Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Sigbjorn Lie
On 02/15/2013 03:17 PM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great, but I already have other data in the ipa ldap

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Sigbjorn Lie
On 02/15/2013 10:31 PM, Dmitri Pal wrote: On 02/15/2013 09:17 AM, Rodney L. Mercer wrote: On Thu, 2013-02-14 at 21:44 +0100, Sigbjorn Lie wrote: I agree with schema support being enough for now. I do not expect the ipa mgmt tools to support Solaris rbac mgmt. The ipa mgmt tools are great, but

Re: [Freeipa-users] Unable to enrol servers with principal

2013-02-16 Thread Charlie Derwent
On Fri, Feb 15, 2013 at 6:56 PM, Rob Crittenden wrote: > Charlie Derwent wrote: > >> Hi >> So there's nothing I can see in the access logs. >> However, I get the following message in the KDC log >> Feb 15 14:05:49 ipa.example.com >> >> krb5kdc[1749](info): AS_REQ (12 ety

Re: [Freeipa-users] Non-human users

2013-02-16 Thread Charlie Derwent
Bit late to the conversation here, but if you want another example of a quasi-system account within IPA, there is the need for a user to handle automated enrollment/re-enrollment of servers. Charlie On Fri, Feb 15, 2013 at 11:32 PM, Brian Cook wrote: > > On Feb 15, 2013, at 3:11 PM, Simo Sorce

Re: [Freeipa-users] RHEL6 IPA and Active Directory synchronisation and Solaris RBAC

2013-02-16 Thread Mercer, Rodney
From: freeipa-users-boun...@redhat.com [freeipa-users-boun...@redhat.com] on behalf of Sigbjorn Lie [sigbj...@nixtra.com] Sent: Saturday, February 16, 2013 6:29 AM To: freeipa-users@redhat.com Subject: Re: [Freeipa-users] RHEL6 IPA and Active Directory syn