Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-08-03 Thread Jakub Hrozek
On Fri, Jul 31, 2015 at 09:19:30AM +0700, Dewangga Bachrul Alam wrote: Hello! Sorry for making you confused. The main problem is the cache on ipa server/client. How long the cache remain active and refresh with correct policy/rules. See man sssd-sudo for explanation of the sudo lookups.

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Jakub Hrozek
On Thu, Jul 30, 2015 at 07:09:47PM +0700, Dewangga Bachrul Alam wrote: Hello Jakub! Sorry for delayed email, My bad, I disabled cache_credentials, not sssd_cache. Then I think it's completely unrelated to the sudo rules problem. I tried modified my user `dewangga` to remove sudo rules,

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Dewangga Bachrul Alam
Hello Jakub! Sorry for delayed email, My bad, I disabled cache_credentials, not sssd_cache. I tried modified my user `dewangga` to remove sudo rules, the cache still active even I restart the sssd service and delete all ccache* files. There's no information on sssd log folder. -rw---. 1

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Dewangga Bachrul Alam
Hello! I don't know start from where to tracking down this issue. I found another something interesting. 1. Set `global_policy` password expired (both min and max) to 0 (zero) 2. Add user called `dummy` 3. Set global_policy password expired min (1) and max (90). 4. Add user called `dummy2` Both

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Jakub Hrozek
On Thu, Jul 30, 2015 at 09:50:23PM +0700, Dewangga Bachrul Alam wrote: Hello! I don't know start from where to tracking down this issue. I found another something interesting. 1. Set `global_policy` password expired (both min and max) to 0 (zero) 2. Add user called `dummy` 3. Set

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread NitrouZ
Thanks Martin, Yes, it is for testing only, when the ipa server ready for production, I will enable the cache. Once again, thank you. On Thursday, July 30, 2015, Martin Kosek mko...@redhat.com wrote: On 07/29/2015 05:03 PM, Dewangga wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Martin Kosek
On 07/29/2015 05:03 PM, Dewangga wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello! Thanks for the hints both of you, yes the sssd_cache is in play. Good! I've set the cache to false, is it have any impact to ipa server/client (performance, security or another issue)? Disabling

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Jakub Hrozek
On Wed, Jul 29, 2015 at 10:03:14PM +0700, Dewangga wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello! Thanks for the hints both of you, yes the sssd_cache is in play. I've set the cache to false, is it have any impact to ipa server/client (performance, security or another

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread NitrouZ
Hello! I set the cache value to False on sssd.conf. (On IPA server and client). On Thursday, July 30, 2015, Jakub Hrozek jhro...@redhat.com wrote: On Wed, Jul 29, 2015 at 10:03:14PM +0700, Dewangga wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello! Thanks for the hints

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-30 Thread Dewangga Bachrul Alam
Hello! Sorry for making you confused. The main problem is the cache on ipa server/client. How long the cache remain active and refresh with correct policy/rules. Whenever I set the sudo rules, modify another configuration (policy, etc), it's always have delay. And until now, the global_policy

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-29 Thread Dewangga
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello! Thanks for the hints both of you, yes the sssd_cache is in play. I've set the cache to false, is it have any impact to ipa server/client (performance, security or another issue)? On 7/29/2015 21:39, Jakub Hrozek wrote: On Wed, Jul 29, 2015

[Freeipa-users] Is there any delay after applied rules to user?

2015-07-29 Thread Dewangga Bachrul Alam
Hello! I'm using FreeIPA 4.1.x on CentOS 7, Is there any delay after applied some rules to specified user? [root@ipa ~]# ipa sudorule-show Rule name: wheel Rule name: Wheel Enabled: TRUE Host category: all Command category: all RunAs User category: all RunAs Group category: all

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-29 Thread Martin Kosek
On 07/29/2015 03:22 PM, Dewangga Bachrul Alam wrote: Hello! I'm using FreeIPA 4.1.x on CentOS 7, Is there any delay after applied some rules to specified user? [root@ipa ~]# ipa sudorule-show Rule name: wheel Rule name: Wheel Enabled: TRUE Host category: all Command category:

Re: [Freeipa-users] Is there any delay after applied rules to user?

2015-07-29 Thread Jakub Hrozek
On Wed, Jul 29, 2015 at 04:32:42PM +0200, Martin Kosek wrote: On 07/29/2015 03:22 PM, Dewangga Bachrul Alam wrote: Hello! I'm using FreeIPA 4.1.x on CentOS 7, Is there any delay after applied some rules to specified user? [root@ipa ~]# ipa sudorule-show Rule name: wheel Rule