[Freeipa-users] Re: performance tuning IPA 4.5 and SSD for large AD integration

2018-08-01 Thread Jakub Hrozek via FreeIPA-users
> On 1 Aug 2018, at 06:08, Alexandre Pitre wrote: > > Hi Jakub, > > I understand that cache_first=true is set in the [nss] section of > /etc/sssd/sssd.conf but what about the negative cache setting you are > referring to ? Could you please give an example ? > > Looking at

[Freeipa-users] Re: FreeIPA replica

2018-08-01 Thread Alfredo De Luca via FreeIPA-users
Hi Alexander. yes I did.. these are all the options with client install ipa-client-install --force-join --domain digit.test --server idm.digit.test --realm MYTESTDOMAIN.IT --hostname ipa-repl.digit.test --mkhomedir -U --principal admin --password and all went well. I can access the host with

[Freeipa-users] Re: FreeIPA replica

2018-08-01 Thread Alexander Bokovoy via FreeIPA-users
On ti, 31 heinä 2018, Alfredo De Luca via FreeIPA-users wrote: Hi all. I am trying to add a replica on a freeIPA Server lev 1 (version 4.5.4 on Centos 7) but I get the following error; ipa.ipapython.install.cli.install_tool(CompatServerReplicaInstall): ERROR Cannot promote this client to a

[Freeipa-users] Re: Problem with replication topology after replica removal

2018-08-01 Thread Florence Blanc-Renaud via FreeIPA-users
On 07/20/2018 04:45 PM, Przemysław Orzechowski via FreeIPA-users wrote: Hi I removed a replica but after removal i got 3 undeleted replication agreements I can't delete it with ipa topologysegment-del error returned ipa: ERROR: Server is unwilling to perform: Removal of Segment

[Freeipa-users] Re: FreeIPA replica

2018-08-01 Thread Alexander Bokovoy via FreeIPA-users
On ke, 01 elo 2018, Alfredo De Luca via FreeIPA-users wrote: Thanks heaps Alexander. That made the trick. Now if all the ipa clients point to the master and it goes down ...the replica will do the job but ...do I need to change the DNS to add the replica? Read ipa-client-install man page, it

[Freeipa-users] Prevent users reading other users' data from the WebUI

2018-08-01 Thread Callum Smith via FreeIPA-users
Dear All, Seems this has come up before but the previous fix no longer works. Is there a way to do this through the Roles, because it doesn't seem obvious to me immediately? Any help welcomed! Regards, Callum -- Callum Smith Research Computing Core Wellcome Trust Centre for Human Genetics

[Freeipa-users] Re: FreeIPA replica

2018-08-01 Thread Alfredo De Luca via FreeIPA-users
Thanks heaps. Cheers On Wed, Aug 1, 2018 at 12:12 PM Alexander Bokovoy wrote: > On ke, 01 elo 2018, Alfredo De Luca via FreeIPA-users wrote: > >Thanks heaps Alexander. That made the trick. > > > >Now if all the ipa clients point to the master and it goes down ...the > >replica will do the job

[Freeipa-users] Re: ERR - attrlist_replace - attr_replace (nsslapd-referral,

2018-08-01 Thread James Harrison via FreeIPA-users
Any ideas, anyone? On Tue, 31 Jul 2018 at 13:22, James Harrison via FreeIPA-users wrote: Hello, We have a machine with the following set up: CentOS Linux release 7.4.1708 (Core)ipa-server-4.5.0-21.el7.centos.2.2.x86_64 CA-less setup We're getting a lot of errors on one of our FreeIPA

[Freeipa-users] Re: ERR - attrlist_replace - attr_replace (nsslapd-referral,

2018-08-01 Thread Mark Reynolds via FreeIPA-users
https://pagure.io/389-ds-base/c/6f585fa9adaa83efa98b72aa112e162f180b0ad1 On 08/01/2018 09:55 PM, James Harrison via FreeIPA-users wrote: Any ideas, anyone? This is a known "issue".  The message itself is harmless, and it has been "fixed" in 389-ds-base-1.3.6.1-22 On Tue, 31 Jul 2018 at

[Freeipa-users] Re: /etc/httpd/alias not getting renewed cert

2018-08-01 Thread Thomas Letherby via FreeIPA-users
I think I'm stuck in a bit of a catch 22 here, I can't update the cert because the cert it's replacing is bad. Is there a way to force it to ignore the existing cert when it goes to update? Thomas On Mon, Jul 23, 2018 at 8:59 PM Thomas Letherby wrote: > Hello Brian, > > No problem, I don't

[Freeipa-users] Creating CA replica fails

2018-08-01 Thread Aaron Hicks via FreeIPA-users
Hello the List, I'm successfully replicating IPA and DNS across two sites, however when I try and replicate CA it fails: [root@ipa01 pki]# ipa-ca-install Directory Manager (existing master) password: Run connection check to master Connection check OK

[Freeipa-users] Re: Creating CA replica fails

2018-08-01 Thread Fraser Tweedale via FreeIPA-users
Hi Aaron, Can you please provide the contents of /var/log/pki/pki-ca-spawn.20180802044015.log, and /var/log/pki/pki-tomcat/ca/debug from both the replica (if it exists) and the master. Thanks, Fraser On Thu, Aug 02, 2018 at 05:03:54PM +1200, Aaron Hicks via FreeIPA-users wrote: > Hello the