-server-certinstall

2013-05-23 Thread John Moyer
Installation failed. Rolling back changes. 2013-05-23T17:45:16Z ERROR IPA client is not configured on this system. Thanks, _ John Moyer Director, IT Operations Digital Reasoning Systems, Inc. john.mo...@digitalreasoning.com Office: 703.678.2311

[Freeipa-users] automember issues

2013-04-30 Thread John Moyer
to specify more than just build in the expression area? Thanks, _ John Moyer ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
Yep, enrolledby is what I'm using, but I have been adding them manually since it hasn't been working. Thanks, _ John Moyer On Apr 30, 2013, at 1:21 PM, JR Aquino jr.aqu...@citrix.com wrote: On Apr 30, 2013, at 9:30 AM, John Moyer

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
there shouldn't be a permissions issue. Thanks, _ John Moyer On Apr 30, 2013, at 1:21 PM, JR Aquino jr.aqu...@citrix.com wrote: On Apr 30, 2013, at 9:30 AM, John Moyer john.mo...@digitalreasoning.commailto:john.mo...@digitalreasoning.com wrote

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
, _ John Moyer On Apr 30, 2013, at 1:48 PM, JR Aquino jr.aqu...@citrix.com wrote: On Apr 30, 2013, at 10:43 AM, John Moyer john.mo...@digitalreasoning.com wrote: One thing to add is that this build user only has the following access: Host

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
It comes back with a ton of stuff the row you are probably interested in is this one: enrolledby: uid=build,cn=users,cn=accounts,dc=example,dc=com Thanks, _ John Moyer On Apr 30, 2013, at 1:57 PM, JR Aquino jr.aqu...@citrix.com wrote

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
, _ John Moyer On Apr 30, 2013, at 2:07 PM, JR Aquino jr.aqu...@citrix.com wrote: On Apr 30, 2013, at 11:02 AM, John Moyer john.mo...@digitalreasoning.com wrote: It comes back with a ton of stuff the row you are probably interested in is this one

Re: [Freeipa-users] automember issues

2013-04-30 Thread John Moyer
So I must have looked at the wrong server name, I just tried to add 4 more servers and none of them worked. Anymore ideas? The target is specified by the rule name test-group is the target. Thanks, _ John Moyer On Apr 30, 2013, at 2

Re: [Freeipa-users] sudo / sssd integration problems

2013-03-21 Thread John Moyer
%admins ALL=(ALL) NOPASSWD: ALL /etc/sudoers Thanks, _ John Moyer On Mar 21, 2013, at 11:27 PM, Brian Cook bc...@redhat.com wrote: Running F18 and following the instructions here: http://jhrozek.fedorapeople.org/sssd/1.9.1/man/sssd-sudo.5.html

Re: [Freeipa-users] sudo / sssd integration problems

2013-03-21 Thread John Moyer
Sorry that's all I have in my notes. I'm sure others will have ideas. Sorry I couldn't be more help. Thanks, _ John Moyer On Mar 21, 2013, at 11:50 PM, Brian Cook bc...@redhat.com wrote: Those packages are installed. The second part

[Freeipa-users] Mail Challenge Password Reset

2013-03-19 Thread John Moyer
before giving up hope. Thanks, _ John Moyer ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Allow IPA Join and remove only

2013-03-14 Thread John Moyer
yielded nothing). Thanks, _ John Moyer Digital Reasoning Systems, Inc. ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Cannot obtain CA Certificate

2013-02-26 Thread John Moyer
Content-Length: 1856 Connection: close Content-Type: text/html; charset=UTF-8 Thanks, _ John Moyer On Feb 19, 2013, at 6:35 AM, Jan-Frode Myklebust janfr...@tanso.net wrote: ipa : ERRORCannot obtain CA certificate 'ldap

[Freeipa-users] Cannot obtain CA Certificate

2013-02-18 Thread John Moyer
, _ John Moyer ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users