[Freeipa-users] attrlist_replace - attr_replace failed

2018-05-09 Thread Sandor Juhasz via FreeIPA-users
Hello, we have a 4 way master master replication. Which is finnaly working, but we still see one error: [09/May/2018:14:21:27.882261986 +0200] attrlist_replace - attr_replace (nsslapd-referral, ldap://ipa34.bph.cxn:389/o%3Dipaca) failed. [09/May/2018:14:21:31.827746424 +0200] attrlist_replace -

[Freeipa-users] upgrade from 4.4 to 4.5

2018-05-10 Thread Sandor Juhasz via FreeIPA-users
Hello, we have upgraded from 4.4 to 4.5. The upgrade seems successful, but there is a small issue. Replication is in sync in the 4 way master cluster. Everything replicates - users, groups, properties. The list gives the last successful update time. If we run ipa-replica-manage force-sync --from

[Freeipa-users] ipa replication issues

2018-04-13 Thread Sandor Juhasz via FreeIPA-users
Hello, we are using freeipa in a 4way multi master replication setup. Servers ipa14,ipa15 and ipa34,ipa35 on CentOS Linux release 7.3.1611 (Core) with version ipa-server-common-4.4.0-14.el7.centos.7.noarch. We have an issue where one of the servers log a missing CSN. It happens even after ipa

[Freeipa-users] Re: ipa replication issues

2018-04-13 Thread Sandor Juhasz via FreeIPA-users
here are the results: [root@ipa14 ~]# ldapsearch -H ldap://ipa14.bpo.cxn -o ldif-wrap=no -D "cn=directory manager" -x -W -b cn=config "objectclass=nsds5replica" nsds5replicaid nsds50ruv Enter LDAP Password: # extended LDIF # # LDAPv3 # base

[Freeipa-users] Re: ipa user-del and UI fails, as well, ldapdelete

2019-08-07 Thread Sandor Juhasz via FreeIPA-users
Park, Záhony utca 7, Budapest, Hungary, H-1031 Cell: +36704258964 On Wed, Aug 7, 2019 at 3:58 PM Rob Crittenden wrote: > Sandor Juhasz via FreeIPA-users wrote: > > We have an entry, what after clicking delete on the UI got partially > > deleted. > > The comp

[Freeipa-users] Re: ipa user-del and UI fails, as well, ldapdelete

2019-08-07 Thread Sandor Juhasz via FreeIPA-users
ilding Hx, GraphiSoft Park, Záhony utca 7, Budapest, Hungary, H-1031 > > Cell: +36704258964 > > > > > > On Wed, Aug 7, 2019 at 3:58 PM Rob Crittenden > <mailto:rcrit...@redhat.com>> wrote: > > > > Sandor Juhasz via FreeIPA-users wrote: >

[Freeipa-users] ipa user-del and UI fails, as well, ldapdelete

2019-08-07 Thread Sandor Juhasz via FreeIPA-users
We have an entry, what after clicking delete on the UI got partially deleted. The compat tree entry is gone. The accounts tree entry is there. ldapsearch finds the entry by uid, but does fail by dn. ipa user-show finds the user ipa user-del says no such user ldapdelete fails to delete the entry

[Freeipa-users] Re: ipa user-del and UI fails, as well, ldapdelete

2019-08-07 Thread Sandor Juhasz via FreeIPA-users
ectClass: mepOriginEntry >> mepManagedEntry: cn=,cn=groups,cn=accounts,dc=cxn >> >> What led you to manually disconnect the group? >> >> rob >> >> > -- >> > *Sándor Juhász* >> > System Administrator >> > *ChemAxon* *Kft*. >> &

[Freeipa-users] Re: ipa user-del and UI fails, as well, ldapdelete

2019-08-07 Thread Sandor Juhasz via FreeIPA-users
c=cxn >>> >>> What led you to manually disconnect the group? >>> >>> rob >>> >>> > -- >>> > *Sándor Juhász* >>> > System Administrator >>> > *ChemAxon* *Kft*. >>> > Building Hx,

[Freeipa-users] Re: ipa user-del and UI fails, as well, ldapdelete

2019-08-08 Thread Sandor Juhasz via FreeIPA-users
, 2019 at 7:15 PM Rob Crittenden wrote: > Sandor Juhasz via FreeIPA-users wrote: > > I was able to cheat it on the replica where the user was not partially > > deleted. > > I had to recreate and reattach the deleted group. > > Then detach it with > > ipa grou

[Freeipa-users] IPA ocsp responder cert

2019-10-28 Thread Sandor Juhasz via FreeIPA-users
Hi, we are running freeipa server 4.6.5. Facing the issue, where the ocsp responder in the Server-Cert is set to Name: Authority Information Access Method: PKIX Online Certificate Status Protocol Location: URI: "http://ipa-ca.bpo.cxn/ca/ocsp; Where the

[Freeipa-users] Re: IPA ocsp responder cert

2019-10-28 Thread Sandor Juhasz via FreeIPA-users
28, 2019 at 2:10 PM Rob Crittenden wrote: > Sandor Juhasz via FreeIPA-users wrote: > > Hi, > > > > we are running freeipa server 4.6.5. > > Facing the issue, where the ocsp responder in the Server-Cert is set > > to > > Name: Authority Information Acc