[Freeipa-users] Issue with fresh install of FreeRADIUS

2016-01-06 Thread Anthony Cheng
Hi all, Just did a fresh install of FreeRADIUS following this guide on a Centos 7 box - http://www.freeipa.org/page/Using_FreeIPA_and_FreeRadius_as_a_RADIUS_based_software_token_OTP_system_with_CentOS/RedHat_7 Local testing with radtest works, however radiusd have issues. I do find it odd that

[Freeipa-users] Documentation on Testing page

2016-01-11 Thread Anthony Cheng
Hi all, I have been looking at the documentation, specifically the test page: http://www.freeipa.org/page/Testing It looks like it has missing info on the Build section, specifically I don't see reference to a makefile or where to run make to build the testing utility. Thanks, Anthony -- Manag

[Freeipa-users] configure: error: xmlrpc-c/base.h not found

2016-01-13 Thread Anthony Cheng
Hi all, I am getting an error with make for both freeipa-4.3.0 and freeipa-4.2.0; both errors are the same: checking for xmlrpc-c/base.h... no configure: error: xmlrpc-c/base.h not found make: *** [client-autogen] Error 1 I read from http://www.freeipa.org/page/Releases/4.0.0 that XMLRPC system

[Freeipa-users] (no subject)

2016-04-20 Thread Anthony Cheng
Hi list, This is an re-occurring subject; the dreaded expired certificate. I am following the renew here http://www.freeipa.org/page/IPA_2x_Certificate_Renewal and testing on a clone VM and I am able to get to the step where the serial number is being replaced: ldapmodify -x -h localhost -p 7389

[Freeipa-users] Migrate FreeIPA data from v2.0. to v4.2.0

2016-04-25 Thread Anthony Cheng
Hi list, Currently in the midst of doing a migration of FreeIPA from v3.0.0 to v4.2.0; I have setup the new IPA instances and I am looking at migrate the data. Based on the section under 'Migrating from other FreeIPA to FreeIPA' here ( http://www.freeipa.org/page/Howto/Migration#Migrating_existin

Re: [Freeipa-users] Migrate FreeIPA data from v3.0. to v4.2.0

2016-04-25 Thread Anthony Cheng
run a "ipa user-show user_name --all" I supposed manual option/script is the only option at this point? Anthony On Mon, Apr 25, 2016 at 1:06 PM Anthony Cheng wrote: > Hi list, > > Currently in the midst of doing a migration of FreeIPA from v3.0.0 to > v4.2.0; I have setup

[Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-04-27 Thread Anthony Cheng
Hi list, I am trying to renew expired certificates following the manual renewal procedure here (http://www.freeipa.org/page/IPA_2x_Certificate_Renewal) but even with resetting the system/hardware clock to a time before expires, I am getting the error "ca-error: Error setting up ccache for local "h

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-04-28 Thread Anthony Cheng
of services to probe status: Directory Server is stopped On Thu, Apr 28, 2016 at 3:21 AM David Kupka wrote: > On 27/04/16 21:54, Anthony Cheng wrote: > > Hi list, > > > > I am trying to renew expired certificates following the manual renewal > procedure > > here (http

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-04-29 Thread Anthony Cheng
certificate;binary: !@#$@!#$#@$ Then I re-run ldapsearch -x -h localhost -p 7389 -D 'cn=directory manager' -W -b uid=ipara,ou=People,o=ipaca I see 2 entries for usercertificate;binary (before modify there was only 1) but they are duplicate and NOT from data that I added. That seems incor

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-04-29 Thread Anthony Cheng
Authority Key Identifier Name: Authority Information Access Name: Certificate Key Usage Name: Extended Key Usage Name: Certificate Subject Key ID On Fri, Apr 29, 2016 at 4:50 PM Anthony Cheng wrote: > OK so I made process on my cert renew issu

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-05-02 Thread Anthony Cheng
On Sat, Apr 30, 2016 at 10:08 AM Rob Crittenden wrote: > Anthony Cheng wrote: > > OK so I made process on my cert renew issue; I was able to get kinit > > working so I can follow the rest of the steps here > > (http://www.freeipa.org/page/IPA_2x_Certificate_Renewal) > &g

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-05-04 Thread Anthony Cheng
On Wed, May 4, 2016 at 9:07 AM, Rob Crittenden wrote: > Anthony Cheng wrote: >> >> Small update, I found an article on the RH solution library >> (https://access.redhat.com/solutions/2020223) that has the same error >> code that I am getting and I followed the steps wit

Re: [Freeipa-users] ca-error: Error setting up ccache for local "host" service using default keytab: Clock skew too great.

2016-05-05 Thread Anthony Cheng
. Certificate operation cannot be completed : Unable to communicate with CMS (Not Found)).) Currently I am on the process to recreate this problem on RHEL 6 to try to get RH support on this. Thanks, Anthony On Wed, May 4, 2016 at 10:34 AM, Anthony Cheng wrote: > On Wed, May 4, 2016 at 9:07 AM,