Re: [Freeipa-users] A public interface (aka My account management)

2013-04-24 Thread Chris Evich
. It also offers a HUGE benefit to greatly extend self-service to the n-th degree, when it's multi-level rights-management features are used. -- Chris Evich, RHCA, RHCE, RHCDS, RHCSS Quality Assurance Engineer ___ Freeipa-users mailing list Freeipa

Re: [Freeipa-users] KISS: DHCP from IPA

2012-08-30 Thread Chris Evich
On 08/29/2012 03:52 PM, Rob Crittenden wrote: Chris Evich wrote: On 08/29/2012 11:57 AM, John Dennis wrote: Thanks for the contribution Chris! Just as an aside if you know Python you can call the IPA commands directly and use Python to extract and reformat the data, it might be a lot simpler

[Freeipa-users] KISS: DHCP from IPA

2012-08-29 Thread Chris Evich
Kool Idm Simple Script :D In case it's helpful to anyone else, I've been using a simple script to keep my dhcp server's static entries in-sync with ipa host info. Since I'm using IPA 2.1 on Fedora 16, I had to hijack the 'location' host info. key to store the MAC address for each host.

Re: [Freeipa-users] KISS: DHCP from IPA

2012-08-29 Thread Chris Evich
is a bit clunky. I actually did stumble on the python stuff by accident, but wasn't able to find much reference / examples for how to use it. At the time I just needed something quick to toss-together. Maybe the python docs/examples are different today, any links handy? -- Chris Evich, RHCA

Re: [Freeipa-users] IPA over the Internet - Security Implications

2012-08-17 Thread Chris Evich
certainly tighter than the average app., I'd pay particular attention to keeping them updated, 0-day if possible. This again can impact availability, for example in the case of unknown and unrelated regressions in the updates themselves. -- Chris Evich, RHCA, RHCE, RHCDS, RHCSS Quality Assurance

[Freeipa-users] Doc. mixup

2012-05-21 Thread Chris Evich
Hi, Not sure if this is the right place or not, but I noticed that the freeipa.org documentation link for 2.0 goes to https://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/index.html which is for version 2.1.3. Freeipa 2.1.x is also what you get with Fedora 16, however the

[Freeipa-users] Doc. mixup

2012-05-21 Thread Chris Evich
Hi, Not sure if this is the right place or not, but I noticed that the freeipa.org documentation link for 2.0 goes to https://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/index.html which is for version 2.1.3. Freeipa 2.1.x is also what you get with Fedora 16, however the

Re: [Freeipa-users] Doc. mixup

2012-05-21 Thread Chris Evich
On 05/21/2012 10:12 AM, Rob Crittenden wrote: Chris Evich wrote: Are there plans to rebase FreeIPA to 2.2 in Fedora 16? No. It can be possible to run a 2.2 server on F-16 but there are some things missing. If not, then should I open a bug to fix up the Fedora 16 FreeIPA docs to point

Re: [Freeipa-users] insecure IPA'd NFS

2012-05-10 Thread Chris Evich
On 05/09/2012 06:18 PM, Steven Jones wrote: Hi, Thanks so I will remove the sec=sys bit and re-test..and then I assume it will be kerberos only. This is not true, it's documented in the exports man page how you can assign different permissions depending on the security type. For

Re: [Freeipa-users] insecure IPA'd NFS

2012-05-10 Thread Chris Evich
On 05/09/2012 08:47 PM, Steven Jones wrote: Removed the sys: and now no IPA'd client can mount.oh joy Hehe, this is typical (and frustrating) for fresh NFS+Kerberos setups. it's very easy to miss a little detail and not get much back as to why it's not working. I'd suggest going

Re: [Freeipa-users] *SOLVED* Re: ipa-replica-prepare Certificate issuance failed

2012-05-08 Thread Chris Evich
On 05/08/2012 09:10 AM, Simo Sorce wrote: On Sat, 2012-05-05 at 21:47 -0400, Chris Evich wrote: On 05/05/2012 09:08 PM, Chris Evich wrote: On 05/05/2012 08:01 PM, Chris Evich wrote: On 05/04/2012 04:17 PM, Chris Evich wrote: That makes me think maybe there's just a missing service principal

Re: [Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-05 Thread Chris Evich
On 05/05/2012 08:01 PM, Chris Evich wrote: On 05/04/2012 04:17 PM, Chris Evich wrote: That makes me think maybe there's just a missing service principal or something I can add? I'll see if I can remove that request and try running ipa-replica-prepare again to see if it still gives that error

[Freeipa-users] *SOLVED* Re: ipa-replica-prepare Certificate issuance failed

2012-05-05 Thread Chris Evich
On 05/05/2012 09:08 PM, Chris Evich wrote: On 05/05/2012 08:01 PM, Chris Evich wrote: On 05/04/2012 04:17 PM, Chris Evich wrote: That makes me think maybe there's just a missing service principal or something I can add? I'll see if I can remove that request and try running ipa-replica-prepare

[Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-04 Thread Chris Evich
Hi, I've got a FreeIPA setup at home I just built the other week on Fedora 16. It's a very small/basic setup I'm mainly using for secure NFS+Kerberos and automount. Today, I updated everything and rebooted, and all seemed to be working okay (even /var/log/ipaupgrade.log). I'm now running:

Re: [Freeipa-users] ipa-replica-prepare Certificate issuance failed

2012-05-04 Thread Chris Evich
On 05/04/2012 03:18 PM, Rob Crittenden wrote: Chris Evich wrote: Hi, I've got a FreeIPA setup at home I just built the other week on Fedora 16. It's a very small/basic setup I'm mainly using for secure NFS+Kerberos and automount. Today, I updated everything and rebooted, ...cut... [04/May