Re: [Freeipa-users] posix ids not propgating

2015-04-17 Thread Bryan Pearson
On Fri, Apr 17, 2015 at 9:19 AM, Rob Crittenden rcrit...@redhat.com wrote: Bryan Pearson wrote: I believe that my master dna server isnt currently being used, so I did this. ldapsearch -x -D 'cn=Directory Manager' -W -b cn=posix-ids,cn=dna,cn=ipa,cn=etc,dc=EXAMPLE,dc=lan Enter LDAP Password

Re: [Freeipa-users] posix ids not propgating

2015-04-17 Thread Bryan Pearson
On Fri, Apr 17, 2015 at 7:08 AM, Sumit Bose sb...@redhat.com wrote: On Fri, Apr 17, 2015 at 06:36:24AM -0400, Bryan Pearson wrote: Should I add the same range to this machine or give each one it's own id range? The ranges are global for the whole IPA domain. The idranges manages with the ipa

[Freeipa-users] posix ids not propgating

2015-04-16 Thread Bryan Pearson
I ran this comand on each of my IPA servers and one returned usable response: ipa idrange-find --- 1 range matched --- Range name: HOSTNAME.LAN_id_range First Posix ID of the range: 192020 Number of IDs in the range: 30 Range type: local domain range

Re: [Freeipa-users] chrony support

2015-02-13 Thread Bryan Pearson
Is installing chrony first a requirement or can it be installed after machine has been setup and is running ipa? Bryan On Fri, Feb 13, 2015 at 9:01 AM, Martin Kosek mko...@redhat.com wrote: On 02/13/2015 01:32 PM, David Kupka wrote: Hello Bryan, I'm currently working on this. This feature

[Freeipa-users] chrony support

2015-02-13 Thread Bryan Pearson
One of our IPA servers, is in a virtualized environment and is continuously losing time, resulting in invalid credentials and breaking replication. We are interested in using chrony instead of ntpd, while ipa start up and use chrony instead of ntp? Bryan -- Manage your subscription for the

Re: [Freeipa-users] SASL(-13) authentication failure

2015-02-07 Thread Bryan Pearson
to the problem? Bryan On Sat, Feb 7, 2015 at 12:17 AM, Bryan Pearson bwp.pear...@gmail.com wrote: I did a bit more digging into the issue, and realized that the ruv-id of ipa2 is different on only one of the servers of the 3. I am imaging I will need to run clean-ruv on inconsistent node

[Freeipa-users] SASL(-13) authentication failure

2015-02-06 Thread Bryan Pearson
Hello, My IPA servers are currently saying: Failed to get data from 'hostname.lan': Invalid credentials SASL(-13): authentication failure: GSSAPI Failure: gss_accept_sec_context tail -f /var/log/dirsrv/slapd-HOSTNAME-LAN/errors [06/Feb/2015:21:42:41 -0500] slapd_ldap_sasl_interactive_bind -

Re: [Freeipa-users] SASL(-13) authentication failure

2015-02-06 Thread Bryan Pearson
I did a bit more digging into the issue, and realized that the ruv-id of ipa2 is different on only one of the servers of the 3. I am imaging I will need to run clean-ruv on inconsistent node. Bryan On Fri, Feb 6, 2015 at 10:11 PM, Bryan Pearson bwp.pear...@gmail.com wrote: Hello, My IPA