[Freeipa-users] Possible to fully proxy AD <-> FreeIPA?

2017-03-22 Thread Dan Dietterich
I am trying to understand if it is possible to NAT between a network running Active Directory (AD) and a network running FreeIPA and have one-way trust from FreeIPA to the AD. My hypothesis is that it is not possible, for two reasons. First, I understand that Kerberos uses several techniques (i

[Freeipa-users] DNSSEC warning when DNSSEC should be disabled

2017-04-13 Thread Dan Dietterich
I am seeing inconsistent results configuring a DNS forward zone. At a bash prompt, as root, after kinit admin, I do: ipa dnsforwardzone-add domain.internal --forwarder= ww.xx.yy.zz --forward-policy=only That works fine and does not warn about DNSSEC. In a Java webapp running as root under a Je

Re: [Freeipa-users] DNSSEC warning when DNSSEC should be disabled

2017-04-19 Thread Dan Dietterich
-enabled and dnssec-validation are set to 'no' in the /etc/named.conf. So I'm confused that you say the DNSSEC should always fail. Thanks for your help! From: Martin Bašti Date: Wednesday, April 19, 2017 at 3:59 AM To: Dan Dietterich , "freeipa-users@redhat.com" Subject: R

Re: [Freeipa-users] DNSSEC warning when DNSSEC should be disabled

2017-04-24 Thread Dan Dietterich
r a subprocess of my Java webapp ALWAYS gets the warning regardless. If there really should be a warning, then why don't I see it from the CLI? And can you help me understand what would be significantly different between an interactive login and a "su –l root" in salt? Thank you fo

[Freeipa-users] Timing behavior on access to AD groups

2017-05-12 Thread Dan Dietterich
I have noticed this behavior when setting up an external AD group: 1. create trust 2. create external group 3. add Group@Domain to external group - FAILS: "trusted domain object not found" 4. retry: add Group@Domain to external group - SUCCESS Two questions: 1.

[Freeipa-users] Confused: LDAP authentication of AD users

2017-05-16 Thread Dan Dietterich
With a one-way trust from FreeIPA 4.4 to Active Directory on WinServ2012r2, I am trying to use FreeIPA LDAP for user authentication. Is that supposed to work? -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://free