[Freeipa-users] krbPasswordExpiration field not updating?

2012-05-07 Thread freeipa
: 20120506011529Z So now when the user(s) logs in, I'm getting password will expire in XX days messages. Any ideas? Can I globally update this somehow, otherwise I'll be re-typing passwords for a while. cya Craig ___ Freeipa-users mailing list

Re: [Freeipa-users] krbPasswordExpiration field not updating?

2012-05-08 Thread freeipa
___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] krbPasswordExpiration field not updating?

2012-05-09 Thread freeipa
for all affected principals in LDAP? Just to prevent confusion? I like variant 2, because variant 1 seems to be confusing to me. Craig, what is user opinion? Petr^2 Spacek ___ Freeipa-users mailing list Freeipa-users@redhat.com The thing

[Freeipa-users] Acrobat Reader errors on Centos 5.8 (getpwuid_r(): failed due to unknown user id)

2012-05-10 Thread freeipa
$ cd /tmp/gconfd-somebody $ ln -s /tmp/gconfd-craig/lock/ior cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Acrobat Reader errors on Centos 5.8 (getpwuid_r(): failed due to unknown user id)

2012-05-10 Thread freeipa
___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] ipa-client-install hangs on Centos 5.2x64

2012-05-16 Thread freeipa
: 2012-05-16 18:04:36,006 DEBUG stderr= 2012-05-16 18:06:01,902 DEBUG args=kdestroy 2012-05-16 18:06:01,902 DEBUG stdout= 2012-05-16 18:06:01,902 DEBUG stderr= ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo

[Freeipa-users] ipa-client-install hangs on ipa-getkeytab

2012-05-28 Thread freeipa
-s ipa-server.example.com -p host/client.example@example.com -k /etc/krb5.keytab cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] ipa-client-install hangs on ipa-getkeytab - Fixed!!

2012-05-29 Thread freeipa
@example.com 1 host/client.example@example.com 1 host/client.example@example.com Martin cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] ipa-client-install hangs on ipa-getkeytab - Fixed!!

2012-05-30 Thread freeipa
___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] su: [ID 219349 auth.debug] pam_unix_auth: user craig not found (Solaris 10 IPA client)

2012-06-04 Thread freeipa
:/bin/bash Plus kerberos works, when simply running `kinit craig`. Any tips?? cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] su: [ID 219349 auth.debug] pam_unix_auth: user craig not found (Solaris 10 IPA client)

2012-06-05 Thread freeipa
-- = ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Postfix IPA

2012-07-02 Thread freeipa
their one solution to ensure the safety of mail delivery with IPA? cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Failed to initialize credentials using keytab

2012-07-10 Thread freeipa
@example.com 2 host/sysvm-ipa.example@example.com 2 host/sysvm-ipa.example@example.com 2 host/sysvm-ipa.example@example.com 2 host/sysvm-ipa.example@example.com 2 host/sysvm-ipa.example@example.com cya Craig ___ Freeipa

[Freeipa-users] IPA Server

2012-07-31 Thread freeipa
last night too. Sounds like a bug in the ipa shutdown script? cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Default Expiry on IPA?

2012-08-28 Thread freeipa
to extend it is via LDAP and the krbPasswordExpiration: attribute? cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Error: Fedora 18 client to IPA Server 2.2.0?

2013-01-21 Thread freeipa
Hi, Has anyone had success with installing the IPA client on Fedora 18 (with SeLinux disabled)? Server: Red Hat Enterprise Linux Server release 6.3 (Santiago) * ipa-server-2.2.0-16.el6.x86_64 Client: Fedora release 18 (Spherical Cow) * freeipa-client-3.1.0-2.fc18.x86_64 Error: I installed

[Freeipa-users] Unable to start replica server after setting up replication

2013-01-29 Thread freeipa
): no mechanism available: ', 'desc': 'Unknown authentication method'} Shutting down Shutting down dirsrv: CLIFF-CLOUDBURRITO-COM... [ OK ] PKI-IPA... [ OK ] ___ Freeipa-users

Re: [Freeipa-users] Unable to start replica server after setting up replication

2013-01-29 Thread freeipa
: RUNNING Unknown error when retrieving list of services from LDAP: {'info': 'SASL(-4): no mechanism available: ', 'desc': 'Unknown authentication method'} ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo

Re: [Freeipa-users] Unable to start replica server after setting up replication

2013-01-30 Thread freeipa
anything in the documentation about having to copy and edit it manually. Thanks -Patrick ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Unable to start replica server after setting up replication

2013-01-30 Thread freeipa
, in main raise RuntimeError(Failed to configure the client) ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Unable to start replica server after setting up replication

2013-01-30 Thread freeipa
: [ OK ] 2013-01-30T16:28:38Z DEBUG stderr=cat: /var/run/sssd.pid: No such file or directory ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Unable to start replica server after setting up replication

2013-01-30 Thread freeipa
of SSSD did not go that smoothly. sssd started up fine, it's running right now. Looks like a race condition, the pid file has an mtime of 16:28:38, the same second as the No such file or directory error. ___ Freeipa-users mailing list Freeipa-users@redhat.com

[Freeipa-users] FQDN Hostname Requirement

2013-02-26 Thread freeipa
Hi All, Spec: Red Hat Enterprise Linux Server release 6.3 (Santiago) ipa-server-2.2.0-16.el6.x86_64 Issue: I made a post a while back regarding IPA and the forcing of the hostname to be a FQDN entry, rather than utilising `hostname --fqdn` ref: https://www.redhat.com/archives/freeipa-users/2012

[Freeipa-users] Host based 2FA ?

2014-12-11 Thread freeipa
that. Is it possible? Help on how would be great. If not, feature request? thanks, -t -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go To http://freeipa.org for more info on the project

[Freeipa-users] Issue upgrading freeipa to ipa-server-4.4.0-14.el7.centos.4.x86_64

2017-03-08 Thread freeipa
is is my only ipa server (setting up a secondary master have been on my todo list). Can you help me troubleshoot this? Or should I just setup a replica and propagate it to primary node for all clients and then reinstall the one that have problem? Thank you in advance! //Robert -- Manage yo

[Freeipa-users] Odd dereference processing failed : Input/output error

2013-09-22 Thread craig . freeipa
Hi, Spec: Fedora release 19 * freeipa-client-3.3.0-2.fc19.x86_64 * sssd-ipa-1.11.0-0.2.beta2.fc19.x86_64 I've got a PC that keeps crashing Anyone see this error before? Note: the dbus messages may be unrelated. File: /var/log/messages Sep 20 16:40:03 craigpc sssd[be[teratext.saic.com.au

[Freeipa-users] Certificate format error: [Errno -8018]

2014-01-22 Thread craig . freeipa
': [Errno -12269] (SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired. Any advise would be greatly appreciated! cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Certificate format error: [Errno -8018]

2014-01-27 Thread craig . freeipa
! http://www.freeipa.org/page/Howto/CA_Certificate_Renewal Since you have FreeIPA before 3.4, you need to follow manual procedure outlined on that page. 2.2 might also be a bit different than 3.x but this is a starting point. For 2.x you want http://www.freeipa.org/page

Re: [Freeipa-users] Certificate format error: [Errno -8018]

2014-01-28 Thread craig . freeipa
] (SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired. Any advise would be greatly appreciated! http://www.freeipa.org/page/Howto/CA_Certificate_Renewal Since you have FreeIPA before 3.4, you need to follow manual procedure outlined on that page. 2.2 might also be a bit different than 3.x

Re: [Freeipa-users] Certificate format error: [Errno -8018]

2014-01-29 Thread craig . freeipa
-ipa.teratext.saic.com.au:443/ca/agent/ca/displayBySerial': [Errno -12269] (SSL_ERROR_EXPIRED_CERT_ALERT) SSL peer rejected your certificate as expired. Any advise would be greatly appreciated! http://www.freeipa.org/page/Howto/CA_Certificate_Renewal Since you have FreeIPA before 3.4, you

Re: [Freeipa-users] Certificate format error: [Errno -8018]

2014-01-29 Thread craig . freeipa
Not After : Tue Jan 14 06:45:05 2014 cya Craig ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Still unclear about relation between IPA DNS domain and company DNS domain.

2016-12-07 Thread freeIPA users list
should use a DNS subdomain like ipa.lautus.net for the IPA domain, or not. It is really depending on your deployment details. If you already have some other Kerberized environment in place and you are not going to replace it by FreeIPA, then you need to make sure that new FreeIPA deployment would