Re: [Freeipa-users] Using FreeIPA for LDAP authentication in 3rd party applications

2015-03-17 Thread Dan
due to the next option) User the User Membership Attribute: (Ensure this is unchecked, it is not supported) Now save and test using the user who is in the groups created above. Hope this helps someone. Dan -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com

Re: [Freeipa-users] Re: Configuring Client SSH Access Problem

2009-12-09 Thread Dan Scott
Generally, I've found that this is caused by incorrect DNS records. Make sure that your A and PTR records are correct for this host. One other thing, you should be able to run ipa-getkeytab directly on the client. Hope this helps, Dan Scott http://danieljamesscott.org On Wed, Dec 9, 2009 at 02

[Freeipa-users] Cross realm authentication

2009-12-18 Thread Dan Scott
be able to authenticate to C.B.EXAMPLE.COM, but not the other way around (This is how I would like it setup). However, this does not appear to work. I assume that I need to add some entries to the LDAP server as well? Does anyone know if this is true and if so, how I should go about it? Thanks, Dan

Re: [Freeipa-users] Cross realm authentication

2009-12-18 Thread Dan Scott
Hi, On Fri, Dec 18, 2009 at 13:40, Nalin Dahyabhai na...@redhat.com wrote: On Fri, Dec 18, 2009 at 12:31:44PM -0500, Dan Scott wrote: I have added these principals to both FreeIPA servers: krbtgt/c.b.example@a.example.com (I see the warning in the FreeIPA documentation about avoiding

[Freeipa-users] Failed to verify that server.example.com is an IPA Server. while running ipa-client-install

2010-01-06 Thread Dan Scott
occurs before the error message above is displayed. Thanks, Dan Scott http://danieljamesscott.org ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Failed to verify that server.example.com is an IPA Server. while running ipa-client-install

2010-01-06 Thread Dan Scott
Sorry, there was an error in my DNS configuration. The TXT entry for _kerberos was incorrect. Dan On Wed, Jan 6, 2010 at 09:50, Dan Scott danieljamessc...@gmail.com wrote: Hi, I've just tried to add an new Fedora 12 PC to our FreeIPA realm and I received the following error: [r...@client

[Freeipa-users] Fedora 13 client login problems

2010-06-28 Thread Dan Scott
quiet use_uid session required pam_unix.so session optional pam_krb5.so [r...@pc45 ~]# Does anyone have any suggestions for why this is not working? Thanks, Dan Scott ___ Freeipa-users mailing list Freeipa-users@redhat.com https

Re: [Freeipa-users] SSSD Cache

2010-06-30 Thread Dan Scott
. Maybe the cache was corrupted? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Upgraded replication slave server - dirsrv process dying

2010-08-11 Thread Dan Scott
://directory.fedoraproject.org/wiki/Subtree_Rename#warning:_upgrade_from_389_v1.2.6_.28a.3F.2C_rc1_.7E_rc6.29_to_v1.2.6_rc6_or_newer Which could well apply in my case, but I wanted to check to ensure that this would apply to FreeIPA. Does anyone have any comments suggestions about this? Thanks, Dan Scott

Re: [Freeipa-users] Upgraded replication slave server - dirsrv process dying

2010-08-11 Thread Dan Scott
in 389-ds-base-1.2.6.rc7 (I'm not sure whether that's earlier or later than 389-ds-base-1.2.6-0.1.a1 - an alpha?). Hopefully there will be an update soon, and this will resolve the problem. Thanks, Dan On Wed, Aug 11, 2010 at 12:26, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi

Re: [Freeipa-users] Upgraded replication slave server - dirsrv process dying

2010-08-12 Thread Dan Scott
.7E_rc6.29_to_v1.2.6_rc6_or_newer The dirsrv process started correctly and started answering requests. Looking good so far. I guess it's time to consider upgrading the master from Fedora 11. :) At least I'll be prepared if this happens again. Thanks for the help, Dan

[Freeipa-users] 389-base-1.2.6-1.fc13.x86_64 package installed - fail to replicate.

2010-09-16 Thread Dan Scott
fails to start at all. Does anyone have any ideas for how to fix this? Thanks, Dan Scott ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] 389-base-1.2.6-1.fc13.x86_64 package installed - fail to replicate.

2010-09-16 Thread Dan Scott
error, sorry. Thanks for your help, Dan On Thu, Sep 16, 2010 at 16:15, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: Hi, Thanks for the reply. It's been upgraded from F12: On Thu, Sep 16, 2010 at 15:49, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote

[Freeipa-users] Upgrade from Fedora 11 to 13

2010-09-21 Thread Dan Scott
server replicate my new server and lose everything? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Fedora 11 master replication problems

2010-09-22 Thread Dan Scott
-0400] NSMMReplicationPlugin - agmt=cn=meTocurie.example.com636 (curie:636): State: sending_updates - start_backoff curie is the replicated server. Does anyone have any suggestions for resolving this? Thanks, Dan ___ Freeipa-users mailing list Freeipa

Re: [Freeipa-users] Fedora 11 master replication problems

2010-09-22 Thread Dan Scott
. Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Fedora 11 master replication problems

2010-09-22 Thread Dan Scott
Excellent, that seems to have solved it, thanks. Dan On Wed, Sep 22, 2010 at 13:32, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, Sorry, I just checked the manpage myself and I see that there's an init option to ipa-replica-manage. On Wed, Sep 22, 2010 at 12:08, Rich

[Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
the replication, but I suspect this has something to do with the schema definition. Does anyone have any pointers/ideas for how I can fix this? Thanks, Dan Scott ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 11:32, Simo Sorce sso...@redhat.com wrote: On Wed, 6 Oct 2010 10:26:48 -0400 Dan Scott danieljamessc...@gmail.com wrote: Hi, I have master and slave FreeIPA servers. I recently upgraded the slave by wiping, re-installing Fedora 13 and re-creating the replication

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, ohm_admins.ldif and curie_admins.ldif attached. I added a '-h $hostname' to the command to ensure that I queried both servers. The results look identical to me, apart from the ordering. Thanks, Dan On Wed, Oct 6, 2010 at 15:34, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
on both servers. Both ohm and curie have groups which contain the correct 'member' attributes. So the problem appears to be that ohm contains groups with correct 'members', but none of the users have any 'memberOf's. Thanks, Dan On Wed, Oct 6, 2010 at 16:17, Rich Megginson rmegg...@redhat.com

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. The problem appears to be related to the users, rather than the groups. None of the users on ohm have

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-06 Thread Dan Scott
Hi, On Wed, Oct 6, 2010 at 19:29, Nathan Kinder nkin...@redhat.com wrote: On 10/06/2010 03:08 PM, Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups. Do any other groups have a member attribute that points to your cn=admins

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Wed, Oct 6, 2010 at 22:02, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm not sure which group this is referring to. Admins only contains 3 users, no nested groups

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
On Thu, Oct 7, 2010 at 10:20, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: On Wed, Oct 6, 2010 at 22:02, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: Hi, On Wed, Oct 6, 2010 at 18:30, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: I'm

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-07 Thread Dan Scott
-memberof nsslapd-pluginEnabled: on dn: cn=MemberOf Plugin,cn=plugins,cn=config cn: MemberOf Plugin nsslapd-pluginEnabled: off This result is the same for both servers. I ran with the '-h' option using each host name. Thanks, Dan ___ Freeipa-users

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Thu, Oct 7, 2010 at 11:47, Dan Scott danieljamessc...@gmail.com wrote: On Thu, Oct 7, 2010 at 11:32, James Roman james.ro...@ssaihq.com wrote:  On 10/07/2010 11:20 AM, Rich Megginson wrote: 20 is type or value exists - I think this means that it is attempting to set a referral

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 11:39, James Roman james.ro...@ssaihq.com wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan I've seen the initial problem where the memberof elements stop updating on my own FreeIPA v1

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 13:18, Rich Megginson rmegg...@redhat.com wrote: Dan Scott wrote: On Fri, Oct 8, 2010 at 11:39, James Roman james.ro...@ssaihq.com wrote: So does anyone have any more suggestions? Or should I just configure a new replica with new hostname and IP? Thanks, Dan

Re: [Freeipa-users] Replica not syncing 'memberOf' attributes

2010-10-08 Thread Dan Scott
On Fri, Oct 8, 2010 at 16:28, Nathan Kinder nkin...@redhat.com wrote: On 10/08/2010 12:08 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 14:52, James Romanjames.ro...@ssaihq.com  wrote:  On 10/08/2010 01:49 PM, Dan Scott wrote: On Fri, Oct 8, 2010 at 13:18, Rich Megginsonrmegg...@redhat.com

Re: [Freeipa-users] Upgraded server from Fedora 13 to 14: Cannot reset user passwords

2010-12-17 Thread Dan Scott
to address the issue as soon as possible, but we are short on time in this period. No problem, thanks for the response. For reference, the archived post with link to the SRPM is here: https://www.redhat.com/archives/freeipa-users/2010-December/msg00011.html Thanks, Dan

Re: [Freeipa-users] FreeIPA 1.2.2 Fedora 14 ldap problem

2010-12-22 Thread Dan Scott
Hi, I saw a similar problem with a recently installed VM. There was a problem with: /etc/nss_ldap.conf which didn't contain the correct configuration. I copied the config from: /etc/ldap.conf and the 'id' command started working correctly. Hope this helps, Dan On Wed, Dec 22, 2010 at 10:30

[Freeipa-users] Fedora 14 dirsrv service problems

2011-01-27 Thread Dan Scott
/init.d/dirsrv status to get things working again. Does anyone know how I can figure out what the problem is? I also have 2 Fedora 13 IPA FreeIPA servers which *don't* exhibit this problem. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com

Re: [Freeipa-users] Fedora 14 dirsrv service problems

2011-01-27 Thread Dan Scott
Hi, Thanks for the quick response On Thu, Jan 27, 2011 at 10:19, Rich Megginson rmegg...@redhat.com wrote: On 01/27/2011 07:47 AM, Dan Scott wrote: Hi, I have a FreeIPA server running on Fedora 14 [root@ohm ~]# rpm -qa|grep ipa-server ipa-server-selinux-1.2.2-5.fc14.x86_64 ipa

Re: [Freeipa-users] Migration from FreeIPA 1.2.1 to 2

2011-05-31 Thread Dan Scott
didn't find a bug report, but can file one if needed? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Migration from FreeIPA 1.2.1 to 2

2011-05-31 Thread Dan Scott
Done: https://fedorahosted.org/freeipa/ticket/1266 Dan On Tue, May 31, 2011 at 18:26, Dmitri Pal d...@redhat.com wrote: On 05/31/2011 06:02 PM, Dan Scott wrote: Hi, Thanks for all the replies. On Wed, May 25, 2011 at 18:13, Rob Crittenden rcrit...@redhat.com wrote: I have a FreeIPA 1.2.1

[Freeipa-users] Mac OSX 10.6 client configuration

2011-06-14 Thread Dan Scott
DHCP-supplied LDAP servers option is no longer available. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Mac OSX 10.6 client configuration

2011-06-15 Thread Dan Scott
Hi, On Tue, Jun 14, 2011 at 18:53, Doug Chapman prjctg...@gmail.com wrote: On Tue, Jun 14, 2011 at 2:25 PM, Dan Scott danieljamessc...@gmail.com wrote: I can't speak to your gid mapping issue, but Under Accounts - Login Options - Network Account Server, you can get access to the Directory

[Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at 11:20, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:06 -0400, Dan Scott wrote: Hi, I'm still running

Re: [Freeipa-users] Configuring a Fedora 15 client to connect to a FreeIPA 1.2 server

2011-06-21 Thread Dan Scott
On Tue, Jun 21, 2011 at 14:19, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:58 -0400, Dan Scott wrote: On Tue, Jun 21, 2011 at 11:37, Stephen Gallagher sgall...@redhat.com wrote: On Tue, 2011-06-21 at 11:31 -0400, Dan Scott wrote: Hi, On Tue, Jun 21, 2011 at 11

[Freeipa-users] Server installation problem

2011-06-24 Thread Dan Scott
conflicting with my existing FreeIPA 1.2.x servers elsewhere on the network? Thanks, Dan Scott 2011-06-24 13:33:04,752 DEBUG Loading StateFile from '/var/lib/ipa/sysrestore/sysrestore.state' 2011-06-24 13:33:04,753 DEBUG Loading Index file from '/var/lib/ipa/sysrestore/sysrestore.index' 2011-06-24 13

Re: [Freeipa-users] Server installation problem

2011-06-24 Thread Dan Scott
Hi, On Fri, Jun 24, 2011 at 14:00, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: I've just installed Fedora 15 onto a VM, configured networking and run the ipa-server-install script - the installation fails with the error: Configuring ntpd   [1/4]: stopping ntpd   [2/4

Re: [Freeipa-users] v1 to v2 migration problem: unknown object class radiusprofile and attribute memberofindirect not allowed

2011-06-27 Thread Dan Scott
the 60radius.ldif file to the FreeIPA 2.0 schema as suggested. Now, I'm getting groupname: attribute memberofindirect not allowed for all of my members. The groups all appear to migrate successfully. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users

[Freeipa-users] Migration to FreeIPA 2 - password update via LDAP

2011-09-07 Thread Dan Scott
Kerberos authentication which requires users to re-login on this special page? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Migration to FreeIPA 2 - password update via LDAP

2011-09-08 Thread Dan Scott
Hi, On Wed, Sep 7, 2011 at 14:59, Dmitri Pal d...@redhat.com wrote: On 09/07/2011 02:45 PM, Dan Scott wrote: I have a FreeIPA 1 system which is being migrated to FreeIPA 2. After migration, the script says: Passwords have been migrated in pre-hashed format. IPA is unable to generate

Re: [Freeipa-users] FreeIPA 2.1 - Authenticated LDAP search

2011-09-15 Thread Dan Scott
Yes, I'd rather do that, but I'm trying to authenticate a Java web application using the Glassfish application server. Glassfish has LDAP authentication built in, I'd have to write a Kerberos login module myself. Dan On Thu, Sep 15, 2011 at 03:28, Ondrej Valousek ondr...@s3group.cz wrote: I

[Freeipa-users] Cannot login to GDM

2011-09-23 Thread Dan Scott
the new ID? I've created a temporary ipausers-legacy group with ID 1002 to eliminate the error temporarily. I think that's it for now :) Thanks, Dan Scott http://danieljamesscott.org/ ___ Freeipa-users mailing list Freeipa-users@redhat.com https

Re: [Freeipa-users] Cannot login to GDM

2011-09-23 Thread Dan Scott
Hi, On Fri, Sep 23, 2011 at 13:57, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2011-09-23 at 13:38 -0400, Dan Scott wrote: Hi, I've recently upgraded from FreeIPA 1.2 to 2.1. Most things are working OK, but I have a few problems: 1. I'm unable to login to a new client machine via

[Freeipa-users] Problem when SSHing into FreeIPA client

2011-10-19 Thread Dan Scott
@pc35:~$ rpm -qa|grep freeipa-client\|sssd sssd-client-1.5.13-1.fc15.2.x86_64 freeipa-client-2.1.0-1.fc15.x86_64 sssd-1.5.13-1.fc15.2.x86_64 sssd-tools-1.5.13-1.fc15.2.x86_64 djscott@pc35:~$ Thanks, Dan secure Description: Binary data sssd.conf Description: Binary data

Re: [Freeipa-users] Problem when SSHing into FreeIPA client

2011-10-19 Thread Dan Scott
Hi, On Wed, Oct 19, 2011 at 16:43, Dmitri Pal d...@redhat.com wrote: On 10/19/2011 04:05 PM, Dan Scott wrote: Hi, I am having some problems when SSHing into my Fedora 15 client which is authenticated using FreeIPA djscott@pc35:~$ ssh admin@pc35 admin@pc35's password: id: cannot find

[Freeipa-users] LDAP search for email address of user in a particular group

2011-11-04 Thread Dan Scott
help me modify the above command so that I can find users, using their email address, who are also members of a particular group? Preferably using one command. Thanks, Dan Scott ___ Freeipa-users mailing list Freeipa-users@redhat.com https

Re: [Freeipa-users] LDAP search for email address of user in a particular group

2011-11-04 Thread Dan Scott
Hi, On Fri, Nov 4, 2011 at 17:38, Stephen Ingram sbing...@gmail.com wrote: On Fri, Nov 4, 2011 at 2:12 PM, Dan Scott danieljamessc...@gmail.com wrote: ldapsearch -b cn=users,cn=accounts,dc=example,dc=com ((mail=${email_address})(memberOf=cn=usergroup,cn=groups,dc=example,dc=com -x

Re: [Freeipa-users] LDAP search for email address of user in a particular group

2011-11-04 Thread Dan Scott
On Fri, Nov 4, 2011 at 19:07, Rich Megginson rmegg...@redhat.com wrote: On 11/04/2011 04:51 PM, Dan Scott wrote: Hi, On Fri, Nov 4, 2011 at 18:13, Rob Crittendenrcrit...@redhat.com  wrote: Dan Scott wrote: Hi, On Fri, Nov 4, 2011 at 17:38, Stephen Ingramsbing...@gmail.com  wrote

Re: [Freeipa-users] LDAP search for email address of user in a particular group

2011-11-07 Thread Dan Scott
On Mon, Nov 7, 2011 at 08:20, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2011-11-04 at 17:12 -0400, Dan Scott wrote: Hi, I've just migrated a couple of servers from FreeIPA 1.2 to 2.1. I'm almost done. I just have a few custom LDAP searches to migrate. With the old system, I

Re: [Freeipa-users] OpenSSH integration - known_hosts

2011-11-08 Thread Dan Scott
SSHing to a local PC and to check the other IPA server(s) if my SSH target is part of the other realm. Even better if it could do this without explicit configuration. Do you think it would be possible to do this securely? Dan On Tue, Nov 8, 2011 at 12:38, Jan Zelenı jzel...@redhat.com wrote: Hello

Re: [Freeipa-users] [Freeipa-devel] OpenSSH integration - known_hosts

2011-11-08 Thread Dan Scott
Hi, On Tue, Nov 8, 2011 at 18:35, Simo Sorce s...@redhat.com wrote: On Tue, 2011-11-08 at 17:57 -0500, Dmitri Pal wrote: On 11/08/2011 02:56 PM, Dan Scott wrote: Hi, This is a great feature. It feels like I'm always re-installing VMs and having to remove old SSH keys and re-accept new

[Freeipa-users] Fedora 16 failing to start dirsrv process

2011-11-14 Thread Dan Scott
state. The /var/log/dirsrv/slapd-EXAMPLE-COM/errors file contains no new entries since Friday 11th. Any ideas how I can get this fixed? How can I find out which 'file or directory' is missing? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users

Re: [Freeipa-users] Fedora 16 failing to start dirsrv process

2011-11-14 Thread Dan Scott
Hi, On Mon, Nov 14, 2011 at 10:19, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 14 Nov 2011, Dan Scott wrote: Hi, I've just upgraded a server from Fedora 15 to 16 and I'm having problems starting the dirsrv process: /var/log/messages Nov 14 09:38:27 fileserver1 ipactl[1351

Re: [Freeipa-users] Fedora 16 failing to start dirsrv process

2011-11-14 Thread Dan Scott
Hi, On Mon, Nov 14, 2011 at 13:06, Alexander Bokovoy aboko...@redhat.com wrote: On Mon, 14 Nov 2011, Dan Scott wrote: In any case, the process is still failing to start. Do I need to create a link in dirsrv.target.wants to somewhere? You need to do some steps like ipa-server-install does. I'm

Re: [Freeipa-users] Fedora 16 failing to start dirsrv process

2011-11-14 Thread Dan Scott
now though: djscott@pc35:~$ ipa host-del pc60 ipa: ERROR: Certificate operation cannot be completed: Unable to communicate with CMS (Not Found) Could this be related? Or should I start a new thread to try and solve it. Dan, could you please file a bug against freeipa in Fedora 16 to ask about

Re: [Freeipa-users] Reinstalling a host without deleting

2011-11-15 Thread Dan Scott
On Tue, Nov 15, 2011 at 16:06, Natxo Asenjo natxo.ase...@gmail.com wrote: On Tue, Nov 15, 2011 at 2:38 PM, Simo Sorce s...@redhat.com wrote: On Tue, 2011-11-15 at 08:33 -0500, Dan Scott wrote: Hi, On Tue, Nov 15, 2011 at 07:07, Natxo Asenjo natxo.ase...@gmail.com wrote: On Tue, Nov 15, 2011

Re: [Freeipa-users] Delete host: Unable to communicate with CMS (Not Found)

2011-11-16 Thread Dan Scott
On Wed, Nov 16, 2011 at 09:23, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I receive the following error when I try to remove a host from IPA: djscott@pc35:~$ ipa host-del pc60 ipa: ERROR: Certificate operation cannot be completed: Unable to communicate with CMS

Re: [Freeipa-users] Delete host: Unable to communicate with CMS (Not Found)

2011-11-17 Thread Dan Scott
On Wed, Nov 16, 2011 at 14:01, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: On Wed, Nov 16, 2011 at 10:39, Rob Crittendenrcrit...@redhat.com  wrote: Dan Scott wrote: On Wed, Nov 16, 2011 at 09:23, Rob Crittendenrcrit...@redhat.com  wrote: Dan Scott wrote: Hi, I receive

Re: [Freeipa-users] Delete host: Unable to communicate with CMS (Not Found)

2011-11-17 Thread Dan Scott
On Thu, Nov 17, 2011 at 11:25, Adam Young ayo...@redhat.com wrote: On 11/17/2011 10:58 AM, Dan Scott wrote: On Wed, Nov 16, 2011 at 14:01, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: On Wed, Nov 16, 2011 at 10:39, Rob Crittendenrcrit...@redhat.com  wrote: Dan Scott wrote

Re: [Freeipa-users] Delete host: Unable to communicate with CMS (Not Found)

2011-11-17 Thread Dan Scott
/symkey.jar Were all broken, pointing into /usr/lib/. Changing them to link to /usr/lib64 allowed pki to start properly and I can make changes to the host entry. It sounds like you have a fix for this in progress, or do I need to file a bug? Thanks, Dan

[Freeipa-users] CA replication

2011-12-08 Thread Dan Scott
, in start_creation method() File /usr/lib/python2.7/site-packages/ipaserver/install/cainstance.py, line 680, in __configure_instance raise RuntimeError('Configuration of CA failed') Anyone have any ideas? Thanks, Dan ___ Freeipa-users mailing list Freeipa

Re: [Freeipa-users] CA replication

2011-12-08 Thread Dan Scott
Hi, On Thu, Dec 8, 2011 at 13:29, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install replica-info-ohm.gpg It proceeds to configure the directory server for the CA, but fails when

Re: [Freeipa-users] CA replication

2011-12-09 Thread Dan Scott
Hi, On Fri, Dec 9, 2011 at 09:24, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, On Thu, Dec 8, 2011 at 13:29, Rob Crittendenrcrit...@redhat.com  wrote: Dan Scott wrote: Hi, I just tried to add a CA replica to my IPA replica (Both Fedora 15) using: ipa-ca-install

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-19 Thread Dan Scott
On Thu, Dec 15, 2011 at 11:51, Rich Megginson rmegg...@redhat.com wrote: On 12/15/2011 09:48 AM, Dan Scott wrote: Hi, On Thu, Dec 15, 2011 at 10:58, Rich Megginsonrmegg...@redhat.com  wrote: On 12/15/2011 08:41 AM, Dan Scott wrote: Hi, On my Fedora 15 FreeIPA server, I'm having some

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-19 Thread Dan Scott
On Mon, Dec 19, 2011 at 11:03, Rich Megginson rmegg...@redhat.com wrote: On 12/19/2011 09:01 AM, Dan Scott wrote: On Thu, Dec 15, 2011 at 11:51, Rich Megginsonrmegg...@redhat.com  wrote: On 12/15/2011 09:48 AM, Dan Scott wrote: Hi, On Thu, Dec 15, 2011 at 10:58, Rich Megginsonrmegg

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-19 Thread Dan Scott
On Mon, Dec 19, 2011 at 14:14, Simo Sorce s...@redhat.com wrote: On Mon, 2011-12-19 at 11:01 -0500, Dan Scott wrote: On Thu, Dec 15, 2011 at 11:51, Rich Megginson rmegg...@redhat.com wrote: On 12/15/2011 09:48 AM, Dan Scott wrote: Hi, On Thu, Dec 15, 2011 at 10:58, Rich Megginsonrmegg

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-21 Thread Dan Scott
On Mon, Dec 19, 2011 at 15:26, Dan Scott danieljamessc...@gmail.com wrote: On Mon, Dec 19, 2011 at 14:14, Simo Sorce s...@redhat.com wrote: On Mon, 2011-12-19 at 11:01 -0500, Dan Scott wrote: On Thu, Dec 15, 2011 at 11:51, Rich Megginson rmegg...@redhat.com wrote: On 12/15/2011 09:48 AM, Dan

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-22 Thread Dan Scott
On Thu, Dec 22, 2011 at 10:12, Simo Sorce s...@redhat.com wrote: On Wed, 2011-12-21 at 17:39 -0500, Dan Scott wrote: This is possible... oops. I tried a few times to add another replica (fileserver3) which failed as I mentioned above. The replication process got most of the way through

Re: [Freeipa-users] ns-slapd hang/segfault

2011-12-22 Thread Dan Scott
On Thu, Dec 22, 2011 at 12:10, Rich Megginson rmegg...@redhat.com wrote: On 12/22/2011 08:42 AM, Dan Scott wrote: On Thu, Dec 22, 2011 at 10:12, Simo Sorces...@redhat.com  wrote: On Wed, 2011-12-21 at 17:39 -0500, Dan Scott wrote: This is possible... oops. I tried a few times to add another

[Freeipa-users] FreeIPA 2.1.4 replication

2012-01-04 Thread Dan Scott
if that would help. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] FreeIPA 2.1.4 replication

2012-01-05 Thread Dan Scott
On Wed, Jan 4, 2012 at 13:48, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, Recently I've had some crash/hang problems with my FreeIPA 2 installation which appear solved using the updates-testing version of freeipa-server (2.1.4-2.fc16.x86_64) which I'm currently running

Re: [Freeipa-users] Fedora 16 client not getting group names

2012-01-27 Thread Dan Scott
Hi, On Fri, Jan 27, 2012 at 10:48, Stephen Gallagher sgall...@redhat.com wrote: On Fri, 2012-01-27 at 10:36 -0500, Dan Scott wrote: Hi, I have a Fedora 16 client running sssd-client-1.6.4-1.fc16.x86_64. When I run, e.g. id djscott, I do not get the names of the groups: -bash-4.2$ id

[Freeipa-users] Latest FreeIPA update causing problems

2012-02-16 Thread Dan Scott
. Can someone help? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Latest FreeIPA update causing problems

2012-02-16 Thread Dan Scott
Hi, On Thu, Feb 16, 2012 at 10:37, Rich Megginson rmegg...@redhat.com wrote: On 02/16/2012 08:26 AM, Dan Scott wrote: Hi, I have recently upgraded one of my FreeIPA servers (Fedora 16) with the latest package versions: Feb 15 14:10:19 Updated: libselinux-2.1.6-6.fc16.x86_64 Feb 15 14:10

Re: [Freeipa-users] Latest FreeIPA update causing problems

2012-02-16 Thread Dan Scott
Hi, On Thu, Feb 16, 2012 at 11:56, Rich Megginson rmegg...@redhat.com wrote: On 02/16/2012 09:12 AM, Dan Scott wrote: Hi, On Thu, Feb 16, 2012 at 10:37, Rich Megginsonrmegg...@redhat.com  wrote: On 02/16/2012 08:26 AM, Dan Scott wrote: Hi, I have recently upgraded one of my FreeIPA

Re: [Freeipa-users] Latest FreeIPA update causing problems

2012-02-16 Thread Dan Scott
On Thu, Feb 16, 2012 at 14:24, Rich Megginson rmegg...@redhat.com wrote: On 02/16/2012 10:40 AM, Dan Scott wrote: Hi, On Thu, Feb 16, 2012 at 11:56, Rich Megginsonrmegg...@redhat.com  wrote: On 02/16/2012 09:12 AM, Dan Scott wrote: Hi, On Thu, Feb 16, 2012 at 10:37, Rich Megginsonrmegg

[Freeipa-users] Replica install problem

2012-02-24 Thread Dan Scott
=com is going offline; disabling replication Any ideas? Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] Feature request

2012-02-24 Thread Dan Scott
, perform an LDAP lookup, the CA is working, etc. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Feature request

2012-02-24 Thread Dan Scott
On Fri, Feb 24, 2012 at 13:43, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I have an idea for a new feature. I've been having a lot of problems with replication recently and I think the following would be useful. Can we show the replication status of the masters/replicas

Re: [Freeipa-users] Replica install problem

2012-02-24 Thread Dan Scott
On Fri, Feb 24, 2012 at 15:47, Rich Megginson rmegg...@redhat.com wrote: On 02/24/2012 09:45 AM, Dan Scott wrote: Hi, I have another replica install problem. I ran into some issues a couple of weeks ago when 389-ds-base-1.2.10-0.10.rc1.fc16.x86_64 was released. My master server is running

[Freeipa-users] CA replica installation failure

2012-02-27 Thread Dan Scott
have to completely remove and re-install the entire IPA replica? i.e. Is there something like ipa-ca-install --uninstall I couldn't see the option anywhere. Thanks, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman

Re: [Freeipa-users] CA replica installation failure

2012-02-29 Thread Dan Scott
Anyone have any suggestions for how I can fix this? Dan On Mon, Feb 27, 2012 at 21:06, Dan Scott danieljamessc...@gmail.com wrote: Hi, I'm having another problem with replica installation - just the CA this time It looks like there's a problem with SELinux and the pki-ca service: After

Re: [Freeipa-users] CA replica installation failure

2012-02-29 Thread Dan Scott
pki_ca_port_t tcp 9180, 9701, 9443-9447 944[456] don't match, but they're in the range, so they should be OK, right? Is it really an error? Or is it just indicating that the port has already been set. Thanks, Dan Its probably best to completely remove the replica. You could try use

Re: [Freeipa-users] CA replica installation failure

2012-03-01 Thread Dan Scott
Hi, I tried with SELinux in permissive mode. It failed in the same way. Dan On Wed, Feb 29, 2012 at 16:28, Ade Lee a...@redhat.com wrote: Its a little strange that its showing up as an error -- it shouldn't if they are already set and they are of the right context. That said, its not really

[Freeipa-users] Another CA replica install issue

2012-03-26 Thread Dan Scott
=system_u:object_r:ephemeral_port_t:s0 tclass=tcp_socket But the install still failed in the same way after I put SELinux into enforcing mode. Thanks, Dan Scott ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo

Re: [Freeipa-users] Another CA replica install issue

2012-03-26 Thread Dan Scott
On Mon, Mar 26, 2012 at 15:53, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I'm having another replica CA install issue. Fedora 16 with latest updates applied this morning: ipa-ca-install replica-info-fileserver4.example.com.gpg [snip] Configuring certificate server

Re: [Freeipa-users] Another CA replica install issue

2012-03-28 Thread Dan Scott
Can anyone help with this? Thanks, Dan On Mon, Mar 26, 2012 at 16:17, Dan Scott danieljamessc...@gmail.com wrote: On Mon, Mar 26, 2012 at 15:53, Rob Crittenden rcrit...@redhat.com wrote: Dan Scott wrote: Hi, I'm having another replica CA install issue. Fedora 16 with latest updates

[Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
, Dan ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 13:43, Rich Megginson rmegg...@redhat.com wrote: On 04/13/2012 11:39 AM, Dan Scott wrote: I'm convinced that my LDAP directories contain lots of cruft which has built up and is causing problems on my system. There may even be some corruption since there's an entry which

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
or so for the past few months - I was beginning to think that it was beyond repair! :) On Fri, Apr 13, 2012 at 14:38, Rich Megginson rmegg...@redhat.com wrote: On 04/13/2012 12:22 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 13:43, Rich Megginsonrmegg...@redhat.com  wrote: On 04/13/2012 11:39 AM

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 15:24, Rich Megginson rmegg...@redhat.com wrote: On 04/13/2012 01:03 PM, Dan Scott wrote: If I'm interpreting this correctly, it can't be deleted because it's not a leaf node, but it doesn't have any sub-entries that I can delete first. You are correct.  Try

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-13 Thread Dan Scott
On Fri, Apr 13, 2012 at 16:41, Rich Megginson rmegg...@redhat.com wrote: On 04/13/2012 02:30 PM, Dan Scott wrote: On Fri, Apr 13, 2012 at 15:24, Rich Megginsonrmegg...@redhat.com  wrote: It's not a problem until it's a problem :-)  I would go ahead and run CLEANRUV. I cleaned up a load

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Dan Scott
On Fri, Apr 13, 2012 at 17:44, Rich Megginson rmegg...@redhat.com wrote: On 04/13/2012 03:40 PM, Dan Scott wrote: I cleaned up all the ruv_compare_ruv: RUV [changelog max RUV] does not contain element errors in the logs for each of fileservers 1, 2 and 3. The ldapsearch for '((nsuniqueid

Re: [Freeipa-users] General status of my FreeIPA servers - is there a method for cleaning them?

2012-04-17 Thread Dan Scott
On Tue, Apr 17, 2012 at 09:26, Rich Megginson rmegg...@redhat.com wrote: On 04/17/2012 07:26 AM, Dan Scott wrote: On Fri, Apr 13, 2012 at 17:44, Rich Megginsonrmegg...@redhat.com  wrote: On 04/13/2012 03:40 PM, Dan Scott wrote: I cleaned up all the ruv_compare_ruv: RUV [changelog max RUV

  1   2   >