Re: [Freeipa-users] Insufficient access during winsync agreement

2011-06-21 Thread Attila Bogár
On 20/06/11 16:37, Attila Bogár wrote: I'm trying to set up the AD-FreeIPA sync agreement and I'm always getting this error: # ipa-replica-manage connect --winsync --binddn cn=IPA Sync,cn=Users,dc=win,dc=example,dc=com --bindpw JamesBond007 --cacert /root/dc1.cer --passsync JamesBond007

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Adam Tkac
On 06/16/2011 09:38 PM, Loris Santamaria wrote: El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: Hi, I would like to use my freeIPA v2 server as my master name server and have other normal (non ldap based) bind servers as

Re: [Freeipa-users] Insufficient access during winsync agreement

2011-06-21 Thread Simo Sorce
On Tue, 2011-06-21 at 10:01 +0100, Attila Bogár wrote: On 20/06/11 16:37, Attila Bogár wrote: I'm trying to set up the AD-FreeIPA sync agreement and I'm always getting this error: # ipa-replica-manage connect --winsync --binddn cn=IPA Sync,cn=Users,dc=win,dc=example,dc=com --bindpw

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Simo Sorce
On Tue, 2011-06-21 at 12:12 +0200, Adam Tkac wrote: On 06/16/2011 09:38 PM, Loris Santamaria wrote: El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: Hi, I would like to use my freeIPA v2 server as my master name server

[Freeipa-users] syncing custom attributes from AD

2011-06-21 Thread Attila Bogár
Dear List, I'd like to sync extra attributes from AD - FreeIPA. These are namely: employeeNumber and employeeType. The following .ldif is always adding value unknown instead of syncing the value in AD. -- 8 -- dn: cn=ipa-winsync,cn=plugins,cn=config changetype: modify add: ipaWinSyncUserAttr

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Loris Santamaria
El mar, 21-06-2011 a las 12:12 +0200, Adam Tkac escribió: On 06/16/2011 09:38 PM, Loris Santamaria wrote: El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: Hi, I would like to use my freeIPA v2 server as my master name

Re: [Freeipa-users] DNS zone transfers

2011-06-21 Thread Adam Tkac
On 06/21/2011 03:51 PM, Loris Santamaria wrote: El mar, 21-06-2011 a las 12:12 +0200, Adam Tkac escribió: On 06/16/2011 09:38 PM, Loris Santamaria wrote: El jue, 16-06-2011 a las 11:27 -0400, Simo Sorce escribió: On Thu, 2011-06-16 at 10:31 -0430, Loris Santamaria wrote: Hi, I would like to

[Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
Hi, I'm still running a FreeIPA 1.2 server but have started installing Fedora 15 clients and am trying to figure out how to manually setup the Krb/LDAP configuration. I've run the 'authconfig-tui' command and manually setup Krb authentication and LDAP authorisation, using DNS discovery for the

[Freeipa-users] ipa-winsync account disable

2011-06-21 Thread Attila Bogár
Dear List, winsync is working between AD and FreeIPA. If I disable a user in FreeIPA, it automatically disables on the AD side. Though, if I disable on the AD side, nothing happens on the FreeIPA side. Moreover, if I get a kerberos ticket for the disabled (only in AD) user from freeipa, then

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: Hi, I'm still running a FreeIPA 1.2 server but have started installing Fedora 15 clients and am trying to figure out how to manually setup the Krb/LDAP configuration. I've run the 'authconfig-tui' command and manually setup Krb

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: Hi, I'm still running a FreeIPA 1.2 server but have started installing Fedora 15 clients and am

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: Hi, I'm still running a

Re: [Freeipa-users] syncing custom attributes from AD

2011-06-21 Thread Rich Megginson
On 06/21/2011 07:24 AM, Attila Bogár wrote: Dear List, I'd like to sync extra attributes from AD - FreeIPA. These are namely: employeeNumber and employeeType. The following .ldif is always adding value unknown instead of syncing the value in AD. -- 8 -- dn:

Re: [Freeipa-users] ipa-winsync account disable

2011-06-21 Thread Rich Megginson
On 06/21/2011 09:17 AM, Attila Bogár wrote: Dear List, winsync is working between AD and FreeIPA. If I disable a user in FreeIPA, it automatically disables on the AD side. Though, if I disable on the AD side, nothing happens on the FreeIPA side. Sounds like a bug. Moreover, if I get a

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 11:58 -0400, Dan Scott wrote: On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 14:19, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:58 -0400, Dan Scott wrote: On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Stephen Gallagher
On Tue, 2011-06-21 at 14:41 -0400, Dan Scott wrote: Excellent! Thanks - that makes much more sense. I've been using authconfig-tui all this time and had no idea that it was doing things incorrectly. One small issue that I found, if I switch on the Use DNS to resolve hosts to realms