[Freeipa-users] Re: ipa: ERROR: No valid Negotiate header in server response

2018-04-06 Thread Zarko Dudic via FreeIPA-users
Thanks for the answer, all servers have same one: gssproxy-0.4.1-13.el7.x86_64 -- Thanks, Zarko ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

[Freeipa-users] Re: read only replicants

2018-04-06 Thread Florence Blanc-Renaud via FreeIPA-users
On 04/06/2018 12:10 PM, Angus Clarke via FreeIPA-users wrote: Hi Is there way to lock down a FreeIPA replica so that it can only receive updates but not make changes to other FreeIPA systems. Some of our environments are considered less secure than others, our security team are concerned

[Freeipa-users] Re: FreeIPA v4.5.0 install lost topology suffixes

2018-04-06 Thread Ludwig Krispenz via FreeIPA-users
On 04/05/2018 11:28 PM, Gavin Williams via FreeIPA-users wrote: Petr Yeh, I was unable to see the suffixes and replication agreements via the WebUI. However searching using ldapsearch, they were still present. So I tracked the issue down to my named user account not having enough

[Freeipa-users] read only replicants

2018-04-06 Thread Angus Clarke via FreeIPA-users
Hi Is there way to lock down a FreeIPA replica so that it can only receive updates but not make changes to other FreeIPA systems. Some of our environments are considered less secure than others, our security team are concerned that a FreeIPA in a less secure environment might become compromised

[Freeipa-users] dns recursion

2018-04-06 Thread Andrew Meyer via FreeIPA-users
Another issue i'm having is that we have DNS setup with split horizon/views in R53.  We want to be able to get a copy of the internal zone from R53 from my local FIPA servers.  Is this possible?  I have zone forwards setup in FIPA so that if you are up in AWS VPC you can query R53.  However I

[Freeipa-users] sudo command group

2018-04-06 Thread Andrew Meyer via FreeIPA-users
So I'm having an issue with sudo policies where I have about ~200 commands in my sudoers, I added those commands to a group and I got an error in the WebUI: Search result has been truncated: Configured size limit exceeded Also when I run the ipa sudocmdgroup-show I don't see all the commands. 

[Freeipa-users] Re: sudo command group

2018-04-06 Thread Rob Crittenden via FreeIPA-users
Andrew Meyer via FreeIPA-users wrote: > So I'm having an issue with sudo policies where I have about ~200 > commands in my sudoers, I added those commands to a group and I got an > error in the WebUI: > > Search result has been truncated: Configured size limit exceeded > > Also when I run the