Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Dan Scott
On Fri, Apr 13, 2012 at 17:44, Rich Megginson wrote: > On 04/13/2012 03:40 PM, Dan Scott wrote: >> I cleaned up all the "ruv_compare_ruv: RUV [changelog max RUV] does >> not contain element" errors in the logs for each of fileservers 1, 2 >> and 3. The ldapsearch for >> >> '(&(nsuniqueid=-

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Rich Megginson
On 04/17/2012 07:26 AM, Dan Scott wrote: On Fri, Apr 13, 2012 at 17:44, Rich Megginson wrote: On 04/13/2012 03:40 PM, Dan Scott wrote: I cleaned up all the "ruv_compare_ruv: RUV [changelog max RUV] does not contain element" errors in the logs for each of fileservers 1, 2 and 3. The ldapsearch

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Dan Scott
On Tue, Apr 17, 2012 at 09:26, Rich Megginson wrote: > On 04/17/2012 07:26 AM, Dan Scott wrote: >> >> On Fri, Apr 13, 2012 at 17:44, Rich Megginson  wrote: >>> >>> On 04/13/2012 03:40 PM, Dan Scott wrote: I cleaned up all the "ruv_compare_ruv: RUV [changelog max RUV] does not contai

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Richard Megginson
- Original Message - > On Tue, Apr 17, 2012 at 09:26, Rich Megginson > wrote: > > On 04/17/2012 07:26 AM, Dan Scott wrote: > >> > >> On Fri, Apr 13, 2012 at 17:44, Rich Megginson > >>  wrote: > >>> > >>> On 04/13/2012 03:40 PM, Dan Scott wrote: > > I cleaned up all the "ruv_compa

[Freeipa-users] Fwd: Problem creating replica file

2012-04-17 Thread Jorge Argibay Molina
Dmitri, I'm attaching the result of rpm -qa | sort I tried to follow the installation instructions to the letter, as it was my first installation. As I didn't have an existing CA, I asked the installation script to install its own CA. This is the only problem the installation seems to be havin

Re: [Freeipa-users] client without certmonger/dbus

2012-04-17 Thread Dmitri Pal
On 04/17/2012 02:09 AM, Christoph Kaminski wrote: > hi > > It is possible to use the ipa-client without certmonger/dbus? Have an > openvz environemnt where I cant start dbus... A quick review of openvz indicates that it supports dbus, so why this is an issue? If you feel this is still necessary pl

Re: [Freeipa-users] Screensaver unlock with expired password

2012-04-17 Thread Sigbjorn Lie
On Mon, April 16, 2012 23:43, Nalin Dahyabhai wrote: > On Mon, Apr 16, 2012 at 11:17:35PM +0200, Sigbjorn Lie wrote: > >> The clients use nss_ldap+pam_krb5, SSSD was crashing for us on RHEL 5. >> >> >> The server is the IPA server provided in RHEL 6.2. >> >> >> When I check the logs on the client i

Re: [Freeipa-users] DNS zone delegation

2012-04-17 Thread Petr Spacek
On 02/02/2012 10:23 AM, Adam Tkac wrote: On 02/01/2012 07:21 PM, Loris Santamaria wrote: Hi, I have a dns zone managed by IPA and I'm trying to delegate a zone managed by Active Directory. The IPA managed zone is called "corpfbk", and the AD one is "ad.corpfbk". I started by adding the proper

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Dan Scott
On Tue, Apr 17, 2012 at 10:29, Richard Megginson wrote: > - Original Message - >> On Tue, Apr 17, 2012 at 09:26, Rich Megginson >> wrote: >> > On 04/17/2012 07:26 AM, Dan Scott wrote: >> >> >> >> On Fri, Apr 13, 2012 at 17:44, Rich Megginson >> >>  wrote: >> >>> >> >>> On 04/13/2012 03:40

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Rich Megginson
On 04/17/2012 09:59 AM, Dan Scott wrote: On Tue, Apr 17, 2012 at 10:29, Richard Megginson wrote: - Original Message - On Tue, Apr 17, 2012 at 09:26, Rich Megginson wrote: On 04/17/2012 07:26 AM, Dan Scott wrote: On Fri, Apr 13, 2012 at 17:44, Rich Megginson wrote: On 04/13/2012 03

Re: [Freeipa-users] client without certmonger/dbus

2012-04-17 Thread Rob Crittenden
Christoph Kaminski wrote: hi It is possible to use the ipa-client without certmonger/dbus? Have an openvz environemnt where I cant start dbus... Is it not working for you at all? lack of certmonger should not cause a fatal installation problem, just a slew of scary error messages. There is

Re: [Freeipa-users] client without certmonger/dbus

2012-04-17 Thread Stephen Ingram
On Mon, Apr 16, 2012 at 11:09 PM, Christoph Kaminski wrote: > hi > > It is possible to use the ipa-client without certmonger/dbus? Have an openvz > environemnt where I cant start dbus... Christoph- You can install IPA in OpenVZ container. I was able to install after doing the following: 1. mkdi

Re: [Freeipa-users] client without certmonger/dbus

2012-04-17 Thread Stephen Ingram
On Tue, Apr 17, 2012 at 10:28 PM, Christoph Kaminski wrote: > done it without success :( > > [root@xaphon ~]# dbus-daemon --system --nofork > Failed to start message bus: Failed to drop capabilities: Operation not > permitted What OS and version are you using? I was using Fedora 15 template from

[Freeipa-users] Antwort: Re: client without certmonger/dbus

2012-04-17 Thread Christoph Kaminski
done it without success :( [root@xaphon ~]# dbus-daemon --system --nofork Failed to start message bus: Failed to drop capabilities: Operation not permittedMfGChristoph Kaminski-Stephen Ingram schrieb: -An: Christoph Kaminski Von: Stephen Ingram Datum: 18.04.2012 00:07Kopie: freeipa-users@

[Freeipa-users] Antwort: Re: Re: client without certmonger/dbus

2012-04-17 Thread Christoph Kaminski
centos 6.2 inside vserver, but I dont know what OS is the host system. (leased at heckrath.com)MfGChristoph KaminskiHealth Services Network AdministrationPhone: +49 (0) 30 68905-4645Fax: +49 (0) 30 68905-2940Mail: christoph.kamin...@biotronik.de-Stephen Ingram schrieb: -An: Christoph Kamin

Re: [Freeipa-users] client without certmonger/dbus

2012-04-17 Thread Stephen Ingram
On Tue, Apr 17, 2012 at 11:07 PM, Christoph Kaminski wrote: > centos 6.2 inside vserver, but I dont know what OS is the host system. > (leased at heckrath.com) You can do a cat /proc/version inside your container to see what version of the kernel they are using. I'm guessing it is pretty old sinc