Re: [Freeipa-users] SUDO does not always works on first try

2015-10-13 Thread Zoske, Fabian
Hi Jakub, thanks for looking through the data. I can not access the bug you mentioned. I already created an account for Bugzilla, but so far nothing. In the second query there is a group which isn't present in the first one ((sudoUser=%ug_freeipa-administrators_int)). This is the IPA-equivalen

Re: [Freeipa-users] Free IPA to Microsoft AD 2008R2 trust question

2015-10-13 Thread Jan Pazdziora
On Mon, Oct 12, 2015 at 08:13:29PM +, Andy Thompson wrote: > > > The company I work for uses AD 2008R2 DC to resolve requests for > > Unix/Linux servers in various environments, under one domain > > example.com, with the Realm EXAMPLE.COM ? > > > > Is it possible to use Freeipa 4.1.0, with a

Re: [Freeipa-users] Free IPA to Microsoft AD 2008R2 trust question

2015-10-13 Thread Petr Spacek
On 12.10.2015 22:20, Alexander Bokovoy wrote: > On Mon, 12 Oct 2015, Andy Thompson wrote: >> >> >>> -Original Message- >>> From: freeipa-users-boun...@redhat.com [mailto:freeipa-users- >>> boun...@redhat.com] On Behalf Of Hoffmaster, John >>> Sent: Monday, October 12, 2015 3:46 PM >>> To: f

Re: [Freeipa-users] Free IPA to Microsoft AD 2008R2 trust question

2015-10-13 Thread Alexander Bokovoy
On Tue, 13 Oct 2015, Petr Spacek wrote: On 12.10.2015 22:20, Alexander Bokovoy wrote: On Mon, 12 Oct 2015, Andy Thompson wrote: -Original Message- From: freeipa-users-boun...@redhat.com [mailto:freeipa-users- boun...@redhat.com] On Behalf Of Hoffmaster, John Sent: Monday, October 12,

Re: [Freeipa-users] import debian (salted SHA-512) password

2015-10-13 Thread Martin Kosek
On 10/13/2015 02:35 AM, Simo Sorce wrote: > On 11/10/15 21:39, Benjamin Reed wrote: >> On 10/11/15 12:59 PM, Benjamin Reed wrote: >>> ...but I'm not sure exactly what format to use to import a >>> "$6$salt$hash" style password from an existing debian system. >> >> Just a note for future folks tryin

[Freeipa-users] ipa-server-install fails at last leg?

2015-10-13 Thread lejeczek
dear all, my first try at ipa server, I get this when install fails: [15/16]: restarting httpd [error] CalledProcessError: Command ''/bin/systemctl' 'restart' 'httpd.service'' returned non-zero exit status 1 Unexpected error - see /var/log/ipaserver-install.log for details: CalledProcessEr

[Freeipa-users] Looking to test one-way trust

2015-10-13 Thread Michael Barkdoll
Hello, I've successfully setup a two-way trust between FreeIPA and AD. My understanding is that FreeIPA is currently or planning to support Global Cataloging. I'm looking to implement a one-way trust between AD and FreeIPA to remove security concerns with my AD administrators in my organization.

Re: [Freeipa-users] Looking to test one-way trust

2015-10-13 Thread Alexander Bokovoy
On Tue, 13 Oct 2015, Michael Barkdoll wrote: Hello, I've successfully setup a two-way trust between FreeIPA and AD. My understanding is that FreeIPA is currently or planning to support Global Cataloging. I'm looking to implement a one-way trust between AD and FreeIPA to remove security concerns

[Freeipa-users] OAuth2

2015-10-13 Thread Ben Francis
Is it supported? Ben -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] OAuth2

2015-10-13 Thread Rob Crittenden
Ben Francis wrote: > Is it supported? No but you should be able to use IPA as an identity backend for an OAuth2 (or other Federation) provider. rob -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for

Re: [Freeipa-users] Correct upgrade steps for IPA server 4.1.0

2015-10-13 Thread Andrey Ptashnik
I usually try not to. On the other side I see that many important fixes are coming with major/minor releases, and trying to figure out my course of actions until fixes and/or release become available. Regards, Andrey Ptashnik On 10/12/15, 7:46 PM, "freeipa-users-boun...@redhat.com on beh

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-13 Thread Gronde, Christopher (Contractor)
Still having issues...if I can still have assistance with this getcert list Number of certificates and requests being tracked: 3. Request ID '20150922143354': status: NEED_TO_SUBMIT stuck: no key pair storage: type=NSSDB,location='/etc/httpd/alias',nickname='ipaCert',token

Re: [Freeipa-users] Certmonger and dogtag not working....issues manually renewing Server-Cert

2015-10-13 Thread Gronde, Christopher (Contractor)
So over the weekend time on the server changed back to normal so I set the time back again and tried to restart the ipa service and I get the following #service ipa start Starting Directory Service Starting dirsrv: ITMODEV-GOV... [FAILED] *** Error: 1

[Freeipa-users] shared ip space for iDM and AD

2015-10-13 Thread Craig White
Our environment is mostly Linux servers but we do have some Windows servers running MSSQL. A co-worker spun up Active Directory Domain Controllers without conferring with me and the Windows boxes are all on one of the VLAN private LAN networks used by FreeIPA. Thus we not only have reverse DNS s