Re: [Freeipa-users] 7.x replica install from 6.x master fails

2016-04-15 Thread Ott, Dennis
To: Ott, Dennis; Freeipa-users@redhat.com Subject: Re: [Freeipa-users] 7.x replica install from 6.x master fails On 04/15/2016 05:13 PM, Ott, Dennis wrote: > My master began life as OS 6.2 / IPA 2.1.3 / pki-9.0.3 and does not have a > cert database at: > > /etc/pki/pki-

Re: [Freeipa-users] 7.x replica install from 6.x master fails

2016-03-31 Thread Ott, Dennis
, March 29, 2016 6:43 AM To: Ott, Dennis; Freeipa-users@redhat.com Subject: Re: [Freeipa-users] 7.x replica install from 6.x master fails On 03/24/2016 04:29 PM, Ott, Dennis wrote: > I am trying to migrate from OS 6.x / IPA 3.0 to OS 7.x / IPA 4.x. > After working through and solving a few issu

[Freeipa-users] 7.x replica install from 6.x master fails

2016-03-24 Thread Ott, Dennis
I am trying to migrate from OS 6.x / IPA 3.0 to OS 7.x / IPA 4.x. After working through and solving a few issues, my current efforts fail when setting up the replica CA. If I set up a new, pristine master on OS 6.7, I am able to create an OS 7.x replica without any problem. However, if I try

Re: [Freeipa-users] Cert Renewal

2014-09-03 Thread Ott, Dennis
-agent-submit -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: Wednesday, September 03, 2014 3:19 PM To: Ott, Dennis; Freeipa-users@redhat.com Subject: Re: [Freeipa-users] Cert Renewal Ott, Dennis wrote: I may need a little more direction here. The output from

Re: [Freeipa-users] Cert Renewal

2014-09-02 Thread Ott, Dennis
I may need a little more direction here. The output from getcert list-cas does not contain the string 'ca_renewal'. What does this indicate? -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: Tuesday, August 26, 2014 3:53 PM To: Ott, Dennis; Freeipa-users

[Freeipa-users] Cert Renewal

2014-08-25 Thread Ott, Dennis
I have an IPA setup, one master, one replica; originally installed as v 2.x and later updated to v 3.0. For whatever reasons, the certs did not automatically renew and the services would no longer start. I updated the certs manually on the master using the procedure shown at:

[Freeipa-users] Password Expiration Grace Limit

2012-09-14 Thread Ott, Dennis
There seems to be nothing in the documentation about a user being able to initiate a password change dialogue after their password has expired, yet it seems that one is able to do just that. There is a value in the ldap store, passwordGraceLimit, which is initialized to zero. I have modified