[Freeipa-users] Re: ipa commands run from cron with keytab sometimes failing

2018-06-14 Thread Robbie Harwood via FreeIPA-users
Roderick Johnstone via FreeIPA-users writes: > [Wed Jun 13 21:30:04.437056 2018] [:error] [pid 29635] ipa: INFO: 401 > Unauthorized: Insufficient access: SASL(-1): generic failure: GSSAPI > Error: The referenced context has expired (Success) This depends slightly on what SASL was trying to do

[Freeipa-users] Re: Two way trust setup issue

2018-06-14 Thread Merritt, Todd R - (tmerritt) via FreeIPA-users
On 6/1/18, 12:20 PM, "Merritt, Todd R - (tmerritt) via FreeIPA-users" wrote: On 5/31/18, 11:32 AM, "Alexander Bokovoy" wrote: On to, 31 touko 2018, Merritt, Todd R - (tmerritt) wrote: > > >On 5/30/18, 10:59 PM, "Alexander Bokovoy" wrote:

[Freeipa-users] FreeIPA API dynamic inventory script for Ansible, Ansible AWX, and Ansible Tower

2018-06-14 Thread Aaron Hicks via FreeIPA-users
Hello the list, I thought I'd share this with you, it's a dynamic inventory script that uses the FreeIPA API to populate the Ansible inventory. I'm using it in AWX, but I expect it'll work with Ansible and RedHat Ansible Tower

[Freeipa-users] Tomcat/CA fails to start after upgrade

2018-06-14 Thread Thomas Letherby via FreeIPA-users
Hello all, I'm running FreeIPA on two CentOS 7 servers, one, the master is on a physical server, the other (a replica with CA, DNS etc) is running on an Ovirt cluster. I patched the boxes and upgraded IPA on the two servers a few days ago, and the master ran through the upgrade without any

[Freeipa-users] Replica can ipa-find but can't id

2018-06-14 Thread Lachlan Musicman via FreeIPA-users
CentOS 7.5 ipa --version VERSION: 4.5.4, API_VERSION: 2.228 When on my replica, and I use ipa idoverrideuser-find 'Default Trust View' I get the expected results: -- 1 User ID override matched -- Anchor to override:

[Freeipa-users] Re: Two way trust setup issue

2018-06-14 Thread Alexander Bokovoy via FreeIPA-users
On to, 14 kesä 2018, Merritt, Todd R - (tmerritt) via FreeIPA-users wrote: Thanks Alexander, The DNS entries were actually correct, I had a missing _ in my test query but thank you for pointing me in the right direction. The underlying issues ended up being a mix of firewall permits