[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-09-20 Thread David Harvey via FreeIPA-users
Thanks for your response and time Jason, much appreciated. It sounds like you in fact have almost the opposite symptoms to me, how strange! I did find that ldapsearch using -Y for GSSAPI was failing on Mac until I sorted out the reverse DNS entries for my IPA servers. The symptom was the

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-09-19 Thread Jason Sherrill via FreeIPA-users
Hello David, I'm experiencing similar issues with ldapsearch command, though no issues authenticating for logon, ssh (to linux machines), DNS updates, and directory services. I'm confident the issue lies with MacOS. I'm running MacOS 10.12.6 and IPA 4.5. I'll keep digging, just wanted to let

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-09-19 Thread David Harvey via FreeIPA-users
Note. The GSSAPI attempts from the MAc side are only attempted when a binddn (security -> "use authentication when connecting") account is provided. Otherwise I suspect it's unable to even work out what type of GSSAPI transaction to attempt.. On 19 September 2017 at 15:19, David Harvey

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-09-19 Thread David Harvey via FreeIPA-users
Some edits and expansion on my previous attempt to post... Free IPA 4.4.3 Mac OSX 10.12 Thanks for all the hard work on this, I've been enjoying an almost functional setup for the last week but have been tearing my hair out with making GSSAPI behave. What I have found so far using the config

[Freeipa-users] Re: How to Setup FreeIPA Services for Mac OS X 10.12

2017-06-14 Thread Lee Wiscovitch via FreeIPA-users
We run almost the exact same setup...Which is sufficient, but not as great as it could be (Basically the password changing issues you've noted). We've also noticed that a single bad login attempt gets counted multiple times on the IPA server, so you can get locked accounts quicker than