[Freeipa-users] Re: FreeIPA failover not working

2017-08-31 Thread Michael Gusek via FreeIPA-users
Hi, just for info. We restart our setup on an other stage in our dc with same result, we run in timeouts if first installed ipa server not available. So we give it a try in a complete different environment, with successfully failover. It seem's we have a problem in our dc and we will have a deepe

[Freeipa-users] Re: sudo policy doesn't work since host is installed with CNAME

2017-08-31 Thread Pavel Březina via FreeIPA-users
On 08/31/2017 08:35 AM, Jakub Hrozek wrote: On Wed, Aug 30, 2017 at 08:51:24PM +, Z D wrote: Does ipa_hostname in sssd.conf point to cname (or, the hostname registered with IPA) ? It points to the DNS A record, the one that is registered with IPA. Pavel, is a setup with a machne where

[Freeipa-users] Unable to create an Active Directory Trust

2017-08-31 Thread PAESSENS Daniel (BCS/PSD) via FreeIPA-users
Hello, When performing a trust between IPA & AD I get the following error: CIFS server communication error: code "-1073741771", message "The object name already exists." (both may be "None") For testing purpose did I remove the trust and want to re-add him like before. Regards, Daniel __

[Freeipa-users] Re: Unable to create an Active Directory Trust

2017-08-31 Thread Alexander Bokovoy via FreeIPA-users
On to, 31 elo 2017, PAESSENS Daniel (BCS/PSD) via FreeIPA-users wrote: Hello, When performing a trust between IPA & AD I get the following error: CIFS server communication error: code "-1073741771", message "The object name already exists." (both may be "None") For testing purpose did I remove

[Freeipa-users] Re: sudo policy doesn't work since host is installed with CNAME

2017-08-31 Thread Z D via FreeIPA-users
This is resolved by updating sudo package. ---> Package sudo.x86_64 0:1.8.6p7-11.el7 will be updated ---> Package sudo.x86_64 0:1.8.19p2-10.el7 will be an update From: Pavel Březina Sent: Thursday, August 31, 2017 1:48:33 AM To: Jakub Hrozek; Z D Cc: FreeIPA us

[Freeipa-users] Re: Freeipa Certficates issues

2017-08-31 Thread Julien Honore via FreeIPA-users
Hi, Do you think if i upgrade the version of my ipa server, it will be better ? I am at the version 3.0. Thank you for your time. Julien Honore - Original Message - From: "Julien Honore" To: "freeipa-users" Cc: "Florence Blanc-Renaud" Sent: Wednesday, 30 August, 2017 10:44:38 Su

[Freeipa-users] using external passwords

2017-08-31 Thread Charles Hedrick via FreeIPA-users
We have a department that would like to use IPA, but would like users to use their University passwords. I conjecture that we can do that by generating users with random passwords, but setting the default authentication as RADIUS, and using a RADIUS server that authenticates with the University

[Freeipa-users] Re: using external passwords

2017-08-31 Thread Alexander Bokovoy via FreeIPA-users
On to, 31 elo 2017, Charles Hedrick via FreeIPA-users wrote: We have a department that would like to use IPA, but would like users to use their University passwords. I conjecture that we can do that by generating users with random passwords, but setting the default authentication as RADIUS, and