Re: [Freeipa-users] Installing on Ubuntu 16.04

2017-05-01 Thread Peter Fern
freeipa-server is still quite broken on Ubuntu I believe. It should install fine, but certmonger can not renew the CA successfully, as nss on Debian/Ubuntu is missing nss-pem, so it can't read certificate files. I wrote about this in a thread titled "Dogtag certs did not auto-renew, very stuck!".

Re: [Freeipa-users] Chrome 58 Doesn't Trust SSL Certificates Signed by FreeIPA

2017-05-01 Thread Prasun Gera
Any ideas why the replica's certs are not being tracked ? That looks like an issue in itself. If they are not being tracked, the replica will fail once they expire. Is there any way to fix the replica ? On Sun, Apr 23, 2017 at 10:08 PM, Prasun Gera wrote: > I tried that, but the replica's "getce

Re: [Freeipa-users] Fedora 25 - SSSD: Smart card login is broken

2017-05-01 Thread Lukas Slebodnik
On (26/04/17 11:37), Sumit Bose wrote: >On Tue, Apr 25, 2017 at 12:38:11PM -0500, Michael Rainey (Contractor) wrote: >> Hello, >> >> While using Fedora 25 we noticed smart card login is broken with the latest >> update to SSSD. A month or so ago a patch was created to fix the same >> issue. Here

Re: [Freeipa-users] List SPAM

2017-05-01 Thread Peter Fern
On 27/12/16 23:32, Martin Basti wrote: > > > On 27.12.2016 13:22, Outback Dingo wrote: >> Im still getting nude porn spam emails and pics from a user >> >> Kimi Rachel >> > > It is not a user, it is a SPAM bot mining public archives. We don't > have any control about it we can just un-publish arch

Re: [Freeipa-users] List SPAM

2017-05-01 Thread Peter Fern
On 01/05/17 22:08, Peter Fern wrote: > On 27/12/16 23:32, Martin Basti wrote: >> It is not a user, it is a SPAM bot mining public archives. We don't >> have any control about it we can just un-publish archives (tested, >> spam stopped after that) but they contain a lot of information for users. > I

Re: [Freeipa-users] List SPAM

2017-05-01 Thread Peter Fern
On 01/05/17 22:15, Peter Fern wrote: > On 01/05/17 22:08, Peter Fern wrote: >> On 27/12/16 23:32, Martin Basti wrote: >>> It is not a user, it is a SPAM bot mining public archives. We don't >>> have any control about it we can just un-publish archives (tested, >>> spam stopped after that) but they

[Freeipa-users] ipa replica between different environments

2017-05-01 Thread Iulian Roman
Hello, is it possible/supported to _clone_ an ipa setup between different environments , disconnect the replicas and use them independently (ex. clone ST to ET and use them as separate IPA servers for ST respective ET clients ? ) or does the disconnect remove the data ? -- Manage your subscrip

Re: [Freeipa-users] List SPAM

2017-05-01 Thread Alexander Bokovoy
On ma, 01 touko 2017, Peter Fern wrote: On 01/05/17 22:15, Peter Fern wrote: On 01/05/17 22:08, Peter Fern wrote: On 27/12/16 23:32, Martin Basti wrote: It is not a user, it is a SPAM bot mining public archives. We don't have any control about it we can just un-publish archives (tested, spam s

Re: [Freeipa-users] Help needed - CA Server role not adding

2017-05-01 Thread Rob Crittenden
Chris Moody wrote: > Hello. > > First wanted to thank everyone working hard to bring this awesome bundle > of applications to market. This is a great project and I really > appreciate the efforts. > > I need a hand with a new 4.4.3 install that I'm still trying to flesh > out fully to support al

[Freeipa-users] EL5 sudo and IdM

2017-05-01 Thread Z D
Hi, we've been using the IdM server 4.4.0 but still have some EL5 (build system) we'd like to be ipa-clients. The ipa-client v2.1.3 has been installed, that works well. And I believe that with EL5, there is no sssd support for sudo, hence it's configured via /etc/ldap.conf The situation I see

Re: [Freeipa-users] EL5 sudo and IdM

2017-05-01 Thread Rob Crittenden
Z D wrote: > Hi, we've been using the IdM server 4.4.0 but still have some EL5 (build > system) we'd like to be ipa-clients. The ipa-client v2.1.3 has been > installed, that works well. > > And I believe that with EL5, there is no sssd support for sudo, hence > it's configured via /etc/ldap.conf