[Freeipa-users] Unexpected ipa usa behaviour

2017-11-21 Thread Ronald Wimmer via FreeIPA-users
Hi, in IPA I defined a user called isomeuser. This username does definitely not exist on the AD side. When I log in as root to an IPA client and issue the su command, I am isomeuser@ad.domain. If I do "su isomeuser@ipa.domain" I am isomeuser@ad.domain. The uid and gid are exactly the same.

[Freeipa-users] Re: Invalid ticket for NFS4 mount

2017-11-21 Thread Jakub Hrozek via FreeIPA-users
On Tue, Nov 21, 2017 at 08:36:16AM +0100, Ray via FreeIPA-users wrote: > Hi, > > yesterday I noticed a strange issue on a Centos 7 client running > ipa-client-4.5.0-21.el7.centos.2.2.x86_64: > > My daughter tried to log in to the machine and was kicked out again after > GNOME failed to load (/hom

[Freeipa-users] Re: Unexpected ipa usa behaviour

2017-11-21 Thread Jakub Hrozek via FreeIPA-users
On Tue, Nov 21, 2017 at 09:05:29AM +0100, Ronald Wimmer via FreeIPA-users wrote: > Hi, > > in IPA I defined a user called isomeuser. This username does definitely not > exist on the AD side. > > When I log in as root to an IPA client and issue the su command, I am > isomeuser@ad.domain. If I do "

[Freeipa-users] Re: Invalid ticket for NFS4 mount

2017-11-21 Thread Ray via FreeIPA-users
Am 2017-11-21 11:26, schrieb Jakub Hrozek via FreeIPA-users: On Tue, Nov 21, 2017 at 08:36:16AM +0100, Ray via FreeIPA-users wrote: Hi, yesterday I noticed a strange issue on a Centos 7 client running ipa-client-4.5.0-21.el7.centos.2.2.x86_64: My daughter tried to log in to the machine and w

[Freeipa-users] Re: Invalid ticket for NFS4 mount

2017-11-21 Thread Jakub Hrozek via FreeIPA-users
On Tue, Nov 21, 2017 at 11:45:36AM +0100, Ray via FreeIPA-users wrote: > > > Am 2017-11-21 11:26, schrieb Jakub Hrozek via FreeIPA-users: > > On Tue, Nov 21, 2017 at 08:36:16AM +0100, Ray via FreeIPA-users wrote: > > > Hi, > > > > > > yesterday I noticed a strange issue on a Centos 7 client runn

[Freeipa-users] Re: Enabling two-factor by host

2017-11-21 Thread Sumit Bose via FreeIPA-users
On Tue, Nov 21, 2017 at 01:47:04PM +1300, Aaron Hicks via FreeIPA-users wrote: > I found it, it was in /etc/ssh/sshd_config > > This requires in the sshd config: > > ChallengeResponseAuthentication yes > AuthenticationMethods keyboard-interactive > > We now can enable 2FA on a per-host basis. g

[Freeipa-users] Re: upgrade to ubuntu 17.10 fails

2017-11-21 Thread David Harvey via FreeIPA-users
Hoi, Anyone out there with experience of whether or not adding a replica of more recent version (4.4.4 and 389 dir 1.3.7.5-1 up from 4.4.3 with 389 dir 1.3.5.15-2) would impact the existing servers in terms of schema or similar? I'm still trying to find a safe way to upgrade safely without going

[Freeipa-users] Re: Invalid ticket for NFS4 mount

2017-11-21 Thread Ray via FreeIPA-users
Am 2017-11-21 11:51, schrieb Jakub Hrozek via FreeIPA-users: On Tue, Nov 21, 2017 at 11:45:36AM +0100, Ray via FreeIPA-users wrote: Am 2017-11-21 11:26, schrieb Jakub Hrozek via FreeIPA-users: > On Tue, Nov 21, 2017 at 08:36:16AM +0100, Ray via FreeIPA-users wrote: > > Hi, > > > > yesterday

[Freeipa-users] Invalid ticket for NFS4 mount

2017-11-21 Thread Raimund Eimann via FreeIPA-users
Hi, yesterday I noticed a strange issue on a Centos 7 client running ipa-client-4.5.0-21.el7.centos.2.2.x86_64: My daughter tried to log in to the machine and was kicked out again after GNOME failed to load (/home on kerberized NFS4). Closer inspection showed that she had no permission to ac

[Freeipa-users] Unable to use externa groups or users, truster domain object not found

2017-11-21 Thread Henrik Stigendal via FreeIPA-users
Hello everyone, I’m new to this and are trying to setup a working trust against an AD forrest, I seem to have a working trust but when I try to reference external groups (or users) I get: # ipa group-add-member ad_users_external --external "AD2\Domain Users" [member user]: [member group]: Gro

[Freeipa-users] Re: upgrade to ubuntu 17.10 fails

2017-11-21 Thread Rob Crittenden via FreeIPA-users
David Harvey wrote: > Hoi, > > Anyone out there with experience of whether or not adding a replica of > more recent version (4.4.4 and 389 dir 1.3.7.5-1 up from 4.4.3 with 389 > dir 1.3.5.15-2) would impact the existing servers in terms of schema or > similar? > I'm still trying to find a safe wa

[Freeipa-users] Re: Autentification in application with freeipa

2017-11-21 Thread Rob Crittenden via FreeIPA-users
Николай Савельев via FreeIPA-users wrote: > Hi. > I asked about Owncloud, Zimbra, etc autentification in freeipa with AD trust. > I was offered to use SAML. > But I dont undestand SAML. It very dificult for me. > I only want use LDAP for autentification as in this artikle > https://www.freeipa.org

[Freeipa-users] Re: Autentification in application with freeipa

2017-11-21 Thread Sumit Bose via FreeIPA-users
On Tue, Nov 21, 2017 at 08:14:49AM -0500, Rob Crittenden via FreeIPA-users wrote: > Николай Савельев via FreeIPA-users wrote: > > Hi. > > I asked about Owncloud, Zimbra, etc autentification in freeipa with AD > > trust. > > I was offered to use SAML. > > But I dont undestand SAML. It very dificul

[Freeipa-users] Re: Invalid ticket for NFS4 mount

2017-11-21 Thread Jakub Hrozek via FreeIPA-users
On Tue, Nov 21, 2017 at 12:39:00PM +0100, Ray via FreeIPA-users wrote: > > > Am 2017-11-21 11:51, schrieb Jakub Hrozek via FreeIPA-users: > > On Tue, Nov 21, 2017 at 11:45:36AM +0100, Ray via FreeIPA-users wrote: > > > > > > > > > Am 2017-11-21 11:26, schrieb Jakub Hrozek via FreeIPA-users: > >

[Freeipa-users] DNS fails to reply the ipa zone records

2017-11-21 Thread Raul Dias via FreeIPA-users
Bind seems to work fine. When queried about a record it logs the answer fine (even for external domains). However it fails to answer any ipa local zone request. e.g. resolve it own host query: -- 8< -- 21-Nov-2017 13:52:06.419 client: debug 3: cl

[Freeipa-users] Re: adding puppet to FreeIPA

2017-11-21 Thread Rob Crittenden via FreeIPA-users
Andrew Meyer via FreeIPA-users wrote: > Ok now I am trying to add puppet to my FreeIPA environment. Following > the instructions > from: https://www.freeipa.org/page/Howto/Using_FreeIPA_CA_for_Puppet Sadly most instructions don't include the versions(s) they were intended for but Fedora 19 had IP

[Freeipa-users] Re: adding puppet to FreeIPA

2017-11-21 Thread Andrew Meyer via FreeIPA-users
Excellent, Thank you for the help. On Tuesday, November 21, 2017 3:01 PM, Rob Crittenden via FreeIPA-users wrote: Andrew Meyer via FreeIPA-users wrote: > Ok now I am trying to add puppet to my FreeIPA environment.  Following > the instructions > from: https://www.freeipa.org/page/Howto/

[Freeipa-users] Re: Expired passwords and generating an OTP token

2017-11-21 Thread Aaron Hicks via FreeIPA-users
Hello the List, This turned out to be a workflow issue, we still have a problem but this first use case works. In the case of a user with an invalid password (none or expired) with no OTP token they can reset their password and ask IPA to create an OTP token for them. 1. Helpdesk a

[Freeipa-users] Re: Expired passwords and generating an OTP token

2017-11-21 Thread Aaron Hicks via FreeIPA-users
Hi the list. .I'd consider createing a permission with permission-add, but there is no token object type. [hicksaw@hpch2fa02 ~]$ ipa permission-add mangage-otptoken --right=all --bindtype=permission --type=token ipa: ERROR: invalid 'type': "token" is not an object type Even though ipat

[Freeipa-users] Re: Expired passwords and generating an OTP token

2017-11-21 Thread Sumit Bose via FreeIPA-users
On Wed, Nov 22, 2017 at 05:16:05PM +1300, Aaron Hicks via FreeIPA-users wrote: > Hello the List, > > > > This turned out to be a workflow issue, we still have a problem but this > first use case works. > > > > In the case of a user with an invalid password (none or expired) with no OTP > to

[Freeipa-users] Re: FreeIPA-users Digest, Vol 7, Issue 22

2017-11-21 Thread Николай Савельев via FreeIPA-users
> > I think the better reference in the documentation is > https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/windows_integration_guide/trust-legacy > > If there is a trust to an AD forest and 'ipa-adtrust-install > --enable-compat' was called. there will be a special sub