Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-03-03 Thread Steve Dainard
Sumit, Unfortunately 1.11.1 is the only version available for Ubuntu 13.10. I've also had the same problem with an updated version of Fedora 20, so I don't think its specific to this package version. *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> |

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-03-03 Thread Steve Dainard
> adm...@miovision.corp),__799000513(domain > us...@miovision.corp),__799002464(it - > adm...@miovision.corp),__799002469(kloperators@__ miovision.corp),799002468(__kladm...@miovision.corp),*__ 176820(admins),176824(__ad_admins)* > *Steve Dainard

Re: [Freeipa-users] local root can su to any IPA user

2014-02-26 Thread Steve Dainard
on on best practices here? Has there been any further discussion on the best way to approach this problem? Thanks, *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* *Blog <http://miovision.com/blog> | **LinkedIn <https://www.linke

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-02-19 Thread Steve Dainard
ber groups: ad_admins_external Member of groups: admins Member of Sudo rule: ad_admins, All Thanks, *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* *Blog <http://miovision.com/blog> | **LinkedIn <https://www.linkedin.com/compa

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-02-18 Thread Steve Dainard
!), thanks. *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* *Blog <http://miovision.com/blog> | **LinkedIn <https://www.linkedin.com/company/miovision-technologies> | Twitter <https://twitter.com/miovision> | Facebook &

Re: [Freeipa-users] Sudo denied on first attempt, allowed on second attempt

2014-02-17 Thread Steve Dainard
inard-admin# Files attached outside of list. Thanks, *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* *Blog <http://miovision.com/blog> | **LinkedIn <https://www.linkedin.com/company/miovision-technologies> | Twitter <htt

Re: [Freeipa-users] authentication against compat

2014-02-14 Thread Steve Dainard
stable as Fedora/EL - but I realize its a one-man show). All your hard work is much appreciated, and I think this is an awesome project that has long been needed. Unfortunately the only time I can dedicate is in testing as I await the RHEL 7 release. *Steve Dainard * IT Infrastructure Manager

Re: [Freeipa-users] authentication against compat

2014-02-13 Thread Steve Dainard
s netmasks: files networks: files protocols: files rpc:files services: files sss netgroup: files sss publickey: nisplus automount: files sss aliases:files nisplus Entry does not exist. *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.c

Re: [Freeipa-users] authentication against compat

2014-02-13 Thread Steve Dainard
Is this server or client side where sudo_provider=ipa is included in ver > 1.11.x? My fedora 20 client doesn't have this option listed, or is it baked in? *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* *Blog <http://m

Re: [Freeipa-users] RHEL 7 beta trust - slow domain user authentication to Linux hosts

2014-02-10 Thread Steve Dainard
, please delete the e-mail and any attachments and notify us immediately. On Mon, Feb 10, 2014 at 11:09 AM, Sumit Bose wrote: > On Mon, Feb 10, 2014 at 10:55:33AM -0500, Steve Dainard wrote: > > I've setup RHEL 7 beta IPA with a trust to an AD domain. > > > > When I use

Re: [Freeipa-users] ipa-client-install does not seem to like the ipa's ntp

2014-02-09 Thread Steve Dainard
I've noticed if ntpd is already running on the client when you run the ipa-client-install, you will get that error. I'm guessing its using ntpdate IP ADDRESS to sync time, and cannot do so when the daemon is running. *Steve * On Sat, Feb 8, 2014 at 8:34 AM, Mauricio Tavares wrote: > Even

Re: [Freeipa-users] Cross domain trust

2014-02-06 Thread Steve Dainard
On Thu, Feb 6, 2014 at 12:42 PM, Alexander Bokovoy wrote: > On Thu, 06 Feb 2014, Steve Dainard wrote: > >>In newer versions (FreeIPA 3.3+, SSSD 1.11+) this is done on IPA master >>>automatically by setting ipa_master_mode = True >>> >>>On R

Re: [Freeipa-users] Cross domain trust

2014-02-06 Thread Steve Dainard
On Thu, Feb 6, 2014 at 11:14 AM, Alexander Bokovoy wrote: > On Thu, 06 Feb 2014, Steve Dainard wrote: > >> So I've completed the setup, and can see the trust on the Windows side. >> >> I've joined a client to the IPA realm, and can login with a IPA user. When &

Re: [Freeipa-users] Cross domain trust

2014-02-06 Thread Steve Dainard
.corp Feb 06 10:13:38 ipa1.miolinux.corp krb5kdc[7687](info): TGS_REQ (4 etypes {18 17 16 23}) 10.0.6.239: ISSUE: authtime 1391699618, etypes {rep=18 tkt=18 ses=18}, host/rhel6-client.miolinux.c...@miolinux.corp for ldap/ipa1.miolinux.c...@miolinux.corp *Steve Dainard * IT Infrastructure Manager

Re: [Freeipa-users] Cross domain trust

2014-02-05 Thread Steve Dainard
I didn't have the firewall on my IPA server down while forming the trust. All seems to be working now. Thanks for your help. Steve > > > -- > / Alexander Bokovoy > ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/

Re: [Freeipa-users] ipa AD trust issue

2014-02-05 Thread Steve Dainard
https://bugzilla.redhat.com/show_bug.cgi?id=1061897 *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* 519-513-2407 ex.250 877-646-8476 (toll-free) *Blog <http://miovision.com/blog> | **LinkedIn <https://www.linkedin.com/co

[Freeipa-users] Cross domain trust

2014-02-05 Thread Steve Dainard
ion.c...@miolinux.corp Also, is it normal to not find the Linux realm listed in the domain trust list on the AD DC? *Steve Dainard * IT Infrastructure Manager Miovision <http://miovision.com/> | *Rethink Traffic* 519-513-2407 ex.250 877-646-8476 (toll-free) *Blog <http://miovision.com/blog> |

Re: [Freeipa-users] ipa-server-install fails (RHEL 6.5)

2014-02-05 Thread Steve Dainard
eb/2014:09:52:00 -0500] - slapd shutting down - closing down internal subsystems and plugins [05/Feb/2014:09:52:00 -0500] - Waiting for 4 database threads to stop [05/Feb/2014:09:52:00 -0500] - All database threads now stopped [05/Feb/2014:09:52:00 -0500] - slapd stopped. Thanks, *Steve Dainard * I

[Freeipa-users] ipa-server-install fails (RHEL 6.5)

2014-02-04 Thread Steve Dainard
4-02-04T20:45:51Z INFO The ipa-server-install command failed, exception: CalledProcessError: Command 'kadmin.local -q addprinc -randkey ldap/ipa1.miovision.linux@MIOVISION.LINUX -x ipa-setup-override-restrictions' returned non-zero exit status 1 *Steve Dainard * IT Infrastructure

Re: [Freeipa-users] ipa AD trust issue

2014-02-04 Thread Steve Dainard
> > > > has anyone worked it out. Secondly cifs-utils has dependency on samba3 > packages and ipa-ad-trust needs samba4 but samba3 and samba4 don't like > each other , so this is the story of my experience with ipa. Any > suggestions ? > > > Why do you need cifs-utils on the same server? > cifs-ut

Re: [Freeipa-users] FreeIPA password sync one direction only (Windows DC -> IPA)

2013-05-17 Thread Steve Dainard
found DB object f6d910 for database /var/lib/dirsrv/slapd-MIOVISION-LINUX/cldb/854fd282-193811e2-9177aa0d-17c9983f_508020360003.db4 [17/May/2013:13:53:48 -0400] NSMMReplicationPlugin - changelog program - _cl5GetDBFileByReplicaName: found DB object f6d910 for database /var/lib/dirsrv/slapd

[Freeipa-users] FreeIPA password sync one direction only (Windows DC -> IPA)

2013-05-17 Thread Steve Dainard
Directory supposed to be two-way? If so where can I start troubleshooting this issue? Thanks, Steve Dainard Infrastructure Manager Miovision Technologies Inc. ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listin