Re: [Freeipa-users] Kerberos hanging approx. once a day

2015-07-24 Thread Torsten Harenberg
Dear Rich and all, thanks to everbody! Really thankful for your support. The situation really approved. We: - enlarged the caches for 389ds until the WARNING messages disappeared in the log files, - (just to be sure) re-sync'ed firewalld rules between primary and secondary server. Now the serv

Re: [Freeipa-users] OT: https://www.freeipa.org missing intermediate certificate

2015-07-24 Thread Martin Kosek
On 07/10/2015 04:36 PM, Natxo Asenjo wrote: hi, earlier today I was reading a post about the new freeipa version on my mobile device and got plenty of warnings about an invalid certificate. On a fedora laptop no warnings, but this is the problem: $ curl -LIv https://www.freeipa.org * Rebuilt UR

Re: [Freeipa-users] FreeIPA Server Won't Start Up After ipactl restart

2015-07-24 Thread Martin Kosek
On 07/14/2015 02:47 PM, Sina Owolabi wrote: Hi Please, I would really need some help in troubleshooting one of my domain servers which I restarted the IPA services. Its an CentOS 7.1 server running ipa-4.1.0 [root@dc01 ~]# ipactl start Existing service file detected! Assuming stale, cleaning a

Re: [Freeipa-users] OTP vs sudo

2015-07-24 Thread Martin Kosek
On 07/16/2015 06:58 PM, Bendl, Kurt wrote: I'm planning our implementation of IdM/IPA, and I'm unclear about how I can implement IPA's OTP for privileged access. I need to be able to set up systems so: * accounts can auth using traditional userid/password * privileged access (sudo) require

Re: [Freeipa-users] dnssec support in 4.1

2015-07-24 Thread Martin Kosek
On 07/22/2015 03:52 PM, Andrew E. Bruno wrote: On Wed, Jul 22, 2015 at 04:48:33PM +0300, Alexander Bokovoy wrote: On Wed, 22 Jul 2015, Andrew E. Bruno wrote: Apologies if this has been answered before but we're interested in dnssec support in FreeIPA. Running Centos 7.1.1503, ipa-server 4.1.0-

Re: [Freeipa-users] FreeIPA Server Won't Start Up After ipactl restart

2015-07-24 Thread Sina Owolabi
Hi Martin I wasn't able to resolve it, so I destroyed and recreated the replica and its replication agreements. On Fri, Jul 24, 2015 at 8:37 AM, Martin Kosek wrote: > On 07/14/2015 02:47 PM, Sina Owolabi wrote: >> >> Hi >> >> Please, I would really need some help in troubleshooting one of my >>