[Freeipa-users] Re: ipa-client package - is it necessary after install?

2017-06-09 Thread Martin Babinsky via FreeIPA-users
On Fri, Jun 09, 2017 at 08:41:18AM +1000, Lachlan Musicman via FreeIPA-users wrote: >Hola, > >So in doing a system analysis, I noted that some of our hosts have >ipa-client and some don't. > >All of the hosts are using SSSD to connect to the FreeIPA server. > >Once a client system has joined the d

[Freeipa-users] FreeIPA and TACACS+

2017-06-09 Thread Andrew Meyer via FreeIPA-users
Has anyone gotten FreeIPA and TACACS+ from shrubbery.net working?___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Re: very slow remove users process

2017-06-09 Thread thierry bordaz via FreeIPA-users
Hi, Just for recording, this issue of slow user-del will be track with https://pagure.io/389-ds-base/issue/49286 regards thierry On 05/31/2017 03:45 PM, thierry bordaz via FreeIPA-users wrote: On 05/31/2017 03:30 PM, Rob Crittenden wrote: thierry bordaz via FreeIPA-users wrote: Hi Adrian,

[Freeipa-users] Re: Enroll CentOS 5 on FreeIPA 4.3

2017-06-09 Thread Rob Crittenden via FreeIPA-users
Jose and I exchanged some files privately and I think I've narrowed down the enrollment problem to failing to get a keytab due to the error: Failed to retrieve encryption type DES cbc mode with CRC-32 (#1) This is because newer IPA servers don't support DES. I don't recall the workaround for thi

[Freeipa-users] Re: Enroll CentOS 5 on FreeIPA 4.3

2017-06-09 Thread Alexander Bokovoy via FreeIPA-users
On pe, 09 kesä 2017, Rob Crittenden via FreeIPA-users wrote: Jose and I exchanged some files privately and I think I've narrowed down the enrollment problem to failing to get a keytab due to the error: Failed to retrieve encryption type DES cbc mode with CRC-32 (#1) This is because newer IPA se

[Freeipa-users] AD - IPA Trust Issues

2017-06-09 Thread Matt Wells via FreeIPA-users
Hello everyone. I hoped I could ask for a little assistance on an AD / IPA Trust. I've for a Windows 2008R2 domain. Response Type: LOGON_SAM_LOGON_RESPONSE_EX GUID: e**6497 Flags: Is a PDC: no Is a GC of the forest: yes Is

[Freeipa-users] Re: [Freeipa-users]FreeIPA and TACACS+

2017-06-09 Thread Jake via FreeIPA-users
it's a pam module and works the same as others, if you are using hbac you'll need to create a service for the module https://serverfault.com/questions/425020/authenticate-linux-sshd-with-tacacs-cisco-acs Anything specific you're having issues with? -Jake From: "freeipa-users" To: "free

[Freeipa-users] String index out of range: -36

2017-06-09 Thread jochem--- via FreeIPA-users
Hello all, This i my first post here, so be gentle. I'm running FreeIPA 4.4.0-14 (ipa-server-4.4.0-14.el7.centos.7.x86_64) on CentOS 7.3.1611 and since a while i can't get any certificates to my hosts. The client has installed: ipa-client-4.4.0-14.el7.centos.7.x86_64 ans is also running CentOS

[Freeipa-users] Re: [Freeipa-users]FreeIPA and TACACS+

2017-06-09 Thread Andrew Meyer via FreeIPA-users
Trying to set it up.. Going to try this weekend if I have time otherwise next week. Sent from Yahoo Mail on Android On Fri, Jun 9, 2017 at 15:51, Jake wrote: it's a pam module and works the same as others, if you are using hbac you'll need to create a service for the module https://server

[Freeipa-users] Re: String index out of range: -36

2017-06-09 Thread Rob Crittenden via FreeIPA-users
jochem--- via FreeIPA-users wrote: > Hello all, > > This i my first post here, so be gentle. > > I'm running FreeIPA 4.4.0-14 (ipa-server-4.4.0-14.el7.centos.7.x86_64) on > CentOS 7.3.1611 and since a while i can't get any certificates to my hosts. > > The client has installed: ipa-client-4.4.0

[Freeipa-users] Re: String index out of range: -36

2017-06-09 Thread jochem--- via FreeIPA-users
Rob, Thank you for replying. I've enable debug and i think this is the relevant portion of the log. [Sat Jun 10 04:18:58.109402 2017] [:error] [pid 11081] ipa: DEBUG: NSSConnection init freeipa.fakedomain.local [Sat Jun 10 04:18:58.271640 2017] [:error] [pid 11081] ipa: DEBUG: Connecting: 192.