Re: [Freeipa-users] ipa-dns-install on a remote host?

2013-07-08 Thread Petr Spacek
On 5.7.2013 17:59, Schmitt, Christian wrote: Yeah i know that feature, but when i have a View i need to declare two zonefiles (i need to create one by hand and the other will getting created by the ipa-dns) thats not exactly what i'm looking for since some sites shall be the same on both sites,

[Freeipa-users] Virtual Machines??

2013-07-08 Thread Schmitt, Christian
Hello, is there currently a good way to install FreeIPA or IdM in virtual machines? Currently we having some Windows Hyper-V Hypervisors since we are planning to buy some Dell Hardware that can't run Linux yet, the Dell VRTX. Also we want to reuse our Windows Server Datacenter Licenses. Is there a

Re: [Freeipa-users] Replicate on Servers with diffrent Version (Minor)

2013-07-08 Thread Rob Crittenden
Stephen Ingram wrote: On Sun, Jul 7, 2013 at 2:11 PM, Schmitt, Christian c.schm...@briefdomain.de mailto:c.schm...@briefdomain.de wrote: Hello is it possible to replicate FreeIPA Server with diffrent Minor versions? Currently we are running a FreeIPA Server on Fedora 19 since

Re: [Freeipa-users] Virtual Machines??

2013-07-08 Thread Jakub Hrozek
On Mon, Jul 08, 2013 at 03:49:03PM +0200, Schmitt, Christian wrote: Hello, is there currently a good way to install FreeIPA or IdM in virtual machines? Currently we having some Windows Hyper-V Hypervisors since we are planning to buy some Dell Hardware that can't run Linux yet, the Dell VRTX.

[Freeipa-users] Glaring hole in AIX telnet regarding HBAC rules

2013-07-08 Thread KodaK
We've just discovered that AIX does not honor HBAC rules with telnet. ssh is fine. [jebalicki@mo0033802 ~]$ ipa hbactest --user=testuser --host= sla765q1.unix.magellanhealth.com --service=sshd - Access granted: False - There was no telnet service by

Re: [Freeipa-users] Glaring hole in AIX telnet regarding HBAC rules

2013-07-08 Thread Rob Crittenden
KodaK wrote: We've just discovered that AIX does not honor HBAC rules with telnet. ssh is fine. [jebalicki@mo0033802 ~]$ ipa hbactest --user=testuser --host=sla765q1.unix.magellanhealth.com http://sla765q1.unix.magellanhealth.com --service=sshd - Access granted: False

[Freeipa-users] What happened to my {cacert,kdc}.pem files?

2013-07-08 Thread Brian Vetter
We had to shut down our FREEIPA server and move it. When I brought it back up again today (all same IPs, network, etc), it failed to come up. I see lots of various forms of the following messages when trying to start the ipa, named, and other services: Failed to init credentials (Cannot