Re: [Freeipa-users] [Freeipa-devel] Open ports for client can auth over wan

2015-11-03 Thread Petr Spacek
Hello, please do not drop freeipa-users list when replying. There is plenty of smart people who can reply instead of me :-) Anyway: On 3.11.2015 10:31, Martin Jørgensen wrote: > Okay all of them, also bind is that not a vulnerability? If you are asking about DNS server BIND, then you need to do

Re: [Freeipa-users] Duplicate objects after 4.1 ipa-server upgrade

2015-11-03 Thread Andrew Krause
I upgraded 4 at the same time actually. It makes sense why the objects were created and I do understand how replication conflicts are handled. I just wanted to be absolutely certain that it was ok to delete these objects since it seems pointless to ever keep them around. Has there been any

Re: [Freeipa-users] Duplicate objects after 4.1 ipa-server upgrade

2015-11-03 Thread Ludwig Krispenz
On 11/03/2015 04:24 PM, Andrew Krause wrote: I upgraded 4 at the same time actually. It makes sense why the objects were created and I do understand how replication conflicts are handled. I just wanted to be absolutely certain that it was ok to delete these objects since it seems pointless

Re: [Freeipa-users] how to chain CA certs

2015-11-03 Thread Sean Conley - US
Not sure if I should start a new thread for this, but... I am now trying to follow the instructions given in this thread: https://www.redhat.com/archives/freeipa-users/2014-August/msg00338.html. I think this configuration should work well with our deployment strategy. I feel like I am following

[Freeipa-users] using wildcard cert from external CA

2015-11-03 Thread Sean Conley - US
Sorry for the redundancy but I thought it would be better to start a new thread since I am really asking a different question at this point. We are trying to stand up an IPA instance using real certs (wildcard) for our domain, so that external users get a valid cert when coming the the https

Re: [Freeipa-users] using wildcard cert from external CA

2015-11-03 Thread Rob Crittenden
Sean Conley - US wrote: > Sorry for the redundancy but I thought it would be better to start a new > thread since I am really asking a different question at this point. > > We are trying to stand up an IPA instance using real certs (wildcard) > for our domain, so that external users get a valid

Re: [Freeipa-users] FreeIPA and Samba4

2015-11-03 Thread Troels Hansen
Hi, I got a bit further. I fount the error, being that I had some groups from the old LDAP with gid aroud 500, and current ID range i IPA sat to start at 2000, which was my start UID on the old LDAP. Is it possible to "reset" the base UID/GID that IPA assigns to the next user? I can't find it

[Freeipa-users] Python IndexError: list index out of range with ipa-server-install --external-cert-file

2015-11-03 Thread Gilbert Wilson
Apologies ahead of time as this is my first post to the list and interaction with the FreeIPA project. If I should be taking this question to a different forum please point me in the right direction! The error condition I’m encountering is mentioned a few times on the list, but the threads die

Re: [Freeipa-users] IPA Replication not working for User and DNS

2015-11-03 Thread Yogesh Sharma
LDAPS is also fine: [root@ipa-inf-prd-ng2-02 ~]# ldapsearch -x -H ldaps:// ipa-inf-prd-ng2-01.klikpay.int -s base -b '' namingContexts # extended LDIF # # LDAPv3 # base <> with scope baseObject # filter: (objectclass=*) # requesting: namingContexts # # dn: namingContexts: cn=changelog