Re: [Freeipa-users] IPA AD Sync error

2010-09-21 Thread Shan Kumaraswamy
Hi Rich, While executing your command (ldapserch), I am getting the following output: ** *Command:* /usr/lib64/mozldap/ldapsearch -h fqdn.of.ad.hostname -Z -P /etc/dirsrv/slapd-YOURINSTANCE/cert8.db -s base -b objectclass=* ** *Output:* ldap_search: Can't contact LDAP server SSL error

Re: [Freeipa-users] IPA AD Sync error

2010-09-21 Thread Rich Megginson
Shan Kumaraswamy wrote: Hi Rich, While executing your command (ldapserch), I am getting the following output: _Command:_ /usr/lib64/mozldap/ldapsearch -h fqdn.of.ad.hostname -Z -P /etc/dirsrv/slapd-YOURINSTANCE/cert8.db -s base -b objectclass=* _Output:_ ldap_search: Can't contact LDAP

Re: [Freeipa-users] IPA+AD sync error

2010-08-18 Thread Rich Megginson
Shan Kumaraswamy wrote: Ok sure, I will do the test and can please let me know command to import AD CA in to dirsrv cert db? It is already in there? This is the certificate called Imported CA with Subject: CN=test-WINDOWS-CA,DC=test,DC=ad and Issuer: CN=test-WINDOWS-CA,DC=test,DC=ad Or are

Re: [Freeipa-users] IPA+AD sync error

2010-08-17 Thread Shan Kumaraswamy
Hi Rich, After I did all the steps, I am getting this error: INFO:root:Added CA certificate /etc/dirsrv/slapd--COM/adcert.cer to certificate database for tesipa001.test.com INFO:root:Restarted directory server tesipa001.test.com INFO:root:Could not validate connection to remote server

Re: [Freeipa-users] IPA+AD sync error

2010-08-17 Thread Rich Megginson
Shan Kumaraswamy wrote: After this error, I have triyed your the following steps: /usr/lib64/mozldap/ldapsearch -h windows.test.ad http://windows.test.ad -D CN=administrator,CN=users,DC=test,DC=ad -w -s base -b objectclass=* Then I got output like this: version: 1 dn:

Re: [Freeipa-users] IPA+AD sync error

2010-08-17 Thread Rich Megginson
Shan Kumaraswamy wrote: Rich, Please find the below out put of the command: [r...@saprhds001 ~]# certutil -d /etc/dirsrv/slapd--COM -L Certificate Nickname Trust Attributes

Re: [Freeipa-users] IPA+AD sync error

2010-08-17 Thread Rich Megginson
Shan Kumaraswamy wrote: Certificate: Data: Version: 3 (0x2) Serial Number: 46:90:cd:94:c6:53:d4:ae:44:a6:df:e2:6b:24:15:56 Signature Algorithm: PKCS #1 SHA-1 With RSA Encryption Issuer: CN=test-WINDOWS-CA,DC=test,DC=ad Validity:

Re: [Freeipa-users] IPA+AD sync error

2010-08-16 Thread Rich Megginson
Shan Kumaraswamy wrote: Hi, I have deployed FreeIPA 1.2.1 in RHEL 5.5 and I want to sync with Active Directory (windows 2008 R2). Can please anyone have step-by-step configuration doc and share to me? Previously I have done the same exercise, but now that is not working for me and I am

Re: [Freeipa-users] IPA+AD sync error

2010-08-16 Thread Shan Kumaraswamy
Rich, While installing IPA its creates its won CA cert right? (cacert.p12), and also I done the setep of export this CA file as dsca.crt. Please let me know steps to generate the IPA CA and server cert? On Mon, Aug 16, 2010 at 5:41 PM, Rich Megginson rmegg...@redhat.com wrote: Shan