Re: [Freeipa-users] IPA Compat + ID Views + AIX 7.1

2017-05-16 Thread Bjarne Blichfeldt
ption. Regards Bjarne Blichfeldt. From: Luiz Fernando Vianna da Silva [mailto:luiz.via...@tivit.com.br] Sent: 16. maj 2017 16:43 To: Bjarne Blichfeldt ; freeipa-users@redhat.com Subject: Re: [Freeipa-users] IPA Compat + ID Views + AIX 7.1 As far as I found out, it is not possible to integrate sudo rules

Re: [Freeipa-users] IPA Compat + ID Views + AIX 7.1

2017-05-14 Thread Bjarne Blichfeldt
rules from IPA into AIX. sudo on aix does not support that. You will have to maintain /etc/sudoers by som other means. Hope that helps, good luck. Regards Bjarne Blichfeldt. From: wouter.hummel...@kpn.com [mailto:wouter.hummel...@kpn.com] Sent: 12. maj 2017 16:03 To: iulian.ro...@gmail.com Cc

Re: [Freeipa-users] ipa-replica-install failes on setup-ca

2017-04-26 Thread Bjarne Blichfeldt
completely and start all over. Now the replica is working again. Server must have had a brain damage at some point. Venlig hilsen Bjarne Blichfeldt Infrastructure Services Direkte +4563636119 Mobile +4521593270 b...@jndata.dk JN Data A/S * Havsteensvej 4 * 4000 Roskilde Telefon 63 63 63 63/ Fax

[Freeipa-users] ipa-replica-install failes on setup-ca

2017-04-24 Thread Bjarne Blichfeldt
roblem can be resolved. p11-kit: couldn't open and map file: /etc/pki/ca-trust/source/ipa.p11-kit: Permission denied I changed the permission on /etc/pki/ca-trust/source/ipa.p11-kit from 600 to 644 and added "NSSEnforceValidCerts off" to /etc/httpd/conf.d/nss.conf After that ipa-ce

Re: [Freeipa-users] nfsv4+kerberos: group ID not mapped on newly create users, however user id is correct

2016-12-08 Thread Bjarne Blichfeldt
> -Original Message- > From: David Kupka [mailto:dku...@redhat.com] > Sent: 8. december 2016 09:40 > To: Bjarne Blichfeldt ; freeipa-users@redhat.com > Subject: Re: [Freeipa-users] nfsv4+kerberos: group ID not mapped on newly > create users, however user id is correct &

Re: [Freeipa-users] nfsv4+kerberos: group ID not mapped on newly create users, however user id is correct

2016-12-08 Thread Bjarne Blichfeldt
se I ran a ipa-server-upgrade, which did not resolve the issue. Regards Bjarne Blichfeldt. From: Bjarne Blichfeldt Sent: 6. december 2016 14:29 To: freeipa-users@redhat.com Subject: nfsv4+kerberos: group ID not mapped on newly create users, however user id is correct VERSION: 4.4.0, API_VERS

[Freeipa-users] directory server does not start after a system reboot

2016-11-28 Thread Bjarne Blichfeldt
529edd4-d9f0aefc.sema; NSPR error - -5943 The access log is not touched. Is there a debug flag somewhere I can add to get further info? Venlig hilsen Bjarne Blichfeldt Infrastructure Services Direkte +4563636119 Mobile +4521593270 b...@jndata.dk [cid:image002.png@01D24975.811CB830]

Re: [Freeipa-users] keytab kvno differs between ipa servers

2016-11-22 Thread Bjarne Blichfeldt
nt shortly. Regards Bjarne Blichfeldt. -Original Message- From: Lukas Slebodnik [mailto:lsleb...@redhat.com] Sent: 22. november 2016 10:25 To: Bjarne Blichfeldt Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] keytab kvno differs between ipa servers On (21/11/16 13:54), Bjarne Blichf

Re: [Freeipa-users] keytab kvno differs between ipa servers

2016-11-21 Thread Bjarne Blichfeldt
ok Thanks I will try to debug that. No errors in the logs, the ldapsearch from your link works fine.. ok work ahead... Regards Bjarne Blichfeldt -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Petr Spacek Sent: 21

[Freeipa-users] keytab kvno differs between ipa servers

2016-11-21 Thread Bjarne Blichfeldt
avoid this? Regards Bjarne Blichfeldt -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Client x.x.xx - RFC 1918 response from Internet in /var/log/messages

2016-11-17 Thread Bjarne Blichfeldt
Excellent - thanks. I was missing some forward statements for a few private segments. Venlig hilsen Bjarne Blichfeldt -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Petr Spacek Sent: 16. november 2016 14:36 To

[Freeipa-users] Client x.x.xx - RFC 1918 response from Internet in /var/log/messages

2016-11-16 Thread Bjarne Blichfeldt
ssages has returned. I read in the changelog for 4.4 that this issue was resolved. What did I miss? Venlig hilsen Bjarne Blichfeldt Infrastructure Services Direkte +4563636119 Mobile +4521593270 b...@jndata.dk [cid:image005.png@01D24008.CA6EF0F0] JN Data A/S * Havsteensvej

Re: [Freeipa-users] krb5 and nfsv4 not working right

2016-11-15 Thread Bjarne Blichfeldt
/krb5cc_%U cred_store = client_keytab:/var/lib/gssproxy/clients/%U.keytab cred_usage = initiate allow_any_uid = yes trusted = yes euid = 0 Regards, Bjarne Blichfeldt -Original Message- From: Tony Brian Albers [mailto:t...@statsbiblioteket.dk] Sent: 15. november 2016 13:18 To

Re: [Freeipa-users] FreeIPA (Add Replica fails on GSSAPI)

2016-07-13 Thread Bjarne Blichfeldt
Well, I just had the same problem, but in my case I also tried to install a ca: “ipa-replica-install --setup-ca …..” Without “--set-up” the installation succeeded. Regards, Bjarne From: Devin Acosta [mailto:linuxguru...@gmail.com] Sent: 12. juli 2016 21:35 To: freeipa-users@redhat.com Subject

Re: [Freeipa-users] Using 3rd party certificates for HTTP/LDAP (again) (SOLVED)

2016-07-06 Thread Bjarne Blichfeldt
The solution was to add to root certificate to tomcat: /var/lib/pki/pki-tomcat/alias/ Now everything seems to work. Regards Bjarne From: freeipa-users-boun...@redhat.com [mailto:freeipa-users-boun...@redhat.com] On Behalf Of Bjarne Blichfeldt Sent: 23. juni 2016 13:40 To: freeipa-users

Re: [Freeipa-users] Replace with 3rd part certificates

2016-06-27 Thread Bjarne Blichfeldt
For the time being and as far as I can see until IPA 4.3.1, the procedure is messy and difficult. The following thread will be a big help: https://www.redhat.com/archives/freeipa-users/2016-January/msg00223.html I think I succeeded at last, but further tests remain. Regards, Bjarne -Origi

Re: [Freeipa-users] Using 3rd party certificates for HTTP/LDAP (again)

2016-06-23 Thread Bjarne Blichfeldt
Following this thread from January: https://www.redhat.com/archives/freeipa-users/2016-January/msg00223.html I am trying to accomplish the same, but seems to be stuck. My environment is: # cat /etc/redhat-release Red Hat Enterprise Linux Server release 7.2 (Maipo) # ipa ping -

[Freeipa-users] /var/log/dirsrv/slapd-*/acces: SSL peer cannot verify your certificate

2016-04-26 Thread Bjarne Blichfeldt
operation cannot be completed: Unable to communicate with CMS (Internal Server Error) Anybody have an idea of what I missed? Venlig hilsen Bjarne Blichfeldt Infrastructure Services Direkte +4563636119 Mobile +4521593270 b...@jndata.dk [cid:image002.png@01D19FD4.9D73F340] JN Data

Re: [Freeipa-users] Using 3rd party certificates for HTTP/LDAP

2016-04-26 Thread Bjarne Blichfeldt
el6 (ipa-client 3.0.xx) and rhel7.1 (ipa-client 4.1.xx), Regards, Bjarne Blichfeldt [cid:image002.png@01D19FCC.DE1B7060] JN Data A/S * Havsteensvej 4 * 4000 Roskilde Telefon 63 63 63 63/ Fax 63 63 63 64 www.jndata.dk [cid:image004.png@01D19FCC.DE1B7060] -- Manag