[Freeipa-users] Seeking advice on testing ipa internal certificate renewal

2018-05-08 Thread Roderick Johnstone via FreeIPA-users
Hi In our current ipa implementation some of the ipa internal certificates are not able to be renewed correctly. After a lot of support both from Redhat and also through this list, neither of which was able to fix the issue, I was advised by Redhat to implement a new instance of ipa and

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-23 Thread Roderick Johnstone via FreeIPA-users
On 15/01/2018 20:07, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 15/01/2018 16:06, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: Hi Our freeipa certificates need to be renewed due to passing their expiry dates

[Freeipa-users] Certificates renewing with the wrong Subject

2018-01-15 Thread Roderick Johnstone via FreeIPA-users
Hi Our freeipa certificates need to be renewed due to passing their expiry dates. While some certificates have renewed ok, the ipaCert and auditSigningCert are renewing but the new certificates have the wrong Subject. Environment is: serverA (CRL, first, master) RHEL 7.3, ipa 4.4 serverB

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-25 Thread Roderick Johnstone via FreeIPA-users
On 25/01/2018 13:43, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 21:09, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 15:22, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-25 Thread Roderick Johnstone via FreeIPA-users
On 24/01/2018 21:09, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 15:22, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 23/01/2018 14:34, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-24 Thread Roderick Johnstone via FreeIPA-users
On 24/01/2018 15:22, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 23/01/2018 14:34, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 15/01/2018 20:07, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-02-01 Thread Roderick Johnstone via FreeIPA-users
On 31/01/2018 20:36, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 16:56, Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 13:43, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 21

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-30 Thread Roderick Johnstone via FreeIPA-users
On 25/01/2018 16:56, Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 13:43, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 21:09, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 24/01/2018 15

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-02-07 Thread Roderick Johnstone via FreeIPA-users
On 05/02/2018 19:44, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone wrote: On 31/01/2018 20:36, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 16:56, Roderick Johnstone via FreeIPA-users wrote: On 25/01/2018 13:43, Rob Crittenden

[Freeipa-users] Re: Certificates renewing with the wrong Subject

2018-01-24 Thread Roderick Johnstone via FreeIPA-users
On 23/01/2018 14:34, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 15/01/2018 20:07, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone via FreeIPA-users wrote: On 15/01/2018 16:06, Rob Crittenden via FreeIPA-users wrote: Roderick Johnstone

[Freeipa-users] What does migration mode actually do?

2018-03-09 Thread Roderick Johnstone via FreeIPA-users
Hi I'm using migration mode (ipa config-mod --enable-migration=true) to help migrate from one freeipa instance to another. I wasn't able to find any docs on what enabling migration mode actually does, exactly. Can anyone supply details please? Thanks. Roderick Johnstone

[Freeipa-users] Re: What does migration mode actually do?

2018-03-09 Thread Roderick Johnstone via FreeIPA-users
On 09/03/2018 09:13, Florence Blanc-Renaud wrote: On 03/09/2018 09:41 AM, Roderick Johnstone via FreeIPA-users wrote: Hi I'm using migration mode (ipa config-mod --enable-migration=true) to help migrate from one freeipa instance to another. I wasn't able to find any docs on what enabling

[Freeipa-users] Inconsistencies in account preserved status

2018-10-22 Thread Roderick Johnstone via FreeIPA-users
Hi This is ipa-server-4.5.4-10.el7_5.4.4.x86_64 on RHEL7.5. I've got four preserved accounts (out of a few hundred preserved accounts). On two of the servers they are showing up correctly as preserved with this command: ipa user-show . On the third server the same command shows the users

[Freeipa-users] Re: Inconsistencies in account preserved status

2018-10-23 Thread Roderick Johnstone via FreeIPA-users
On 22/10/2018 21:27, Florence Blanc-Renaud wrote: On 10/22/18 2:10 PM, Roderick Johnstone via FreeIPA-users wrote: Hi This is ipa-server-4.5.4-10.el7_5.4.4.x86_64 on RHEL7.5. I've got four preserved accounts (out of a few hundred preserved accounts). On two of the servers they are showing

[Freeipa-users] LDAP schema query

2019-02-21 Thread Roderick Johnstone via FreeIPA-users
Hi I've integrated our netapp VSMs (Data onTap 9.4) into our freeipa environment using a simple bind to the ldap servers. freeipa has compat mode enbled. The netapps are currently configured to use the RFC2307 ldap schema and that seems to work well. Now I'm wondering whether using the

[Freeipa-users] Replica not renewing IPA certificates

2020-01-31 Thread Roderick Johnstone via FreeIPA-users
Hi This is freeipa (ipa-server-4.6.5-11.el7_7.3.x86_64) on RHEL7 with freeipa's own internal CA. One of my ipa server replicas (host3) has not renewed its IPA system certificates and is now showing ca-error: Invalid cookie: u'' in the 'getcert list' output for certificates:

[Freeipa-users] Re: Replica not renewing IPA certificates

2020-01-31 Thread Roderick Johnstone via FreeIPA-users
On 31/01/2020 13:25, Florence Blanc-Renaud wrote: On 1/31/20 2:03 PM, Roderick Johnstone via FreeIPA-users wrote: Hi This is freeipa (ipa-server-4.6.5-11.el7_7.3.x86_64) on RHEL7 with freeipa's own internal CA. One of my ipa server replicas (host3) has not renewed its IPA system

[Freeipa-users] Apparently transient error cl5DBData2Entry - Invalid data version

2020-04-29 Thread Roderick Johnstone via FreeIPA-users
Hi We have 3 IPA servers which we are in the process of updating from RHEL 7.7 to RHEL 7.8. Servers X, Z are at: ipa-server-4.6.6-11.el7.x86_64 (RHEL 7.8) Server W is at: ipa-server-4.6.5-11.el7_7.3.x86_64 (RHEL 7.7) Server X was updated some time ago, and server Z was updated last Thursday.