Re: [Freeipa-users] Freeipa-users Digest, Vol 54, Issue 42

2013-01-22 Thread Vijay Thakur
On Monday 21 January 2013 10:30 PM, freeipa-users-requ...@redhat.com wrote: Send Freeipa-users mailing list submissions to freeipa-users@redhat.com To subscribe or unsubscribe via the World Wide Web, visit https://www.redhat.com/mailman/listinfo/freeipa-users or, via email, send

Re: [Freeipa-users] Error: Fedora 18 client to IPA Server 2.2.0?

2013-01-22 Thread Rob Crittenden
free...@noboost.org wrote: Hi, Has anyone had success with installing the IPA client on Fedora 18 (with SeLinux disabled)? Server: Red Hat Enterprise Linux Server release 6.3 (Santiago) * ipa-server-2.2.0-16.el6.x86_64 Client: Fedora release 18 (Spherical Cow) *

Re: [Freeipa-users] Freeipa-users Digest, Vol 54, Issue 42

2013-01-22 Thread Rob Crittenden
Vijay Thakur wrote: On Monday 21 January 2013 10:30 PM, freeipa-users-requ...@redhat.com wrote: Vijay Thakur Here is the logs of server side: an 22 16:21:02 ds.example.com krb5kdc[1376](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.51.16: NEEDED_PREAUTH: ad...@example.com for

Re: [Freeipa-users] Error: Fedora 18 client to IPA Server 2.2.0?

2013-01-22 Thread Jakub Hrozek
On Tue, Jan 22, 2013 at 11:02:39AM -0500, Rob Crittenden wrote: free...@noboost.org wrote: Hi, Has anyone had success with installing the IPA client on Fedora 18 (with SeLinux disabled)? Server: Red Hat Enterprise Linux Server release 6.3 (Santiago) * ipa-server-2.2.0-16.el6.x86_64

Re: [Freeipa-users] FreeIPA Client Setup in Windows 7 Ubuntu

2013-01-22 Thread Petr Spacek
On 22.1.2013 17:04, Rob Crittenden wrote: Vijay Thakur wrote: On Monday 21 January 2013 10:30 PM, freeipa-users-requ...@redhat.com wrote: Vijay Thakur Here is the logs of server side: an 22 16:21:02 ds.example.com krb5kdc[1376](info): AS_REQ (4 etypes {18 17 16 23}) 192.168.51.16:

[Freeipa-users] OneWaySync Issues

2013-01-22 Thread Joseph, Matthew (EXP)
Hello, I'm trying to configure the oneWaySync option for IPA so only the Windows AD can replicate changes to IPA. When I use the command that I listed below it says it works but when I delete a user form IPA it will then delete the user in Active Directory. Is my command listed below correct?

Re: [Freeipa-users] OneWaySync Issues

2013-01-22 Thread Rob Crittenden
Joseph, Matthew (EXP) wrote: Hello, I’m trying to configure the oneWaySync option for IPA so only the Windows AD can replicate changes to IPA. When I use the command that I listed below it says it works but when I delete a user form IPA it will then delete the user in Active Directory. Is my

Re: [Freeipa-users] OneWaySync Issues

2013-01-22 Thread Rich Megginson
On 01/22/2013 11:46 AM, Rob Crittenden wrote: Joseph, Matthew (EXP) wrote: Hello, I’m trying to configure the oneWaySync option for IPA so only the Windows AD can replicate changes to IPA. When I use the command that I listed below it says it works but when I delete a user form IPA it will

Re: [Freeipa-users] EXTERNAL: Re: OneWaySync Issues

2013-01-22 Thread Joseph, Matthew (EXP)
Hey Rob, According to the Red Hat Identity Management documentation provided by Red hat it says to do it with the ldapmodify command. They don't mention any options during the replicator/sync agreement process about uni-directional sync. Matt -Original Message- From: Rich Megginson

Re: [Freeipa-users] EXTERNAL: Re: OneWaySync Issues

2013-01-22 Thread Joseph, Matthew (EXP)
Hello Rob, Sorry typo on my part. The command I put in is actually fromWindows Matt -Original Message- From: Rob Crittenden [mailto:rcrit...@redhat.com] Sent: Tuesday, January 22, 2013 2:47 PM To: Joseph, Matthew (EXP) Cc: freeipa-users@redhat.com Subject: EXTERNAL: Re: [Freeipa-users]

Re: [Freeipa-users] Fedora 18 - FreeIPA + AD

2013-01-22 Thread MaSch
On 1/21/13 9:44 AM, Sumit Bose wrote: This is not related to AD because it is still the step before establishing the trust as Marco said below. The message Outdated Kerberos credentials. Use kdestroy and kinit to update your ticket indicate that we failed to connect to the local LDAP server.

[Freeipa-users] Starting from scratch migrating users?

2013-01-22 Thread Matthew Barr
We've got a freeipa system installed, but it's experiencing some bugs. I suspect some of it came from adding removing a replica, as well as upgrading from prior versions. (we're on centos 6.3 now) We're about to do a datacenter rebuild move, and I'd like to start from scratch, yet still

[Freeipa-users] Some interrogations about the freeipa deployment

2013-01-22 Thread Bob Sauvage
Hi *, I plan to review the network architecture of my office. 10 Windows/Linux desktops and 2 Linux servers will be deployed on the network. I want to install freeipa on the first server to act like an AD DS. I want to authenticate users on the server and controlling what can be done or not

Re: [Freeipa-users] Some interrogations about the freeipa deployment

2013-01-22 Thread Steven Jones
Hi, I have all done this, so from what you write I think IPA would be a good fit for what you want, except that is the single sign on bit I have not looked to see if that can be done. For http restart you control that via sudo in IPA so its centrally managed, I have this working for one such

Re: [Freeipa-users] Some interrogations about the freeipa deployment

2013-01-22 Thread Dale Macartney
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/22/2013 09:51 PM, Steven Jones wrote: Hi, I have all done this, so from what you write I think IPA would be a good fit for what you want, except that is the single sign on bit I have not looked to see if that can be done. For http restart

Re: [Freeipa-users] Starting from scratch migrating users?

2013-01-22 Thread Dmitri Pal
On 01/22/2013 03:39 PM, Matthew Barr wrote: We've got a freeipa system installed, but it's experiencing some bugs. I suspect some of it came from adding removing a replica, as well as upgrading from prior versions. (we're on centos 6.3 now) We're about to do a datacenter rebuild move, and

Re: [Freeipa-users] Starting from scratch migrating users?

2013-01-22 Thread Matthew Barr
On Jan 22, 2013, at 5:15 PM, Dmitri Pal d...@redhat.com wrote: Which exactly LDAP method? ldif dump and load? This would not work well unless you also manage to move certs and kerberos master key over which is really hard. I was assuming the ipa migrate-ds. Thoughts? I don't

Re: [Freeipa-users] Starting from scratch migrating users?

2013-01-22 Thread Dmitri Pal
On 01/22/2013 06:28 PM, Matthew Barr wrote: On Jan 22, 2013, at 5:15 PM, Dmitri Pal d...@redhat.com wrote: Which exactly LDAP method? ldif dump and load? This would not work well unless you also manage to move certs and kerberos master key over which is really hard. I was assuming the ipa

Re: [Freeipa-users] Managing jboss through sudo

2013-01-22 Thread David Sastre Medina
On Wed, Jan 16, 2013 at 08:18:12PM -0500, Dmitri Pal wrote: On 01/16/2013 07:30 PM, William Muriithi wrote: Hello I am trying to set up dev systems and want to only allow developers to modify the jboss directory tree, shutdown and restarting jboss. This is mainly so that they dev

Re: [Freeipa-users] FreeIPA Client Setup in Windows 7 Ubuntu

2013-01-22 Thread David Sastre Medina
On Mon, Jan 21, 2013 at 07:37:39AM -0500, Dmitri Pal wrote: On 01/21/2013 04:45 AM, Vijay Thakur wrote: Guide me about Ubuntu 12.04 as FreeIPA Client setting. I know there have been work done for Ubuntu but we unfortunately I do not have information on the state of this work. Regarding

Re: [Freeipa-users] FreeIPA Client Setup in Windows 7 Ubuntu

2013-01-22 Thread 小龙 陈
Date: Wed, 23 Jan 2013 08:28:57 +0100 From: d.sastre.med...@gmail.com To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] FreeIPA Client Setup in Windows 7 Ubuntu On Mon, Jan 21, 2013 at 07:37:39AM -0500, Dmitri Pal wrote: On 01/21/2013 04:45 AM,