Re: [Freeipa-users] Desperate help requested.

2012-08-28 Thread Innes, Duncan
> -Original Message- > From: freeipa-users-boun...@redhat.com > [mailto:freeipa-users-boun...@redhat.com] On Behalf Of KodaK > Sent: 26 August 2012 05:06 > To: freeipa-users@redhat.com > Subject: [Freeipa-users] Desperate help requested. > > I've just been informed by my boss's boss's bos

[Freeipa-users] Default Expiry on IPA?

2012-08-28 Thread freeipa
Hi All, System: Red Hat Enterprise Linux Server release 6.3 (Santiago) ipa-server-2.2.0 Question: Has anyone managed to to actually set an expiry date (or longer 900+ day expiry time) on user account passwords in IPA? >From my testing, the default of 90 days is hard coded and the only way to ex

Re: [Freeipa-users] Default Expiry on IPA?

2012-08-28 Thread Petr Vobornik
On 08/28/2012 09:44 AM, free...@noboost.org wrote: Hi All, System: Red Hat Enterprise Linux Server release 6.3 (Santiago) ipa-server-2.2.0 Question: Has anyone managed to to actually set an expiry date (or longer 900+ day expiry time) on user account passwords in IPA? From my testing, the de

Re: [Freeipa-users] Default Expiry on IPA?

2012-08-28 Thread Rob Crittenden
Petr Vobornik wrote: On 08/28/2012 09:44 AM, free...@noboost.org wrote: Hi All, System: Red Hat Enterprise Linux Server release 6.3 (Santiago) ipa-server-2.2.0 Question: Has anyone managed to to actually set an expiry date (or longer 900+ day expiry time) on user account passwords in IPA? F

[Freeipa-users] PAM / SSSD / HBAC (was: Re: tacacs+ integration)

2012-08-28 Thread Michael Mercier
On 2012-08-22, at 4:12 PM, Rob Crittenden wrote: > Michael Mercier wrote: >> Hello, >> >> In Aug 2010, someone posted a message to this list about integrating >> tacacs+ with freeipa >> https://www.redhat.com/archives/freeipa-users/2010-August/msg00058.html >> >> At the time, it was mentioned th

Re: [Freeipa-users] PAM / SSSD / HBAC

2012-08-28 Thread Rob Crittenden
Michael Mercier wrote: On 2012-08-22, at 4:12 PM, Rob Crittenden wrote: Michael Mercier wrote: Hello, In Aug 2010, someone posted a message to this list about integrating tacacs+ with freeipa https://www.redhat.com/archives/freeipa-users/2010-August/msg00058.html At the time, it was mentione

[Freeipa-users] SELinux user mapping

2012-08-28 Thread Erinn Looney-Triggs
I am hoping I haven't missed something here, but it appears that the SELinux user mapping portion is not working for me. This is tested on a RHEL 6.3 client and server. The rule I have: Rule name: Developers staff_U SELinux User: staff_u:s0-s0:c0.c1023 Description: Confines developers on de