Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, lejeczek wrote: On Fri, 2016-06-10 at 12:12 +0300, Alexander Bokovoy wrote: On Fri, 10 Jun 2016, Jakub Hrozek wrote: > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > hi everyone > > > > there is a master IPA which in some weird way puts AD users into > > its

Re: [Freeipa-users] IPA trust external DNS Default-First-Site-Name records

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, Jan Karásek wrote: Hi, I am trying to setup external DNS for IPA with AD trust. I have set all records in DNS according doc but in the internal IPA DNS I can see 3 more DNS records which are not mentioned in doc. They were set automatically during ipa trust-add commnad I

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
On Fri, 2016-06-10 at 12:12 +0300, Alexander Bokovoy wrote: > On Fri, 10 Jun 2016, Jakub Hrozek wrote: > > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > > hi everyone > > > > > > there is a master IPA which in some weird way puts AD users into > > > its ldap > > > catalog. I say

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Günther J . Niederwimmer
Hello, Am Freitag, 10. Juni 2016, 10:12:50 CEST schrieb Martin Basti: > On 10.06.2016 09:09, Günther J. Niederwimmer wrote: > > Hello, > > > > can any help me to clear a question for DNSSEC, NSEC3 > > > > I have a domain created with bind and DNSSEC and NSEC3 I test this Domain > > and other,

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, lejeczek wrote: On Fri, 2016-06-10 at 12:12 +0300, Alexander Bokovoy wrote: On Fri, 10 Jun 2016, Jakub Hrozek wrote: > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > hi everyone > > > > there is a master IPA which in some weird way puts AD users into > > its

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, lejeczek wrote: On Fri, 2016-06-10 at 11:01 +0200, Jakub Hrozek wrote: On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > hi everyone > > there is a master IPA which in some weird way puts AD users into > its ldap > catalog. I say weird cause there is no trust nor

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Petr Spacek
On 10.6.2016 14:21, Günther J. Niederwimmer wrote: > Hello, > > Am Freitag, 10. Juni 2016, 10:12:50 CEST schrieb Martin Basti: >> On 10.06.2016 09:09, Günther J. Niederwimmer wrote: >>> Hello, >>> >>> can any help me to clear a question for DNSSEC, NSEC3 >>> >>> I have a domain created with bind

Re: [Freeipa-users] Can't establish trust with 2008 AD

2016-06-10 Thread pgb205
Alexander, here you go. One thing that came to mind that might the a problem. My Active directory is adserver.addomain.comwhile IPA is ipax1.ipadomain; there is no suffix. Not sure if that would matter.  Anyway here is the log as requested.  Thank you.  net ads lookup -d 10 -S  

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Martin Basti
On 10.06.2016 17:33, Günther J. Niederwimmer wrote: Am Freitag, 10. Juni 2016, 15:26:39 CEST schrieb Petr Spacek: On 10.6.2016 14:21, Günther J. Niederwimmer wrote: Hello, Am Freitag, 10. Juni 2016, 10:12:50 CEST schrieb Martin Basti: On 10.06.2016 09:09, Günther J. Niederwimmer wrote:

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Martin Basti
On 10.06.2016 18:14, Günther J. Niederwimmer wrote: Am Freitag, 10. Juni 2016, 18:01:32 CEST schrieb Martin Basti: On 10.06.2016 17:33, Günther J. Niederwimmer wrote: Am Freitag, 10. Juni 2016, 15:26:39 CEST schrieb Petr Spacek: On 10.6.2016 14:21, Günther J. Niederwimmer wrote: Hello, Am

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Günther J . Niederwimmer
Am Freitag, 10. Juni 2016, 15:26:39 CEST schrieb Petr Spacek: > On 10.6.2016 14:21, Günther J. Niederwimmer wrote: > > Hello, > > > > Am Freitag, 10. Juni 2016, 10:12:50 CEST schrieb Martin Basti: > >> On 10.06.2016 09:09, Günther J. Niederwimmer wrote: > >>> Hello, > >>> > >>> can any help me

Re: [Freeipa-users] Using LDAP directly - Password Expiry

2016-06-10 Thread Rob Crittenden
Prashant Bapat wrote: Hi, I'm using FreeIPA's LDAP component as user database in another application. The binds happen using the user's credentials (password+otp) and the search happens by a service account created under cn=sysaccounts. Things are working as expected except one small hitch.

[Freeipa-users] Replication time and relation to cache size

2016-06-10 Thread Ash Alam
Hello I have been going through the lists but i have not found the answer i am looking for. I am seeing few issues for which i am looking for some clarification. 1. What is the relationship between replication time and cache size? - I am noticing that it's taking up to 5 minutes for some things

Re: [Freeipa-users] Redhat Summit

2016-06-10 Thread Randy Morgan
Awesome, Thanks Rob, I am looking forward to it. Randy Randy Morgan CSR Department of Chemistry and Biochemistry Brigham Young University 801-422-4100 On 6/10/2016 11:51 AM, Rob Crittenden wrote: Randy Morgan wrote: So I have a slightly different question. Redhat Summit is the end of this

[Freeipa-users] Redhat Summit

2016-06-10 Thread Randy Morgan
So I have a slightly different question. Redhat Summit is the end of this month, and I was wondering why FreeIPA was not doing a presentation at the summit? This is a subject I would be very interested in at the summit. Randy -- Randy Morgan CSR Department of Chemistry and Biochemistry

Re: [Freeipa-users] Redhat Summit

2016-06-10 Thread Rob Crittenden
Randy Morgan wrote: So I have a slightly different question. Redhat Summit is the end of this month, and I was wondering why FreeIPA was not doing a presentation at the summit? This is a subject I would be very interested in at the summit. Randy IPA will be there in at least these

Re: [Freeipa-users] problem in sudo policy when target commands use local environment variables

2016-06-10 Thread Mitra Dehghan
Dear Paul, Thanks for your suggestion. It worked. By the way, using -i option I had to change sudocmd definition in IPA SERVER, to the " /bin/bash -c /path/to/target_cmd" then after -i option worked successfully. Thanks a lot. On Jun 6, 2016 8:33 PM, "Brennan, Paul J"

Re: [Freeipa-users] FreeIPA 4.2.0: An error has occurred (IPA Error 4301: CertificateOperationError)

2016-06-10 Thread Dan.Finkelstein
That’s exactly right, and we got the files and links back to serviceable order. Now we're (merely) facing issues with our restored certificate store, which the pki-tomcatd process is not happy with. All IPA services start normally except for tomcat, which spits out SSL errors (and we're pretty

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
On Fri, 2016-06-10 at 11:01 +0200, Jakub Hrozek wrote: > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > hi everyone > > > > there is a master IPA which in some weird way puts AD users into > > its ldap > > catalog. I say weird cause there is no trust nor other sync > > established,

Re: [Freeipa-users] FreeIPA 4.2.0: An error has occurred (IPA Error 4301: CertificateOperationError)

2016-06-10 Thread Dan.Finkelstein
And, from the 'ipactl -d --ignore-service-failures restart' we get this: ipa: DEBUG: stderr= ipa: DEBUG: wait_for_open_ports: localhost [8080, 8443] timeout 300 ipa: DEBUG: Waiting until the CA is running ipa: DEBUG: Starting external process ipa: DEBUG: args='/usr/bin/wget' '-S' '-O' '-'

Re: [Freeipa-users] Redhat Summit

2016-06-10 Thread Randy Morgan
Do you know the vendor name on the booth, or will it be under Redhat? Randy Randy Morgan CSR Department of Chemistry and Biochemistry Brigham Young University 801-422-4100 On 6/10/2016 11:51 AM, Rob Crittenden wrote: Randy Morgan wrote: So I have a slightly different question. Redhat Summit

Re: [Freeipa-users] Redhat Summit

2016-06-10 Thread Rob Crittenden
Randy Morgan wrote: Do you know the vendor name on the booth, or will it be under Redhat? I'm told there will be an Identity Management kiosk/demo area at the Red Hat booth. rob Randy Randy Morgan CSR Department of Chemistry and Biochemistry Brigham Young University 801-422-4100 On

Re: [Freeipa-users] Can't establish trust with 2008 AD

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, pgb205 wrote: Alexander, here you go. One thing that came to mind that might the a problem. My Active directory is adserver.addomain.comwhile IPA is ipax1.ipadomain; there is no suffix. Not sure if that would matter.  Anyway here is the log as requested.  So here is what we

Re: [Freeipa-users] FreeIPA 4.2.0: An error has occurred (IPA Error 4301: CertificateOperationError)

2016-06-10 Thread Rob Crittenden
dan.finkelst...@high5games.com wrote: And, from the 'ipactl -d --ignore-service-failures restart' we get this: ipa: DEBUG: stderr= ipa: DEBUG: wait_for_open_ports: localhost [8080, 8443] timeout 300 ipa: DEBUG: Waiting until the CA is running ipa: DEBUG: Starting external process ipa:

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Günther J . Niederwimmer
Am Freitag, 10. Juni 2016, 18:01:32 CEST schrieb Martin Basti: > On 10.06.2016 17:33, Günther J. Niederwimmer wrote: > > Am Freitag, 10. Juni 2016, 15:26:39 CEST schrieb Petr Spacek: > >> On 10.6.2016 14:21, Günther J. Niederwimmer wrote: > >>> Hello, > >>> > >>> Am Freitag, 10. Juni 2016,

[Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Günther J . Niederwimmer
Hello, can any help me to clear a question for DNSSEC, NSEC3 I have a domain created with bind and DNSSEC and NSEC3 I test this Domain and other, not my Domain with http://dnsviz.net/d/esslmaier.at/dnssec/ This site from Verisign tell me, I have all Secure and also the A, Records

Re: [Freeipa-users] Can't establish trust with 2008 AD

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, pgb205 wrote: The trust setup still results in Shared secret for the trust:: ERROR: CIFS server communication error: code "None",                  message "NT_STATUS_IO_TIMEOUT" (both may be "None") If you want I can provide with logs. Can you show output of net ads

Re: [Freeipa-users] ipa-client-install

2016-06-10 Thread Martin Basti
On 09.06.2016 22:36, David Zabner wrote: Occassionally in our system we will see a failure in ipa-client-install script and the cleanup will leave around the host in ipa. This means that all future client installs fail because the host already exists. Is there any way to make sure that

[Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
hi everyone there is a master IPA which in some weird way puts AD users into its ldap catalog. I say weird cause there is no trust nor other sync established, there was a trust agreement, one way type, but now 'trust-find' shows nothing, that trust was removed. but still when I create a

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Jakub Hrozek
On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > hi everyone > > there is a master IPA which in some weird way puts AD users into its ldap > catalog. I say weird cause there is no trust nor other sync established, > there was a trust agreement, one way type, but now 'trust-find' shows

Re: [Freeipa-users] FreeOTP

2016-06-10 Thread Winfried de Heiden
Hi all, I agree on it's look like a 32 bit issue. Trying to reproduce on Fedora 64 bit; no problems Trying to reproduce on Fedora 23 32 bit (x886): [root@freeipa ~]# journalctl -l -u ipa-otpd@0-6397-0.service -- Logs begin at vr

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Sumit Bose
On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > hi everyone > > there is a master IPA which in some weird way puts AD users into its ldap > catalog. I say weird cause there is no trust nor other sync established, > there was a trust agreement, one way type, but now 'trust-find' shows

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread Alexander Bokovoy
On Fri, 10 Jun 2016, Jakub Hrozek wrote: On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: hi everyone there is a master IPA which in some weird way puts AD users into its ldap catalog. I say weird cause there is no trust nor other sync established, there was a trust agreement, one way

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Martin Basti
On 10.06.2016 09:09, Günther J. Niederwimmer wrote: Hello, can any help me to clear a question for DNSSEC, NSEC3 I have a domain created with bind and DNSSEC and NSEC3 I test this Domain and other, not my Domain with http://dnsviz.net/d/esslmaier.at/dnssec/ This site from Verisign tell me,

Re: [Freeipa-users] DNSSEC A, AAAA Records

2016-06-10 Thread Martin Basti
On 10.06.2016 10:12, Martin Basti wrote: On 10.06.2016 09:09, Günther J. Niederwimmer wrote: Hello, can any help me to clear a question for DNSSEC, NSEC3 I have a domain created with bind and DNSSEC and NSEC3 I test this Domain and other, not my Domain with

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
On Fri, 2016-06-10 at 11:08 +0200, Sumit Bose wrote: > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > hi everyone > > > > there is a master IPA which in some weird way puts AD users into > > its ldap > > catalog. I say weird cause there is no trust nor other sync > > established, >

[Freeipa-users] IPA trust external DNS Default-First-Site-Name records

2016-06-10 Thread Jan Karásek
Hi, I am trying to setup external DNS for IPA with AD trust. I have set all records in DNS according doc but in the internal IPA DNS I can see 3 more DNS records which are not mentioned in doc. They were set automatically during ipa trust-add commnad I guess:

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
On Fri, 2016-06-10 at 13:24 +0300, Alexander Bokovoy wrote: > On Fri, 10 Jun 2016, lejeczek wrote: > > On Fri, 2016-06-10 at 12:12 +0300, Alexander Bokovoy wrote: > > > On Fri, 10 Jun 2016, Jakub Hrozek wrote: > > > > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > > > > hi everyone

Re: [Freeipa-users] FreeIPA 4.2.0: An error has occurred (IPA Error 4301: CertificateOperationError)

2016-06-10 Thread Dan.Finkelstein
An update: The journalctl command has some really interesting output: Jun 10 11:16:23 ipa.example.com pkidaemon[25032]: WARNING: Symbolic link '/var/lib/pki/pki-tomcat/alias' does NOT exist! Jun 10 11:16:23 ipa.example.com pkidaemon[25032]: INFO: Attempting to create

Re: [Freeipa-users] it's a weird one - how AD users get into IPA ?

2016-06-10 Thread lejeczek
On Fri, 2016-06-10 at 15:34 +0300, Alexander Bokovoy wrote: > On Fri, 10 Jun 2016, lejeczek wrote: > > On Fri, 2016-06-10 at 12:12 +0300, Alexander Bokovoy wrote: > > > On Fri, 10 Jun 2016, Jakub Hrozek wrote: > > > > On Fri, Jun 10, 2016 at 09:54:19AM +0100, lejeczek wrote: > > > > > hi everyone