[Freeipa-users] ipa-replica-manage re-initialize and database size

2015-04-24 Thread Dominik Korittki
Hello all, I am running two ipa3.3.3 instances in a replication on Centos 7 servers. Last day the rootpartition went full (where the dirsrv databases are stored), because of a big changelog-db. dirsrv managed to do a graceful shutdown. Luckily, the second master was still working properly, so i

Re: [Freeipa-users] ipa-replica-manage re-initialize and database size

2015-04-24 Thread Ludwig Krispenz
On 04/24/2015 09:26 AM, Dominik Korittki wrote: Hello all, I am running two ipa3.3.3 instances in a replication on Centos 7 servers. Last day the rootpartition went full (where the dirsrv databases are stored), because of a big changelog-db. dirsrv managed to do a graceful shutdown. Luckily, t

[Freeipa-users] Unable to Rebuid Replica

2015-04-24 Thread Sina Owolabi
Hi! I noticed that my IPA domain masters were out of sync, with users having to login with different passwords depending on the IPA client they were connected to. I noticed it was the replica that was the problem, and I took it down, uninstalled IPA with a "ipa-server-install --uninstall -U", dele

Re: [Freeipa-users] Unable to Rebuid Replica

2015-04-24 Thread dbischof
Sina, On Fri, 24 Apr 2015, Sina Owolabi wrote: I noticed that my IPA domain masters were out of sync, with users having to login with different passwords depending on the IPA client they were connected to. I noticed it was the replica that was the problem, and I took it down, uninstalled IPA

Re: [Freeipa-users] Unable to Rebuid Replica

2015-04-24 Thread Sina Owolabi
Thanks Daniel! Please what are the downsides of installing without --setup-ca? And how do I make certain both servers have the same number of modules? On Fri, Apr 24, 2015 at 10:44 AM, wrote: > Sina, > > On Fri, 24 Apr 2015, Sina Owolabi wrote: > >> I noticed that my IPA domain masters were out

Re: [Freeipa-users] Unable to Rebuid Replica

2015-04-24 Thread dbischof
Sina, On Fri, 24 Apr 2015, Sina Owolabi wrote: Please what are the downsides of installing without --setup-ca? I don't know exactly, sorry. If you install with "--setup-ca" an IPA replica and master only differ in two details: https://www.redhat.com/archives/freeipa-users/2014-July/msg0011

Re: [Freeipa-users] Unable to Rebuid Replica

2015-04-24 Thread Rob Crittenden
dbisc...@hrz.uni-kassel.de wrote: > Sina, > > On Fri, 24 Apr 2015, Sina Owolabi wrote: > >> I noticed that my IPA domain masters were out of sync, with users >> having to login with different passwords depending on the IPA client >> they were connected to. I noticed it was the replica that was th

[Freeipa-users] Ticket delegation

2015-04-24 Thread John Obaterspok
Hello, I'm on F21 and if I login to my workstation I can then sso using ssh to host X. But then I'm also able to sso from x -> y. If I'm on x and issue klist I see this: klist: No credentials cache found (ticket cache FILE:/tmp/krb5 Should I really be able to do this? --- john -- Manage your s

[Freeipa-users] FreeIPA 4 JSON API documentation

2015-04-24 Thread Wanderley Mayhé
Where can I find a clear documentation on JSON RPC API to Free IPA latest version (4.x.x)? http://www.freeipa.org/page/Documentation has nothing such as code samples for authenticating, adding or updating users in Linux. I think this cannot be the only documentation available in internet:

Re: [Freeipa-users] Ticket delegation

2015-04-24 Thread Rob Crittenden
John Obaterspok wrote: > Hello, > > I'm on F21 and if I login to my workstation I can then sso using ssh to > host X. But then I'm also able to sso from x -> y. > > If I'm on x and issue klist I see this: > klist: No credentials cache found (ticket cache FILE:/tmp/krb5 > > Should I really be abl

Re: [Freeipa-users] FreeIPA 4 JSON API documentation

2015-04-24 Thread Rob Crittenden
Wanderley Mayhé wrote: > Where can I find a clear documentation on JSON RPC API to Free IPA > latest version (4.x.x)? > > > > http://www.freeipa.org/page/Documentation has nothing such as code > samples for authenticating, adding or updating users in Linux. > > > > I think this cannot be t

[Freeipa-users] Web UI: Migrated Admins missing action buttons

2015-04-24 Thread Christopher Lamb
Hi I am in the process of setting up and configuring a FreeIPA Server 4.1.0. I have successfully migrated all the users from an existing FreeIPA Server 3.0.0 with the following command: ipa migrate-ds --group-overwrite-gid --user-container='cn=users,cn=accounts' --group-container='cn=groups,cn=

[Freeipa-users] IPA Web UI behind proxy

2015-04-24 Thread Benjamen Keroack
Hi, Does anybody have any experience putting the IPA web UI behind a reverse proxy? In an attempt to allow our users to access the UI without browser warnings and without having to add the root CA certificate to their trusted store (there was some resistance to that idea), I set up an nginx server

Re: [Freeipa-users] Ticket delegation

2015-04-24 Thread John Obaterspok
2015-04-24 17:47 GMT+02:00 Rob Crittenden : > John Obaterspok wrote: > > Hello, > > > > I'm on F21 and if I login to my workstation I can then sso using ssh to > > host X. But then I'm also able to sso from x -> y. > > > > If I'm on x and issue klist I see this: > > klist: No credentials cache fou

Re: [Freeipa-users] Web UI: Migrated Admins missing action buttons

2015-04-24 Thread Dmitri Pal
On 04/24/2015 12:58 PM, Christopher Lamb wrote: Hi I am in the process of setting up and configuring a FreeIPA Server 4.1.0. I have successfully migrated all the users from an existing FreeIPA Server 3.0.0 with the following command: ipa migrate-ds --group-overwrite-gid --user-container='cn=us

Re: [Freeipa-users] Web UI: Migrated Admins missing action buttons

2015-04-24 Thread Rob Crittenden
Dmitri Pal wrote: > On 04/24/2015 12:58 PM, Christopher Lamb wrote: >> Hi >> >> I am in the process of setting up and configuring a FreeIPA Server 4.1.0. >> >> I have successfully migrated all the users from an existing FreeIPA >> Server >> 3.0.0 with the following command: >> >> ipa migrate-ds --g

[Freeipa-users] problem with reinstall ipa client

2015-04-24 Thread alireza baghery
hi i REMOVE server ipa-server (3.0.0 centos 6.5) with HOSTNAME (ipasrv.linux) and REINSTALL server ipa with same hostname and OS (centos 6.5) server IPA integrate with AD windows (2008) and on Clients first Uninstall IPa-Client with Command ipa-client-install --uninstall but when i want INSTALL ip