[Freeipa-users] Re: several IPA CA certificate entries

2017-10-23 Thread Anvar Kuchkartaev via FreeIPA-users
Have you tried to add CA to systemwide database?

[Freeipa-users] Re: several IPA CA certificate entries

2017-10-23 Thread Anvar Kuchkartaev via FreeIPA-users
Peer certificate cannot be authenticated with known CA certificatesThis error shows that your system cannot authenticate remote host (curl probably trying to authenticate using systemwide database rather than the

[Freeipa-users] Re: SSHFP Records on external DNS

2017-12-03 Thread Anvar Kuchkartaev via FreeIPA-users
From client command line ssh-keygen -r `hostname` will give you sshfp records. Anvar Kuchkartaev  an...@aegisnet.eu    Original Message   From: Günther J. Niederwimmer via FreeIPA-users Sent: domingo, 3 de diciembre de 2017 15:50 To: freeipa-users@lists.fedorahosted.org Reply To: FreeIPA users lis

[Freeipa-users] One way trust between 2 different freeipa servers

2017-12-10 Thread Anvar Kuchkartaev via FreeIPA-users
Hello I would like to setup one way trust between 2 different freeipa structures which belongs to different companies. The stucture is:Company A has own freeipa structures with replicas etc. with domain companya.com. Company B has own freeipa domain independent from company A (let's say companyb.c

[Freeipa-users] Re: Centos7.4: users not seeing password expired notifications

2017-12-22 Thread Anvar Kuchkartaev via FreeIPA-users
Upgrading from 7.3 to 7.4 caused inability to login to gnome environment for me and I made fresh install all workstations of Centos/RHEL/Oracle Linux manually. Anvar Kuchkartaev  an...@aegisnet.eu    Original Message   From: Stephen Berg (Contractor, Code 7320) via FreeIPA-users Sent: jueves, 21

[Freeipa-users] Re: how to avoid ntpd?

2018-01-15 Thread Anvar Kuchkartaev via FreeIPA-users
If you installed freeipa service or client with option --no-ntp then it won't use ntp to synchronise clock. If you have already ipa server with ntpd installed: ‎https://www.redhat.com/archives/freeipa-users/2014-August/msg00197.html Anvar Kuchkartaev  an...@aegisnet.eu    Original Message   Fro

[Freeipa-users] Using multiple hostnames in freeipa https, ldap, kerberos kdc certificates

2018-07-23 Thread Anvar Kuchkartaev via FreeIPA-users
Hello everyone, I am planning to deploy replica of freeipa to AWS, and I have following idea: * Lets say freeipa domain is example.com * freeipa domain has it's own CA * all aws hosts will get hostname automatically over dhcp options in vpc like ip-xxx-xxx-xxx-xxx.aws.example.com * Fr

[Freeipa-users] using multiple hostnames in freeipa https, ldap, kerberos kdc certificates

2018-07-23 Thread Anvar Kuchkartaev via FreeIPA-users
Hello everyone, I am planning to deploy replica of freeipa to AWS, and I have following idea: * Lets say freeipa domain is example.com * freeipa domain has it's own CA * all aws hosts will get hostname automatically over dhcp options in vpc like ip-xxx-xxx-xxx-xxx.aws.example.com * Fr