[Freeipa-users] Cert Issue

2019-09-07 Thread Randy Morgan via FreeIPA-users
We have been working to solve an expired certificate issue in IPA.  There is an open ticket in Red Hat supportCASE 02438518.  We have tried many things but so far have had no luck getting the certs to update.  Currently the system is running RHEL 8.0 and IPA 4.7.1. pki-server cert-fix -n 'subs

[Freeipa-users] Terminating replication agreement

2019-09-26 Thread Randy Morgan via FreeIPA-users
I have a two year image of one of my IPA servers that I am trying to bring live.  Unfortunately all of the certs except the CA are expired.  I have attempted to follow the instructions for updating the certs, but it has failed to update them.  After careful and extensive digging, I have found t

[Freeipa-users] Re: Terminating replication agreement

2019-09-26 Thread Randy Morgan via FreeIPA-users
by making regular recovery points (backups, snapshots, periodic master updates). I’m assuming this is a recovery action from total loss of everything? If not: don’t bother with that image, install a fresh master instead. John On 26 Sep 2019, at 23:59, Randy Morgan via FreeIPA-users wrote: I

[Freeipa-users] Re: Terminating replication agreement

2019-09-26 Thread Randy Morgan via FreeIPA-users
-users wrote: What do you mean by ‘rebuilt’? Also: is that image a CA master and how does it fail when you run it with the clock turned back and network unplugged/firewalled? John On 27 Sep 2019, at 00:10, Randy Morgan via FreeIPA-users wrote: Tried everything you just suggested, and it

[Freeipa-users] Zone transfers between external DNS slave and Internal IPA master

2018-03-01 Thread Randy Morgan via FreeIPA-users
We are reconfiguring our DNS to move away from a much older version of Bind on some RHEL 5 servers to Bind 9+ on RHEL 7.4. Currently our setup has two external slaves that do zone transfers from the internal masters allowing public facing servers to be known on the internet.  Our new setup will

[Freeipa-users] FreeIPA and Automount

2018-03-27 Thread Randy Morgan via FreeIPA-users
We have been working to get automounting working on RHEL 7.4 without any success.  I am including how the server has been built, ipa-client installed and configured, etc.  I will also include the relevant parts of the logs. 1. Install RHEL 7.4 or other required version 2. subscription-ma

[Freeipa-users] Re: FreeIPA and Automount

2018-03-28 Thread Randy Morgan via FreeIPA-users
Randy Morgan CSR Department of Chemistry and Biochemistry Brigham Young University 801-422-4100 On 03/28/2018 13:19, Rob Crittenden wrote: Randy Morgan via FreeIPA-users wrote: We have been working to get automounting working on RHEL 7.4 without any success.  I am including how the server has

[Freeipa-users] Re: FreeIPA and Automount

2018-03-28 Thread Randy Morgan via FreeIPA-users
Randy Morgan CSR Department of Chemistry and Biochemistry Brigham Young University 801-422-4100 On 03/28/2018 13:19, Rob Crittenden wrote: Randy Morgan via FreeIPA-users wrote: We have been working to get automounting working on RHEL 7.4 without any success.  I am including how the server has

[Freeipa-users] Extended Schema attributes missing

2017-08-02 Thread Randy Morgan via FreeIPA-users
When we setup our IPA server, we extended the schema to include 3 fields that were important to the work we do. When we performed the last update, those fields still show as required, but they are missing and we cannot add users to IPA unless we remove the required aspect of those fields. The

[Freeipa-users] IPA Master won't start and replicas are not taking over

2017-08-14 Thread Randy Morgan via FreeIPA-users
Over the weekend our IPA Master failed and I can not get ipactl to start, the Directory Service fails. We have two replicas and I was under the impression that if one of the servers failed the others would pickup the load, that is not happening however, and we have been down for two days now.

[Freeipa-users] Samba update can't read NT Hash

2017-08-17 Thread Randy Morgan via FreeIPA-users
Yesterday we updated our fileserver to bring it up to the newest kernel. At the same time it update the ipa-client and samba. After the update was finished our ability to access the shared resources on the fileserver disappeared. After some very careful troubleshooting we have been able to na