[Freeipa-users] /var/kerberos/krb5kdc/principal missing

2013-10-03 Thread Brian J. Murrell
I have a FreeIPA server set up on EL 6.4 with the following package versions: ipa-admintools-3.0.0-26.el6_4.4.x86_64 krb5-libs-1.10.3-10.el6_4.6.x86_64 ipa-server-selinux-3.0.0-26.el6_4.4.x86_64 ipa-client-3.0.0-26.el6_4.4.x86_64 ipa-pki-common-theme-9.0.3-7.el6.noarch krb5-server-1.10.3-10.el6_

Re: [Freeipa-users] /var/kerberos/krb5kdc/principal missing

2013-10-03 Thread Rob Crittenden
Brian J. Murrell wrote: I have a FreeIPA server set up on EL 6.4 with the following package versions: ipa-admintools-3.0.0-26.el6_4.4.x86_64 krb5-libs-1.10.3-10.el6_4.6.x86_64 ipa-server-selinux-3.0.0-26.el6_4.4.x86_64 ipa-client-3.0.0-26.el6_4.4.x86_64 ipa-pki-common-theme-9.0.3-7.el6.noarch kr

Re: [Freeipa-users] /var/kerberos/krb5kdc/principal missing

2013-10-03 Thread Brian J. Murrell
On 13-10-03 11:49 AM, Rob Crittenden wrote: Can clues on how it got to this point? Files changed, etc? Not really. This machine has been sitting mostly dormant in fact since I was last working on it a week or two ago. What does the dbmodules section of /etc/krb5.conf look like? And ther

Re: [Freeipa-users] /var/kerberos/krb5kdc/principal missing

2013-10-03 Thread Rob Crittenden
Brian J. Murrell wrote: On 13-10-03 11:49 AM, Rob Crittenden wrote: Can clues on how it got to this point? Files changed, etc? Not really. This machine has been sitting mostly dormant in fact since I was last working on it a week or two ago. What does the dbmodules section of /etc/krb5.con

Re: [Freeipa-users] /var/kerberos/krb5kdc/principal missing

2013-10-03 Thread Brian J. Murrell
Thanks much! That got things back up and running. Now to go fix the errant configuration management recipe. Cheers, b. ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] RFE - groups of services

2013-10-03 Thread Dmitri Pal
On 10/01/2013 04:08 AM, Lukás( Bezdic(ka wrote: > We came to situation when we need to add parameter memberOf to > services, but there is no configuration in 389 for this nor UI in > freeipa. Is it possible to implement groups for services? > > Example of usecase: > We have web service infront of w

Re: [Freeipa-users] Startup issue witrh dirsrv using slapi-nis

2013-10-03 Thread Dmitri Pal
On 09/27/2013 08:13 AM, Ade wrote: > Hi > > I have a dirsrv server using the slapi-nis plugin to provide 190+ nis > maps. It works well apart from one issue - boot up > > If I do a reboot, the dirsrv starts up ok, but slapi-nis doesnt seem > to register to rpc - logging in and restarting dirsrv fix

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-10-03 Thread Dmitri Pal
On 09/30/2013 10:59 PM, Mohan Cheema wrote: >> -Original Message- >> From: freeipa-users-boun...@redhat.com [mailto:freeipa-users- >> boun...@redhat.com] On Behalf Of Sumit Bose >> Sent: Monday, September 30, 2013 3:47 PM >> To: freeipa-users@redhat.com >> Subject: Re: [Freeipa-users] krb5k

Re: [Freeipa-users] Startup issue witrh dirsrv using slapi-nis

2013-10-03 Thread Nalin Dahyabhai
On Thu, Oct 03, 2013 at 05:02:44PM -0400, Dmitri Pal wrote: > On 09/27/2013 08:13 AM, Ade wrote: > > I have a dirsrv server using the slapi-nis plugin to provide 190+ nis > > maps. It works well apart from one issue - boot up > > > > If I do a reboot, the dirsrv starts up ok, but slapi-nis doesnt s

Re: [Freeipa-users] Automated Kickstart Enrollment

2013-10-03 Thread Dmitri Pal
On 09/28/2013 12:24 PM, Charlie Derwent wrote: > > On Tue, Sep 3, 2013 at 4:50 PM, Dmitri Pal > wrote: > > On 09/03/2013 04:21 AM, Innes, Duncan wrote: >> Hi folks, >> >> I've got a question about kickstart enrollment with a one-time >> password. Name

Re: [Freeipa-users] Fwd: FreeIPA on Fedora 19 won't work

2013-10-03 Thread Dmitri Pal
On 09/29/2013 06:48 AM, Glenn Jenkins wrote: > Alexander Bokovoy writes: > >> On Fri, 14 Jun 2013, Steve Dickson wrote: >>> The $subject says it all... Any ideas what is going on here? >> I did fresh install right now on a up to date F19 VM and experienced no >> problem whatsoever. >> >> There wer

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-10-03 Thread Mohan Cheema
Hi Dmitri, Yes its solved now. It didn't work with single user mapping I had map all users as per the HOWTO and it worked. Initially I was trying with just one user mapped to ipa user which didn't worked. Regards, Mohan > -Original Message- > From: freeipa-users-boun...@redhat.com [mai

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-10-03 Thread Dmitri Pal
On 10/03/2013 11:15 PM, Mohan Cheema wrote: > Hi Dmitri, > > Yes its solved now. It didn't work with single user mapping I had map all > users as per the HOWTO and it worked. Initially I was trying with just one > user mapped to ipa user which didn't worked. Anything would be worth adding to the H

[Freeipa-users] FreeIPA client setup in AWS

2013-10-03 Thread Mohan Cheema
Hi, We are number of Amazon AMI (Amazon Linux) in AWS. As this is based on RHEL we installed number of packages to enable user on those machine to get authenticated against ipa. The client gets configured with below warning. --- WARNING Installed OpenSSH serv

Re: [Freeipa-users] krb5kdc Additional pre-authentication required

2013-10-03 Thread Mohan Cheema
> -Original Message- > From: Dmitri Pal [mailto:d...@redhat.com] > Sent: Friday, October 04, 2013 4:38 AM > To: Mohan Cheema > Cc: freeipa-users@redhat.com > Subject: Re: [Freeipa-users] krb5kdc Additional pre-authentication > required > > On 10/03/2013 11:15 PM, Mohan Cheema wrote: > > Hi