Re: [Freeipa-users] [Freeipa-interest] Announcing FreeIPA 3.3.0

2013-08-12 Thread Ellen Newlands
Congrats team, this is a very nice list of new features. On Aug 8, 2013, at 10:03 AM, Martin Kosek mko...@redhat.com wrote: The FreeIPA team is proud to announce FreeIPA v3.3.0! It can be downloaded from http://www.freeipa.org/page/Downloads. Fedora 19 builds are already on their way to

Re: [Freeipa-users] tough one on DNS

2013-08-12 Thread Petr Spacek
Hello, I wonder if your problems with SSL are really caused by problems with reverse name resolution ... I think that SSL libraries usually don't care about PTR records. Which SSL libraries do you use? Do you use server's IP address in certificate subject field? Regarding the DNS: First of

[Freeipa-users] Blocking 389 and 636 for AD trusts

2013-08-12 Thread Brian Lee
Hello everyone, I understand this is well documented that we need to block AD from establishing communication to the LDAP ports, but I've never heard an explanation on why this is needed. Additionally, In our environment, we have a 100+ AD servers. Do I need to add an iptables rule for each AD

Re: [Freeipa-users] Can't update ssh keys

2013-08-12 Thread Bret Wortman
I can get the host keys in okay, it's the user keys that are giving me fits. No combination of fields seems to work. Before we troubleshoot very far, I will update to a newer release and try again. Every now and again, I just need the right motivation to upgrade. * * *Bret Wortman*

[Freeipa-users] Freeipa Active Directory Sync problems

2013-08-12 Thread luis lugo
Hi, I have the following error when I try to sync Freeipa 3.2.2 with Active Directory. reports: Update failed! Status: [-1 Total update abortedLDAP error: Can't contact LDAP server] Failed to start replication All current users sync with freeipa, but new users cannot. I have differents OU and

Re: [Freeipa-users] Freeipa Active Directory Sync problems

2013-08-12 Thread Rich Megginson
On 08/12/2013 11:37 AM, luis lugo wrote: Hi, I have the following error when I try to sync Freeipa 3.2.2 with Active Directory. reports: Update failed! Status: [-1 Total update abortedLDAP error: Can't contact LDAP server] Failed to start replication All current users sync with