Re: [Freeipa-users] Not able to get kerberos ticket from keytab

2016-02-26 Thread David Kupka
On 26/02/16 02:22, Teik Hooi Beh wrote: Hi, I have manged to deployed 1 ipa master and 1 ipa client with success on centos 7.2 with freeipa v4.2. I also managed to create user and set sshd-rules to for ttester user and also successfully get krb ticket using *kinit ttes...@example.my*. I am tryin

Re: [Freeipa-users] Not able to get kerberos ticket from keytab

2016-02-26 Thread David Kupka
On 26/02/16 08:56, David Kupka wrote: On 26/02/16 02:22, Teik Hooi Beh wrote: Hi, I have manged to deployed 1 ipa master and 1 ipa client with success on centos 7.2 with freeipa v4.2. I also managed to create user and set sshd-rules to for ttester user and also successfully get krb ticket using

Re: [Freeipa-users] Not able to get kerberos ticket from keytab

2016-02-26 Thread Teik Hooi Beh
Thanks. It's working now using ipa-getkeytab. Correct me if I am wrong (as I am new to freeipa), using ktutil I could add multiple user in a keytab file (correct???) but in this case using ipa-getkeytab can I do the same? On Fri, Feb 26, 2016 at 9:15 PM, David Kupka wrote: > On 26/02/16 08:56,

Re: [Freeipa-users] Not able to get kerberos ticket from keytab

2016-02-26 Thread Teik Hooi Beh
And yes, i also need to include -s ipaserver in the get-ipakeytab command, otherwise it kept giving wrong usage error On Fri, Feb 26, 2016 at 10:29 PM, Teik Hooi Beh wrote: > Thanks. It's working now using ipa-getkeytab. > > Correct me if I am wrong (as I am new to freeipa), using ktutil I c

Re: [Freeipa-users] Not able to get kerberos ticket from keytab

2016-02-26 Thread Martin Kosek
On 02/26/2016 10:31 AM, Teik Hooi Beh wrote: > And yes, i also need to include -s ipaserver in the get-ipakeytab command, > otherwise it kept giving wrong usage error Just for the record, this should no longer be needed from FreeIPA 4.3.0: https://fedorahosted.org/freeipa/ticket/2203 > On Fri

[Freeipa-users] version compatibility between server and client

2016-02-26 Thread Rakesh Rajasekharan
Hi!, I had successfully set up ipa in our qa environment, but since we are running cenots 6, i just got 3.0.25 version of IPA. I wanted to try out the latest 4.x version, for server by using a centos 7 OS. But have few questions regarding that Will there be compatibility issues, if I use a serve

[Freeipa-users] Preserved users not replicated to new master (FreeIPA 4.2.0)

2016-02-26 Thread Justin Bushey
Hello, I've noticed that when creating a new IPA master users that are set to be Preserved after deletion are not being replicated to the new master. I haven't been able to experiment much with this since I'm working in our production environment, but I did notice that if I restore them as active