[Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Исаев Виталий Анатольевич
Dear Freeipa users and developers, We need to alter the default behavior of the IdM server in the situation when user exceeds the limit of incorrect password login attempts. By default the user is getting locked in this case, but we need to disable him fully. How can we manage this situation?

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Natxo Asenjo
On Wed, Dec 4, 2013 at 10:59 AM, Исаев Виталий Анатольевич is...@fintech.ru wrote: Dear Freeipa users and developers, We need to alter the default behavior of the IdM server in the situation when user exceeds the limit of incorrect password login attempts. By default the user is getting

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Natxo Asenjo
On Wed, Dec 4, 2013 at 11:44 AM, Natxo Asenjo natxo.ase...@gmail.com wrote: On Wed, Dec 4, 2013 at 10:59 AM, Исаев Виталий Анатольевич is...@fintech.ru wrote: Dear Freeipa users and developers, We need to alter the default behavior of the IdM server in the situation when user exceeds the

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Martin Kosek
On 12/04/2013 11:53 AM, Natxo Asenjo wrote: On Wed, Dec 4, 2013 at 11:44 AM, Natxo Asenjo natxo.ase...@gmail.com wrote: On Wed, Dec 4, 2013 at 10:59 AM, Исаев Виталий Анатольевич is...@fintech.ru wrote: Dear Freeipa users and developers, We need to alter the default behavior of the IdM

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Natxo Asenjo
On Wed, Dec 4, 2013 at 12:05 PM, Martin Kosek mko...@redhat.com wrote: On 12/04/2013 11:53 AM, Natxo Asenjo wrote: On Wed, Dec 4, 2013 at 11:44 AM, Natxo Asenjo natxo.ase...@gmail.com wrote: On Wed, Dec 4, 2013 at 10:59 AM, Исаев Виталий Анатольевич is...@fintech.ru wrote: To change a value:

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Martin Kosek
On 12/04/2013 12:10 PM, Natxo Asenjo wrote: On Wed, Dec 4, 2013 at 12:05 PM, Martin Kosek mko...@redhat.com wrote: On 12/04/2013 11:53 AM, Natxo Asenjo wrote: On Wed, Dec 4, 2013 at 11:44 AM, Natxo Asenjo natxo.ase...@gmail.com wrote: On Wed, Dec 4, 2013 at 10:59 AM, Исаев Виталий

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Исаев Виталий Анатольевич
Thank you for your responses! In terms of IdM lock state and disable state are different: when user becomes locked after several failed login attempts, he is still enabled. The locked state is not shown neither in ipa user-show or ipa user-find --all commands output, nor in Web GUI... Locked

Re: [Freeipa-users] CA expiration and renewal

2013-12-04 Thread Rob Crittenden
Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/27/2013 11:11 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/25/2013 11:09 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: Folks just wanted to

Re: [Freeipa-users] How to disable user automatically when he becomes locked

2013-12-04 Thread Martin Kosek
On 12/04/2013 12:43 PM, Исаев Виталий Анатольевич wrote: Thank you for your responses! In terms of IdM lock state and disable state are different: when user becomes locked after several failed login attempts, he is still enabled. The locked state is not shown neither in ipa user-show or

[Freeipa-users] Install FreeIPA on CentOS 6.4

2013-12-04 Thread Dimitar Georgievski
hi, I plan to install FreeIPA on CentOS 6.4. Initially FreeIPA should provide secure authentication and authorization for system (shell) accounts (users and groups) by integration with SSSD. There is already a DNS server and FreeIPA should integrate with it. I am looking for some guidelines for

Re: [Freeipa-users] Install FreeIPA on CentOS 6.4

2013-12-04 Thread Christian Horn
Hi, On Wed, Dec 04, 2013 at 10:52:58AM -0500, Dimitar Georgievski wrote: I plan to install FreeIPA on CentOS 6.4. Initially FreeIPA should provide secure authentication and authorization for system (shell) accounts (users and groups) by integration with SSSD. There is already a DNS server

Re: [Freeipa-users] Install FreeIPA on CentOS 6.4

2013-12-04 Thread Dmitri Pal
On 12/04/2013 10:52 AM, Dimitar Georgievski wrote: hi, I plan to install FreeIPA on CentOS 6.4. Initially FreeIPA should provide secure authentication and authorization for system (shell) accounts (users and groups) by integration with SSSD. There is already a DNS server and FreeIPA should

Re: [Freeipa-users] CA expiration and renewal

2013-12-04 Thread Erinn Looney-Triggs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 12/04/2013 07:15 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 11/27/2013 11:11 AM, Rob Crittenden wrote: Erinn Looney-Triggs wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1