Re: [Freeipa-users] Do we need ipa-client-update script?

2012-09-24 Thread Martin Kosek
On 09/22/2012 01:22 AM, Sigbjorn Lie wrote: On 09/21/2012 10:45 AM, Petr Spacek wrote: Hello users, we have a question for client machine administrators: On 09/21/2012 10:12 AM, Martin Kosek wrote: snip ..., that it may be useful to implement a script like ipa-client-update which would

Re: [Freeipa-users] sudden ipa errors.

2012-09-24 Thread Martin Kosek
Hello Nathan, you can file the bug on Red Hat Bugzilla (bugzilla.redhat.com), you can use this link: https://bugzilla.redhat.com/enter_bug.cgi?product=Red%20Hat%20Enterprise%20Linux%206 Thanks in advance! Martin On 09/21/2012 05:53 PM, Nathan Lager wrote: Sure thing, can you point me to where

Re: [Freeipa-users] NSMMReplicationPlugin - changelog program - cl5DBData2Entry: invalid data version

2012-09-24 Thread Ikaro Silva
Hi Rich, Thanks for the help. We have tried your suggestion below, however the problem still persists: systemctl status dirsrv.service dirsrv.service Loaded: error (Reason: No such file or directory) Active: inactive (dead) [root@fileserver2 ~]# ipactl status Directory

Re: [Freeipa-users] errors when one ipa server down

2012-09-24 Thread Jakub Hrozek
On Wed, Sep 19, 2012 at 12:27:25PM -0400, Dmitri Pal wrote: On 09/19/2012 12:11 PM, Jakub Hrozek wrote: On Wed, Sep 19, 2012 at 12:00:08PM -0400, Michael Mercier wrote: On 2012-09-18, at 4:03 PM, Jakub Hrozek wrote: On Tue, Sep 18, 2012 at 02:38:13PM -0400, Michael Mercier wrote: On

Re: [Freeipa-users] NSMMReplicationPlugin - changelog program - cl5DBData2Entry: invalid data version

2012-09-24 Thread Alexander Bokovoy
On Mon, 24 Sep 2012, Ikaro Silva wrote: Hi Rich, Thanks for the help. We have tried your suggestion below, however the problem still persists: systemctl status dirsrv.service There is no dirsrv.service. dirsrv instances are arranged in following setup: - there is dirsrv.target that is used

[Freeipa-users] Migration from OpenLDAP to IPA: reset expired password in IPA UI

2012-09-24 Thread Qing Chang
Using https://IPA/ipa/migration, users can migrate their password to their Kerberos principals successfully, a subsequent login to /ui gives them interface to change attrs to their account. But if their LDAP password is shorter than the default policy of 8 letter (IPA migrate the password but

Re: [Freeipa-users] Migration from OpenLDAP to IPA: reset expired password in IPA UI

2012-09-24 Thread Dmitri Pal
On 09/24/2012 02:51 PM, Qing Chang wrote: Using https://IPA/ipa/migration, users can migrate their password to their Kerberos principals successfully, a subsequent login to /ui gives them interface to change attrs to their account. But if their LDAP password is shorter than the default

[Freeipa-users] Easy deployment

2012-09-24 Thread James James
Hi guys, we are planning to install 150 freeipa clients and I was wondering if there is a way to easily install (from kickstart) nfsv4 client. I can add host with # ipa host-add --password=secret But to get the keytab (host and service), I have to log into the machine, launch kinit and get the

Re: [Freeipa-users] Easy deployment

2012-09-24 Thread Steven Jones
Hi, I did a while back ask if this could be automated in some way into RH satellite. So future roadmap thing. regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: freeipa-users-boun...@redhat.com

Re: [Freeipa-users] Easy deployment

2012-09-24 Thread James James
Ok Thanks .. 2012/9/25 Steven Jones steven.jo...@vuw.ac.nz Hi, I did a while back ask if this could be automated in some way into RH satellite. So future roadmap thing. regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272

Re: [Freeipa-users] Easy deployment

2012-09-24 Thread Dmitri Pal
On 09/24/2012 06:17 PM, James James wrote: Hi guys, we are planning to install 150 freeipa clients and I was wondering if there is a way to easily install (from kickstart) nfsv4 client. I can add host with # ipa host-add --password=secret This was exactly intended for the bulk

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-24 Thread Steven Jones
Hi, I am trying to run this and getting search exceeded. ldapsearch -xLLL -D winsync_binddn -w passwd -h AD_host -s sub -b OU=VUW_Staff,DC=staff,DC=vuw,DC=ac,DC=nz cn=* dn ad.dns.txt Looks like I have 5900 AD users buy only 4300 are transferred to IPA...they also lose their IPA groups which

Re: [Freeipa-users] Easy deployment

2012-09-24 Thread Steven Jones
Hi, So maybe I should or would you like me to raise this as a feature request for Satellite? regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 From: freeipa-users-boun...@redhat.com

Re: [Freeipa-users] winsync agreement wipes IPA users

2012-09-24 Thread Steven Jones
Hi, Im confused here, has no one tried to winsync 2000+ users before? Are there any docs on working around this limit? Ive up'd the user to 2 but that seems to have had no effectmy AD ppl dont know of any other way to increase that at present. regards Steven Jones Technical