[Freeipa-users] Re: Exclude only one command on SUDO ?

2018-02-15 Thread Brian Candler via FreeIPA-users
On 15/02/2018 04:04, freeipa-users-requ...@lists.fedorahosted.org wrote: I wanted to ask if there is any way to exclude only one sudo commands and allow all the others. For example, I want to exclude "passwd" command but allow all the others without need to write each of the one by one. This

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Bret Wortman via FreeIPA-users
On 02/15/2018 07:09 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/15/2018 11:47 AM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 04:50 AM, Florence Blanc-Renaud wrote: On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Florence Blanc-Renaud via FreeIPA-users
On 02/15/2018 11:47 AM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 04:50 AM, Florence Blanc-Renaud wrote: On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret Wortman wrote: On 02/14/2018 10:22 AM, Florence Blanc-Renaud wrote: On

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Bret Wortman via FreeIPA-users
On 02/15/2018 04:50 AM, Florence Blanc-Renaud wrote: On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret Wortman wrote: On 02/14/2018 10:22 AM, Florence Blanc-Renaud wrote: On 02/14/2018 12:52 PM, Bret Wortman via FreeIPA-users wrote: I did

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Alexander Bokovoy via FreeIPA-users
On to, 15 helmi 2018, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret Wortman wrote: On 02/14/2018 10:22 AM, Florence Blanc-Renaud wrote: On 02/14/2018 12:52 PM, Bret Wortman via FreeIPA-users

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Florence Blanc-Renaud via FreeIPA-users
On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret Wortman wrote: On 02/14/2018 10:22 AM, Florence Blanc-Renaud wrote: On 02/14/2018 12:52 PM, Bret Wortman via FreeIPA-users wrote: I did figure out that I can use # ldapsearch -D 'directory

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Bret Wortman via FreeIPA-users
On 02/15/2018 07:09 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/15/2018 11:47 AM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 04:50 AM, Florence Blanc-Renaud wrote: On 02/15/2018 10:08 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/14/2018 05:58 PM, Bret

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Florence Blanc-Renaud via FreeIPA-users
On 02/15/2018 02:40 PM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 07:09 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/15/2018 11:47 AM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 04:50 AM, Florence Blanc-Renaud wrote: On 02/15/2018 10:08 AM, Florence

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Florence Blanc-Renaud via FreeIPA-users
On 02/15/2018 05:01 PM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 09:29 AM, Florence Blanc-Renaud wrote: On 02/15/2018 02:40 PM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 07:09 AM, Florence Blanc-Renaud via FreeIPA-users wrote: On 02/15/2018 11:47 AM, Bret Wortman via

[Freeipa-users] Re: Fixing limit on DNS searches

2018-02-15 Thread Bret Wortman via FreeIPA-users
On 02/15/2018 12:27 PM, Florence Blanc-Renaud wrote: On 02/15/2018 05:01 PM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 09:29 AM, Florence Blanc-Renaud wrote: On 02/15/2018 02:40 PM, Bret Wortman via FreeIPA-users wrote: On 02/15/2018 07:09 AM, Florence Blanc-Renaud via FreeIPA-users

[Freeipa-users] Excessive replication activity

2018-02-15 Thread Jim Richard via FreeIPA-users
Trying to understand what appears to be an excessive amount of replication activity. Running IPA 4.5 on CentOS 7.4 2 IPA hosts, multi-master about 800-1000 hosts enrolled and maybe 100 users, maybe 20 or 30 who login via ssh keys on a regular basis. I enabled: 8192 — Replication debugging

[Freeipa-users] Re: Excessive replication activity

2018-02-15 Thread Jim Richard via FreeIPA-users
looks like: KDC:Disable Last Success enabled in the webui, did the trick good info here: https://github.com/freeipa/freeipa/pull/641#issuecomment-289474747 and here: http://freeipa-devel.redhat.narkive.com/mGuWzyA9/freeipa-pr-641-opened-set-kdc-disable-last-success-by-default