[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-09-19 Thread Jason Sherrill via FreeIPA-users
Hello David, I'm experiencing similar issues with ldapsearch command, though no issues authenticating for logon, ssh (to linux machines), DNS updates, and directory services. I'm confident the issue lies with MacOS. I'm running MacOS 10.12.6 and IPA 4.5. I'll keep digging, just wanted to let you

[Freeipa-users] Re: Integrations with non-linux environments

2018-05-07 Thread Jason Sherrill via FreeIPA-users
Hi Jeff, Concerning your issues with freeIPA and Mac OS X, are local user accounts created and then converted to mobile accounts ($ sudo /System/Library/CoreServices/ManagedClient.app/Contents/Resources/createmobileaccount -n *username)? *Otherwise, I would verify the Directory Utility configurati

[Freeipa-users] Re: Integrations with non-linux environments

2018-05-08 Thread Jason Sherrill via FreeIPA-users
It sounds that there is an issue with connecting to the LDAP service (you can authenticate w/ kinit but can't browse the directory). It could be server's firewall but I suspect you are not having an issue with Linux workstations. Mac OS's directory services setup is likely the issue, if in *Direct

[Freeipa-users] Request to Contribute a How/To Page

2017-05-24 Thread Jason Sherrill via FreeIPA-users
I would like to post the procedure that I used for configuring OS X 10.12 for use with IPA. My fedora account is jr_sherr...@yahoo.com, may it be added to the editors group for the IPA's wiki? Thank you! -- *Jason Sherrill* Deeplocal Inc. mobile: 412-636-2073 <(412)%20636

[Freeipa-users] Re: Request to Contribute a How/To Page

2017-05-25 Thread Jason Sherrill via FreeIPA-users
25, 2017 at 6:43 AM, Martin Bašti wrote: > Hello, > > could you please log in to wiki page, we can add permissions after initial > login. > > Martin > > On 24.05.2017 16:39, Jason Sherrill via FreeIPA-users wrote: > > I would like to post the procedure that I used fo

[Freeipa-users] Re: Request to Contribute a How/To Page

2017-05-25 Thread Jason Sherrill via FreeIPA-users
Opened in incognito, same error: "An error occurred: an invalid token was found." On Thu, May 25, 2017 at 12:12 PM, Martin Bašti wrote: > Could you try to clean cookies or incognito mode? > > On 25.05.2017 16:08, Jason Sherrill via FreeIPA-users wrote: > > I su

[Freeipa-users] How to Setup FreeIPA Services for Mac OS X 10.12

2017-06-14 Thread Jason Sherrill via FreeIPA-users
Hello All, I have recently submitted a How/To for FreeIPA. I'd very much appreciate any feedback or editing on it- I don't want to link to it without a review. Thanks! -- *Jason Sherrill* Deeplocal Inc.

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-06-15 Thread Jason Sherrill via FreeIPA-users
Thank you Lee and Jens! I've been testing your suggestions and I'll start deploying the changes next week. On Thu, Jun 15, 2017 at 6:03 AM, Jens Timmerman via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi, > > On 14/06/2017 18:02, Jason Sherril

[Freeipa-users] Re: OSX (El Capitan) - FreeIPA

2017-07-25 Thread Jason Sherrill via FreeIPA-users
Hi Luiz, Would you please verify your settings in: System Preferences > Users & Groups > Login Options > Network Account Server > Directory Utility > Services > LDAP > Your LDAP server > Search & Mappings There should be a Record Type called 'Groups' with an attribute 'PrimaryGroupID' that is mapp

[Freeipa-users] Re: OSX (El Capitan) - FreeIPA

2017-07-26 Thread Jason Sherrill via FreeIPA-users
Luiz, Would you please run the below command from an OS X workstation's terminal to test look-up/caching of groups? If it displays a gid then we know the issue isn't LDAP mapping. dscacheutil -q group -a name *yourGroupName* On Tue, Jul 25, 2017 at 11:30 AM, Luiz Garrido ALKEMY X via FreeIPA-us

[Freeipa-users] Re: web UI - login failed after updates on server

2017-08-17 Thread Jason Sherrill via FreeIPA-users
Stefan, I resolved a similar issue on a Fedora host by setting selinux to permissive instead of enforcing. The setting is located in /etc/selinux/config On Thu, Aug 17, 2017 at 10:37 AM, Stefan Uygur via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hi everyone, > > I have an IP