[Freeipa-users] Re: Export service keytab as Active Directory user

2018-11-23 Thread Alexander Bokovoy via FreeIPA-users
Not possible in centos 7. Possible in RHEL8 beta. (Sorry for being short, I'm on the phone) - Michael Gusek via FreeIPA-users wrote: > Hi, > > we are running FreeIPA 4.5.4 on Centos 7 with a one way trust to an > Active Directory. We want to allow AD users to retrieve service keytab > on

[Freeipa-users] Export service keytab as Active Directory user

2018-11-23 Thread Michael Gusek via FreeIPA-users
Hi, we are running FreeIPA 4.5.4 on Centos 7 with a one way trust to an Active Directory. We want to allow AD users to retrieve service keytab on FreeIPA managed hosts. AD users are linked to a external group, and these group to a FreeIPA group.  We've created a service and allowed FreeIPA group

[Freeipa-users] Re: IPA server upgrade fails with KDC error

2018-11-23 Thread Zarko D via FreeIPA-users
Hi, have you found resolution here? I get same/similar error while troubleshooting expired certificates, for example going back in time when all certs are valid and restarting certmonger, then I see this error. ___ FreeIPA-users mailing list --

[Freeipa-users] Re: IPA server upgrade fails with KDC error

2018-11-23 Thread Zarko D via FreeIPA-users
> Hi, have you found resolution here? > > I get same/similar error while troubleshooting expired certificates, for > example going > back in time when all certs are valid and restarting certmonger, then I see > this error. sorry, please ignore. Apologies.