Re: [Freeipa-users] Password Complexity Requirements Seems Insufficient

2016-10-12 Thread Anon Lister
Unfortunately, policy and regulation often lag behind current theory by several decades. For what it's worth, I'd second being able to set more complicated policies as a useful feature. On Oct 12, 2016 6:38 PM, "Simpson Lachlan" wrote: > > -Original Message- > > From: freeipa-users-boun.

Re: [Freeipa-users] IPA and FIPS 140-2

2016-08-04 Thread Anon Lister
Sorry, certified openssl implementation* On Aug 4, 2016 9:38 AM, "Anon Lister" wrote: > I'd also like to throw in that the requirements you are facing are likely > requiring FIPS Certified, not just compliant, as I'm somewhat familiar with > them. (800-53 or 800

Re: [Freeipa-users] IPA and FIPS 140-2

2016-08-04 Thread Anon Lister
I'd also like to throw in that the requirements you are facing are likely requiring FIPS Certified, not just compliant, as I'm somewhat familiar with them. (800-53 or 800-171) Essentially it will have to fall back on the FIPS compliant openssl implementation, however I believe there are other cryp

Re: [Freeipa-users] Account/password expirations

2016-04-29 Thread Anon Lister
Yep sorry I missed that. You need to put your public keys in IPA. On Apr 29, 2016 3:32 AM, "Jakub Hrozek" wrote: On Thu, Apr 28, 2016 at 09:14:48PM -0400, Prasun Gera wrote: > > > > Your can still authenticate with SSH keys, but to access any NFS 4 shares > > they will need a Kerberos ticket, whi

Re: [Freeipa-users] Account/password expirations

2016-04-28 Thread Anon Lister
Your can still authenticate with SSH keys, but to access any NFS 4 shares they will need a Kerberos ticket, which can be obtained via a 'kinit' after logging in. I forget what the default timeout is but they do expire, and at that point access to those shares (by a user or process acting as that us

Re: [Freeipa-users] [requirements gathering] Notification system / hooks

2016-03-10 Thread Anon Lister
Well... I suppose that's problem #2. Problem #1 would be implementing the bidirectional authentication in the first place. :p On Mar 10, 2016 11:22 AM, "Petr Spacek" wrote: > On 10.3.2016 17:20, Anon Lister wrote: > > I would like an alert when my IPA servers

Re: [Freeipa-users] [requirements gathering] Notification system / hooks

2016-03-10 Thread Anon Lister
I would like an alert when my IPA servers successfully establish a bidirectional trust with mutual authentication with our AD server Actually I could even skip the alert ;) On Mar 9, 2016 11:27 AM, "Petr Spacek" wrote: > Dear users, > > FreeIPA team is thinking about adding notification syste

Re: [Freeipa-users] Fwd: Creating Trusts with AD - (RH#878168, FIPA#3266)

2016-01-20 Thread Anon Lister
So I had the same problem. For me it ended up being that some attribute was not created correctly in 389 using the instructions in the guide. I don't remember what it was off the top of my head. Something about a default user or group SID I think. Had to turn samba logging up. Eventually it shows t

[Freeipa-users] Bi directional login with AD trusts

2015-12-30 Thread Anon Lister
Hello, New to list. This is kind of a followup to the post here: https://www.redhat.com/archives/freeipa-users/2015-January/msg00351.html We are one of the odder shops that runs almost entirely linux, but the need to support some windows stuff that requires AD has come up. We have things setup as