[Freeipa-users] Re: Samba integration

2018-12-11 Thread Николай Савельев via FreeIPA-users
10.12.2018, 14:13, "Alexander Bokovoy" : > On ma, 10 joulu 2018, Николай Савельев via FreeIPA-users wrote: >> Hello. >> I try to set up samba with freeipa. >> I use this article >> https://www.freeipa.org/page/Howto/Integrating_a_Samba_File_Server_With_IPA >> >> But I have strange error: >> >>

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread Florence Blanc-Renaud via FreeIPA-users
On 12/11/18 12:59 PM, 74cmonty via FreeIPA-users wrote: Hi Flo, thanks for your reply. I decided to start replica setup from scratch. This means I executed this command on master: ipa-replica-manage del ipa-replica.biszumbitterenen.de Then I restored the replica server to a previous state,

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hi Flo, I have defined the IP of my router as DNS: [root@ipa-master ~]# ipa dnsserver-show Servername: ipa-master.biszumbitterenen.de Servername: ipa-master.biszumbitterenen.de SOA mname override: ipa-master.biszumbitterenen.de. Forwarders: 192.168.100.1 Forward policy: only The same IP

[Freeipa-users] FreeIPA ca for kerberos

2018-12-11 Thread None via FreeIPA-users
Hello, if possible i would like to use the FreeIPA ca for Kubernetes. but kubernetes has some requirements on the CN and O. the CN has to match the pattern system:node:$FQDN and O has to match system:node also see:

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hello Flo, I successfully installed FreeIPA 4.7.2 packages on replica server: ``` [root@ipa-replica ~]# rpm -q freeipa-server freeipa-client ipa-server ipa-client 3 89-ds-base pki-ca krb5-server

[Freeipa-users] Re: is anyone running Debian as freeipa-client

2018-12-11 Thread Harald Dunkel via FreeIPA-users
Hi Johan, I am using freeipa 4.4.4-3 and sssd 1.16.3-1 on Stretch. Just the client part of freeipa, of course. Requires systemd for running ipa-client-install, but it works fine for me. My ipa servers are running on CentOS 7. Regards Harri ___

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread Alexander Bokovoy via FreeIPA-users
On ti, 11 joulu 2018, cdknight via FreeIPA-users wrote: When a user signs in to FreeIPA, I do not want them to be able to view the list of users in my LDAP server under the "Active users" link. I still want them to be able to administer self-service, so they can reset their password, add OTP

[Freeipa-users] Re: client ldap issue

2018-12-11 Thread Jaroslav Shejbal via FreeIPA-users
Hi, I've completely solved my issue, the last part was missing libnss-sss. I wonder that this package was not some dependency, anyway here is the list of packages needed to run client under current stable debian(stretch): - nscd - sssd - sssd-tools -

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread 74cmonty via FreeIPA-users
Hi Flo, thanks for your reply. I decided to start replica setup from scratch. This means I executed this command on master: ipa-replica-manage del ipa-replica.biszumbitterenen.de Then I restored the replica server to a previous state, installed freeipa-packages 4.7.2 (and its dependencies).

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread cdknight via FreeIPA-users
Thanks for the responses. Therefore, I will instead have to restrict access to the Web UI either by creating an HBAC rule (this is my understanding of what to do), and instead allowing them access a secondary self-service UI like https://github.com/ubccr/mokey. While this secondary software

[Freeipa-users] Re: How to prevent non-admin users of FreeIPA from reading the list of users in the web interface?

2018-12-11 Thread Alexander Bokovoy via FreeIPA-users
On ti, 11 joulu 2018, cdknight via FreeIPA-users wrote: Thanks for the responses. Therefore, I will instead have to restrict access to the Web UI either by creating an HBAC rule (this is my understanding of what to do), and instead allowing them access a secondary self-service UI like

[Freeipa-users] Re: Installation Replica reports error: Full PKINIT configuration did not succeed

2018-12-11 Thread Florence Blanc-Renaud via FreeIPA-users
On 12/11/18 11:23 AM, 74cmonty via FreeIPA-users wrote: Hello Flo, I successfully installed FreeIPA 4.7.2 packages on replica server: ``` [root@ipa-replica ~]# rpm -q freeipa-server freeipa-client ipa-server ipa-client 3