Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-28 Thread Rodney L. Mercer
What is the preferred IPA platform for performing this endeavor? Would it be best to create an environment, virtual or physical, that has RHEL6 update 4 fully patched and IdM installed? or would Fedora 18 with the http://jdennis.fedorapeople.org/ipa-devel/fedora/18/x86_64/os/ yum repository

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-28 Thread Rob Crittenden
Rodney L. Mercer wrote: What is the preferred IPA platform for performing this endeavor? Would it be best to create an environment, virtual or physical, that has RHEL6 update 4 fully patched and IdM installed? or would Fedora 18 with the

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-26 Thread Dmitri Pal
On 02/25/2013 02:29 PM, Mercer, Rodney wrote: I think that this is a good explanation or the solaris rbac model. http://www.softpanorama.org/Solaris/Security/solaris_rbac.shtml Regards, Rodney. I will definitely read it. But assume I did. What are the next steps? The schema is the right one

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-25 Thread Mercer, Rodney
AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC On 02/15/2013 10:31 PM, Dmitri Pal wrote: On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-21 Thread Dmitri Pal
: From: freeipa-users-boun...@redhat.com [freeipa-users-boun...@redhat.com] on behalf of Sigbjorn Lie [sigbj...@nixtra.com] Sent: Saturday, February 16, 2013 6:29 AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC On 02

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-19 Thread Dmitri Pal
[sigbj...@nixtra.com] Sent: Saturday, February 16, 2013 6:29 AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC On 02/15/2013 10:31 PM, Dmitri Pal wrote: On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-17 Thread Dmitri Pal
: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC On 02/15/2013 10:31 PM, Dmitri Pal wrote: On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Sigbjorn Lie
On 02/15/2013 03:17 PM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great, but I already have other data in the ipa

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Sigbjorn Lie
On 02/15/2013 10:31 PM, Dmitri Pal wrote: On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great,

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Mercer, Rodney
From: freeipa-users-boun...@redhat.com [freeipa-users-boun...@redhat.com] on behalf of Sigbjorn Lie [sigbj...@nixtra.com] Sent: Saturday, February 16, 2013 6:29 AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] RHEL6 IPA and Active Directory

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-15 Thread Rodney L. Mercer
On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great, but I already have other data in the ipa ldap that I have to manage manually anyway.

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-15 Thread Dmitri Pal
On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great, but I already have other data in the ipa

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-14 Thread Sigbjorn Lie
On 02/13/2013 04:10 PM, Rob Crittenden wrote: Also since we also require compatibility with Solaris, and roles (RBAC) is currently used on Solaris, does IPA support RBAC on Solaris ? (We noticed that RBAC mentioned in the IPA web interface only relates to IPA management). No, IPA doesn't

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-14 Thread Rob Crittenden
Sigbjorn Lie wrote: On 02/13/2013 04:10 PM, Rob Crittenden wrote: Also since we also require compatibility with Solaris, and roles (RBAC) is currently used on Solaris, does IPA support RBAC on Solaris ? (We noticed that RBAC mentioned in the IPA web interface only relates to IPA management).

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-14 Thread Rodney L. Mercer
On Thu, 2013-02-14 at 18:56 +0100, Sigbjorn Lie wrote: On 02/13/2013 04:10 PM, Rob Crittenden wrote: Also since we also require compatibility with Solaris, and roles (RBAC) is currently used on Solaris, does IPA support RBAC on Solaris ? (We noticed that RBAC mentioned in the IPA web

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-14 Thread Dag Wieers
On Thu, 14 Feb 2013, Rob Crittenden wrote: Sigbjorn Lie wrote: On 02/13/2013 04:10 PM, Rob Crittenden wrote: Also since we also require compatibility with Solaris, and roles (RBAC) is currently used on Solaris, does IPA support RBAC on Solaris ? (We noticed that RBAC mentioned

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-14 Thread Rob Crittenden
Dag Wieers wrote: On Thu, 14 Feb 2013, Rob Crittenden wrote: Sigbjorn Lie wrote: On 02/13/2013 04:10 PM, Rob Crittenden wrote: Also since we also require compatibility with Solaris, and roles (RBAC) is currently used on Solaris, does IPA support RBAC on Solaris ? (We noticed

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Rob Crittenden
Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be limited to a subset. Since we would like to only

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Rich Megginson
On 02/13/2013 08:10 AM, Rob Crittenden wrote: Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Steven Jones
Hi, You can specify a --winsubtree, provided all the users you want are in that, I think that will work. For filters, Ive suggested that, we have so much garbage in our AD that its cluttering IPA badly. eg we have hundred templates, so I'd like to block those from being transferred. regards

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Dmitri Pal
On 02/13/2013 09:58 AM, Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD) is whether the synchronization with AD can be limited to a subset.

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-13 Thread Steven Jones
: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC On 02/13/2013 09:58 AM, Dag Wieers wrote: Hi, We are investigating whether IPA is an acceptable solution for our environment. One of the aspects that is not clear (from reading the documentation and testing it without AD