Re: [Freeipa-users] Exporting data?

2013-09-05 Thread Bret Wortman
D'Oh! Thanks, Petr. * * *Bret Wortman* http://damascusgrp.com/ http://about.me/wortmanbret On Thu, Sep 5, 2013 at 2:33 AM, Petr Spacek wrote: > On 4.9.2013 20:23, Bret Wortman wrote: > >> ...and I tried exporting the DNS data but ended up with a bunch of files >> that looked liket his: >> >>

[Freeipa-users] slapi-nis user password error

2013-09-05 Thread cbul...@gmail.com
Hi, I have some services that need to work with a NIS server and I would like to use slapi-nis plugin in order to use just FreeIPA as our Directory Server. The users were imported from a openldap server and the password encryption is MD5. I installed slapi-nis in the server and configure a NIS cli

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread Alexander Bokovoy
On Thu, 05 Sep 2013, cbul...@gmail.com wrote: Hi, I have some services that need to work with a NIS server and I would like to use slapi-nis plugin in order to use just FreeIPA as our Directory Server. The users were imported from a openldap server and the password encryption is MD5. I installed

Re: [Freeipa-users] Exporting data?

2013-09-05 Thread Petr Spacek
On 5.9.2013 16:49, Bret Wortman wrote: That worked for one out of 24 zones. Dig gave the same error on the rest: # dig +onesoa -t AXFR foo.net ; <<>> DiG 99.3-rl.156.01-P1-RedHat-9.9.3-3.P1.fc18 <<>> +onesoa -t AXFR foo.net ;; global options: +cmd ; Transfer failed. # /var/log/messages errors

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread Alexander Bokovoy
On Thu, 05 Sep 2013, cbul...@gmail.com wrote: Hi Alexander, Thanks so much for you reply. Do you know if there is a patch available for RH 6.3 that I can use?... There is no backport available. Look at the Dmitri's answer as well. You can authenticate these boxes through pam_krb5 in combinatio

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread Dmitri Pal
On 09/05/2013 10:47 AM, Alexander Bokovoy wrote: > On Thu, 05 Sep 2013, cbul...@gmail.com wrote: >> Hi, >> >> I have some services that need to work with a NIS server and I would >> like to use slapi-nis plugin in order to use just FreeIPA as our >> Directory Server. >> The users were imported from

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread cbul...@gmail.com
Hi Alexander, Thanks so much for you reply. Do you know if there is a patch available for RH 6.3 that I can use?... Thanks again, On 09/05/2013 09:47 AM, Alexander Bokovoy wrote: > On Thu, 05 Sep 2013, cbul...@gmail.com wrote: >> Hi, >> >> I have some services that need to work with a NIS ser

Re: [Freeipa-users] Ldap schema

2013-09-05 Thread John Dennis
On 09/05/2013 02:29 AM, Dmitri Pal wrote: > On 09/05/2013 12:38 AM, Jason Prouty wrote: >> This is the AV-Pair I would like to implement to pass back to radius. >> >> >> dn: cn=priv-15,ou=cisco,ou=radius,dc=example,dc=com >> objectClass: radiusObjectProfile >> objectClass: radiusprofile >> cn: priv

Re: [Freeipa-users] Exporting data?

2013-09-05 Thread Bret Wortman
That worked for one out of 24 zones. Dig gave the same error on the rest: # dig +onesoa -t AXFR foo.net ; <<>> DiG 99.3-rl.156.01-P1-RedHat-9.9.3-3.P1.fc18 <<>> +onesoa -t AXFR foo.net ;; global options: +cmd ; Transfer failed. # /var/log/messages errors at the same time with: named[925]: LDAP

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread Nalin Dahyabhai
On Thu, Sep 05, 2013 at 09:17:36AM -0500, cbul...@gmail.com wrote: > The users were imported from a openldap server and the password > encryption is MD5. Is that {CRYPT} using an md5-based crypt, or {MD5} or {SMD5}? A client that's trying to check passwords using hashes which it reads via NIS is

Re: [Freeipa-users] slapi-nis user password error

2013-09-05 Thread cbul...@gmail.com
Nalin, Alexander and Dmitri, Thanks so much for help and clarified me some points. Yes, we are using {CRYPT} and after configure Kerberos for authentication we are able to log in. Again, thank so much! On 09/05/2013 10:11 AM, Nalin Dahyabhai wrote: > On Thu, Sep 05, 2013 at 09:17:36AM -0500, cb