Re: [Freeipa-users] ipa-client-install remove the passwordless connection with root

2015-06-03 Thread Martin Kosek
On 06/02/2015 06:27 PM, bahan w wrote: > Hello ! > > I send you this mail because I have a problem linked with SSH and FreeIPA. > > I have multiple servers : > - One with FreeIPA server 3.0.0-26 > - The others with FreeIPA client 3.0.0-26 > > They are running on RHEL 6.4. > > I configured a roo

Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA client on EL7.1 -->Not Solved

2015-06-03 Thread Martin Kosek
On 06/02/2015 06:15 PM, Christopher Lamb wrote: > > Hi > > Earlier today I setup 2 throwaway EL7.1 VMs to help narrow down the cause > of this problem. Let's call them HOST09 and HOST10 > > Both are mimimum installs of EL7.1, with NTPD installed and configured. > > HOST09 had ipa-client 4.1 in

Re: [Freeipa-users] IPA Error 4301: Certificate operation cannot be completed: Unable to communicate with CMS (Not Found)

2015-06-03 Thread Martin Kosek
On 06/02/2015 10:10 PM, Chris Tobey wrote: > Hi everyone, > > > > This is my first time posting here - please be gentle. Ok :-) > I currently have ~40 CentOS 6.6 servers authenticating against my FreeIPA > server running on another CentOS 6.6 server. > (ipa-server-3.0.0-42.el6.centos.x86_64 a

Re: [Freeipa-users] How to handle users with multiple homedirs on different machines?

2015-06-03 Thread Alexander Bokovoy
On Tue, 02 Jun 2015, swartz wrote: I have a environment that spans across multiple physical locations where there is a mix of Linux and Solaris workstations/servers. So far we've been managing accounts (/etc/password) via Puppet. Problem: FreeIPA allows to store only one homedir path. Q: Is ther

Re: [Freeipa-users] How to handle users with multiple homedirs on different machines?

2015-06-03 Thread Sumit Bose
On Wed, Jun 03, 2015 at 08:29:20AM +0200, Lukas Slebodnik wrote: > On (02/06/15 17:07), swartz wrote: > >I have a environment that spans across multiple physical locations where > >there is a mix of Linux and Solaris workstations/servers. So far we've been > >managing accounts (/etc/password) via P

Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA client on EL7.1 -->Not Solved

2015-06-03 Thread Jakub Hrozek
On Wed, Jun 03, 2015 at 09:34:28AM +0200, Martin Kosek wrote: > On 06/02/2015 06:15 PM, Christopher Lamb wrote: > > > > Hi > > > > Earlier today I setup 2 throwaway EL7.1 VMs to help narrow down the cause > > of this problem. Let's call them HOST09 and HOST10 > > > > Both are mimimum installs of

Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA client on EL7.1 -->Not Solved

2015-06-03 Thread Christopher Lamb
Hi all This is a quick(ish) note to bring everybody up to speed on this issue. Yesterday we had some private mail exchange on this issue as I did not wish to broadcast the krb5 and ipa install logs to the user list. The basic situation is that we are in the process of migrating from an FreeIPA 3.

Re: [Freeipa-users] Fw: ssh problem with migrated FreeIPA client on EL7.1 -->Not Solved

2015-06-03 Thread Martin Kosek
On 06/03/2015 10:30 AM, Christopher Lamb wrote: > Hi all > > This is a quick(ish) note to bring everybody up to speed on this issue. > Yesterday we had some private mail exchange on this issue as I did not wish > to broadcast the krb5 and ipa install logs to the user list. > > The basic situation

Re: [Freeipa-users] ipa-client-install remove the passwordless connection with root

2015-06-03 Thread Martin Kosek
Thanks for update. Adding mailing list back, to be aware of the results. Given this description, I wonder if this is hitting https://bugzilla.redhat.com/show_bug.cgi?id=1201454 that is planned to be fixed in next RHEL-6 minor version. On 06/03/2015 10:46 AM, bahan w wrote: > Hello again. > > The

Re: [Freeipa-users] How to handle users with multiple homedirs on different machines?

2015-06-03 Thread Coy Hile
For solaris, just use the standard automounter config in auto_home: *  /export/home/& Sent via the Samsung GALAXY S® 5, an AT&T 4G LTE smartphone Original message From: Lukas Slebodnik Date: 06/03/2015 02:29 (GMT-05:00) To: netv...@gmail.com Cc: freeipa-users@redhat.com S

Re: [Freeipa-users] IPA Error 4301: Certificate operation cannot be completed: Unable to communicate with CMS (Not Found)

2015-06-03 Thread Chris Tobey
Hi Martin, Thank you for the response. Here is what I can see on my FreeIPA server (I replaced my server name with server.com): [Wed Jun 03 10:05:36:..//var/lib/pki-ca]$ ipa cert-show 1 ipa: ERROR: Certificate operation cannot be completed: Unable to communicate with CMS (Not Found) [Wed Jun 03 1

Re: [Freeipa-users] How to handle users with multiple homedirs on different machines?

2015-06-03 Thread Lukas Slebodnik
On (03/06/15 12:54), Coy Hile wrote: > > >For solaris, just use the standard automounter config in auto_home: >*  /export/home/& I thought that automount and "getent passwd user" are two different thigs on Solaris (the same as on Linux) LS -- Manage your subscription for the Freeipa-users mailin

Re: [Freeipa-users] How to handle users with multiple homedirs on different machines?

2015-06-03 Thread Coy Hile
They are, but a correct automounter config will allow you to keep the attribute as /home/jdoe notwithstanding the OS. Sent via the Samsung GALAXY S® 5, an AT&T 4G LTE smartphone Original message From: Lukas Slebodnik Date: 06/03/2015 11:32 (GMT-05:00) To: coy.h...@coyh

Re: [Freeipa-users] freeipa server upgrade from fedora 20 to fedora 22 glitches

2015-06-03 Thread Thomas Sailer
I have now managed to upgrade the replica as well. I stumbled over a few additional problems: 1) whenever a user becomes member of a group with +nsuniqueid= in its name, the user can no longer login. The reason is that ldb_dn_validate doesn't like the + character, thus returns false, which cau

[Freeipa-users] Could not update DNSSSHFP records when joining domain

2015-06-03 Thread nathan
I am running FreeIPA 4.1.3 on CentOS7. I am attempting to join a CentOS 6.5 client using ipa-client 3.0.0-42. The client hostname is ipaclient.login.mydomain.net. The FreeIPA domain is mydomain.net. This post here : https://www.redhat.com/archives/freeipa-users/2015-April/msg00368.html states t

Re: [Freeipa-users] sssd not caching public keys in sss_authorized_keys file

2015-06-03 Thread nathan
Comments inline > On (02/06/15 15:25), nat...@nathanpeters.com wrote: >>I am running FreeIPA 4.1.3 on CentOS 7 for the server and on the client >> is >>CentOS 6.5 with client 3.0.0-42 (sssd 1.11.6-30). >> >>I have created a user in FreeIPA and he has access to a server through >>HBAC rules. This

Re: [Freeipa-users] sssd not caching public keys in sss_authorized_keys file

2015-06-03 Thread Simo Sorce
On Wed, 2015-06-03 at 09:57 -0700, nat...@nathanpeters.com wrote: > Comments inline > > > On (02/06/15 15:25), nat...@nathanpeters.com wrote: > >>I am running FreeIPA 4.1.3 on CentOS 7 for the server and on the client > >> is > >>CentOS 6.5 with client 3.0.0-42 (sssd 1.11.6-30). > >> > >>I have cr

Re: [Freeipa-users] sssd not caching public keys in sss_authorized_keys file

2015-06-03 Thread nathan
> On Wed, 2015-06-03 at 09:57 -0700, nat...@nathanpeters.com wrote: >> Comments inline >> >> > On (02/06/15 15:25), nat...@nathanpeters.com wrote: >> >>I am running FreeIPA 4.1.3 on CentOS 7 for the server and on the >> client >> >> is >> >>CentOS 6.5 with client 3.0.0-42 (sssd 1.11.6-30). >> >> >>

Re: [Freeipa-users] Could not update DNSSSHFP records when joining domain

2015-06-03 Thread nathan
> I am running FreeIPA 4.1.3 on CentOS7. > > I am attempting to join a CentOS 6.5 client using ipa-client 3.0.0-42. > > The client hostname is ipaclient.login.mydomain.net. > > The FreeIPA domain is mydomain.net. > > This post here : > https://www.redhat.com/archives/freeipa-users/2015-April/msg003

Re: [Freeipa-users] vSphere and freeIPA

2015-06-03 Thread Rees
If I applied the original vsphere_groupmod.ldif (with the %regsub()) is there anything special I have to do to reapply the modification? When I attempt to apply this ldif i just get an error message telling me "type or value exists" and then when I run the steps you have, (creating users, groups,