Re: [Freeipa-users] Handle openssl issue

2014-04-15 Thread Nathan Broadbent
Hi Barry, FreeIPA only uses OpenSSL for some client libraries. The web server and CA components are not affected by heartbleed. Best, Nathan On Tue, Apr 15, 2014 at 7:34 PM, barry...@gmail.com wrote: Dear all: http://heartbleed.com/ openssl announced before. We use 3rd part official

Re: [Freeipa-users] freeIPA client sudo / sssd setup

2014-04-08 Thread Nathan Broadbent
I know I'm missing something simple. But I just can't get this ipa client to accept any sudo rules. I rand into the same issue. It's not documented anywhere, but you need to enable the 'sudo' service in /etc/sssd/sssd.conf You need to change: [sssd] services = nss, pam, ssh to: [sssd]

Re: [Freeipa-users] freeIPA client sudo / sssd setup

2014-04-08 Thread Nathan Broadbent
man sssd-sudo says: CONFIGURING SSSD TO FETCH SUDO RULES All configuration that is needed on SSSD side is to extend the list of services with sudo in [sssd] section of sssd.conf(5). I would say it is