Re: [Freeipa-users] ipa-replica-prepare error

2015-07-31 Thread Martin Kosek
On 07/30/2015 05:28 PM, Orion Poplawski wrote: On 07/28/2015 11:09 PM, Jan Cholasta wrote: Dne 20.7.2015 v 19:52 Orion Poplawski napsal(a): On 07/20/2015 12:57 AM, Jan Cholasta wrote: Dne 15.7.2015 v 20:57 Orion Poplawski napsal(a): On 07/14/2015 11:53 PM, Jan Cholasta wrote: # ipa-r

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Sumit Bose
On Thu, Jul 30, 2015 at 05:35:53PM -0500, Dan Mossor wrote: > Greetings, folks. > > So, I've been fighting with getting a trust set up between FreeIPA 4.1 on > CentOS 7.1 and Windows Server 2008r2 for nearly a week. Today I finally came > to a conclusion as to what my issue is. > > I operate a se

Re: [Freeipa-users] OT: https://www.freeipa.org missing intermediate certificate

2015-07-31 Thread Natxo Asenjo
Hi, Maybe just one more redirect if people come directly to https://freeipa.org? $ curl -LIv https://freeipa.org * Rebuilt URL to: https://freeipa.org/ * Hostname was NOT found in DNS cache * Trying 209.132.183.105... * Connected to freeipa.org (209.132.183.105) port 443 (#0) * Initializing

Re: [Freeipa-users] OT: https://www.freeipa.org missing intermediate certificate

2015-07-31 Thread Martin Kosek
On 07/31/2015 10:10 AM, Natxo Asenjo wrote: Hi, Maybe just one more redirect if people come directly to https://freeipa.org? Right, this is the last missing part. I did not implement it yet as I would first need to set up some own redirecting machine that I could trust and upload FreeIPA HT

[Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Matt .
Hi Guys, I'm really struggeling getting a NON AD Samba server authing against a FreeIPA server: Ubuntu 14.04 -> Samba (no AD) / SSD 1.12.5 CentOS 7.1 -> FreeIPA 4.1 Now this seems to be the way: https://www.freeipa.org/page/Howto/Integrating_a_Samba_File_Server_With_IPA But as this, which I al

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Youenn PIOLET
Hi, I asked the very same question a few weeks ago, but no answer yet. http://comments.gmane.org/gmane.linux.redhat.freeipa.user/18174 The only method I see is to install samba extensions in FreeIPA's LDAP directory, and bind samba with LDAP. There may be a lot of difficulties with password manage

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Dan Mossor
On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that currently FreeIPA does not have a global catalog, because Windows typically tries to get SIDs from remote objects from the Global Catalog. So, to

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Christopher Lamb
Hi We use the Samba extensions for FreeIPA. Windows 7 users connect to the "shares" using their FreeIPA credentials. The only password mgmt problem that we have is, that the users get no notice of password expiry until "suddenly" their Samba user (really the FreeIPA user) password is not accepted

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Matt .
Hi, This is nice to have confirmed. Is it possible for you to descrive what you do ? It might be handy to add this to the IPA documentation also with some explanation why... Cheers, Matt 2015-07-31 16:55 GMT+02:00 Christopher Lamb : > Hi > > We use the Samba extensions for FreeIPA. Windows 7 u

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Sumit Bose
On Fri, Jul 31, 2015 at 09:23:53AM -0500, Dan Mossor wrote: > On 07/31/2015 02:52 AM, Sumit Bose wrote: > > > >Thank you for the detailed analysis. I guess the 'server was > >inaccessible' error is due to the fact that currently FreeIPA does not > >have a global catalog, because Windows typically t

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Lukas Slebodnik
On (31/07/15 16:03), Matt . wrote: >Hi Guys, > >I'm really struggeling getting a NON AD Samba server authing against a >FreeIPA server: > >Ubuntu 14.04 -> Samba (no AD) / SSD 1.12.5 >CentOS 7.1 -> FreeIPA 4.1 > >Now this seems to be the way: > >https://www.freeipa.org/page/Howto/Integrating_a_Samba

Re: [Freeipa-users] Setting up Active Directory trusts in a secure environment

2015-07-31 Thread Dan Mossor
On 07/31/2015 10:08 AM, Sumit Bose wrote: On Fri, Jul 31, 2015 at 09:23:53AM -0500, Dan Mossor wrote: On 07/31/2015 02:52 AM, Sumit Bose wrote: Thank you for the detailed analysis. I guess the 'server was inaccessible' error is due to the fact that currently FreeIPA does not have a global cata

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Matt .
Hi Lucas, Thank you for this reply. In this case it simply should work as it shoul by creating the symlinks, Or are there other issues we might get ? Thanks, Matt 2015-07-31 17:21 GMT+02:00 Lukas Slebodnik : > On (31/07/15 16:03), Matt . wrote: >>Hi Guys, >> >>I'm really struggeling getting a

Re: [Freeipa-users] Ubuntu Samba Server Auth against IPA

2015-07-31 Thread Lukas Slebodnik
On (31/07/15 18:15), Matt . wrote: >Hi Lucas, > >Thank you for this reply. > >In this case it simply should work as it shoul by creating the >symlinks, Or are there other issues we might get ? > 1st problem: current samba version of libwbclient need to be moved ot other place. 2nd problem: manualy