[Freeipa-users] nss_getpwnam: name 't...@my.dom@localdomain' does not map into domain 'nix.my.dom'

2018-03-07 Thread TomK via FreeIPA-users
Hey Guy's, Getting below message which in turn fails to list proper UID / GID on NFSv4 mounts from within an unprivileged account. All files show up with owner and group as nobody / nobody when viewed from the client. Is there a way to structure /etc/idmapd.conf to allow for proper UID / GID

[Freeipa-users] Re: nss_getpwnam: name 't...@my.dom@localdomain' does not map into domain 'nix.my.dom'

2018-03-07 Thread Rob Crittenden via FreeIPA-users
TomK via FreeIPA-users wrote: > Hey Guy's, > > Getting below message which in turn fails to list proper UID / GID on > NFSv4 mounts from within an unprivileged account. All files show up with > owner and group as nobody / nobody when viewed from the client. > > Is there a way to structure /etc/id

[Freeipa-users] client machines and server related questions

2018-03-07 Thread Andrew Meyer via FreeIPA-users
I have a few more questions regarding joining client machines to the domain. If I manually specify a FreeIPA server when joining the client to it, can I go back and add the _srv_ to the line in /etc/sssd/sssd.conf ?  Will doing that work just like if I did autodiscover? Can I specify more than 1

[Freeipa-users] ipa-kra-install error

2018-03-07 Thread Natxo Asenjo via FreeIPA-users
hi, I want to try the vault but when I tried installing it it failed. Unfortunately the error log got overwritten the next time I tried to install it, so now I am stuck. This is what I get: # ipa-kra-install Directory Manager password: Directory Manager password is invalid The ipa-kra-install

[Freeipa-users] Re: ipa-kra-install error

2018-03-07 Thread Natxo Asenjo via FreeIPA-users
hi, this is on a centos 7.4 fully patched, by the way On Wed, Mar 7, 2018 at 8:33 PM, Natxo Asenjo wrote: > hi, > > I want to try the vault but when I tried installing it it failed. > Unfortunately the error log got overwritten the next time I tried to > install it, so now I am stuck. > > > Thi

[Freeipa-users] removing a replica

2018-03-07 Thread Andrew Meyer via FreeIPA-users
I am trying to follow  HowTo/Remove replica in a managed topology - FreeIPA to remove replica servers correctly.  However when I do this I am running into an error: [andrew.meyer@infra-test-ipa ~]$ ipa topologysegment-delSuffix name: domainSegment name: freeipa01.east.gatewayblend.net-to-freeip

[Freeipa-users] Unable to retrieve ticket despite setting the adding the system on allow list

2018-03-07 Thread William Muriithi via FreeIPA-users
Hello, I am attempting to setup apache behind a load balancer and have setup the necessary host and DNS entry to represent a virtual host. I also have added the ACL to pull and also create the ticket. I am however unable to run ipa-getkeytab with the -r flag. If I remove the flag, I get the tic

[Freeipa-users] timestamp of ipa backup and test on backup restore

2018-03-07 Thread barrykfl--- via FreeIPA-users
hi : any timestamp expiry of the ipa backup copy ? My steps are: On orginal server , I backup a copy then I shut it down. Then I reinstall an new one with same host name and I can really restore from the backup. (test finish) after that I shutown the new server , and want to get back the orgin