[Freeipa-users] Best practices on securing freeipa

2016-06-14 Thread Danila Ladner
Greetings Folks. I could not find any information on best practices of securing free ipa servers and its replicas. Since the hosts become an important part of IT IM infrastructure, wanted to see if anyone can point me to the right sources beyond default configuration. Thank you, Danila -- Manage y

Re: [Freeipa-users] Freeipa and spacewalk integration.

2016-06-30 Thread Danila Ladner
Thank you for reaching out. The problem has been fixed. I have forgotten to restart tomcat6 to disable tomcat auth. User error!!! On Thu, Jun 30, 2016 at 6:09 AM, Jan Pazdziora wrote: > On Wed, Jun 29, 2016 at 03:33:34PM -0400, Danila Ladner wrote: > > Hello Folks. > > > &g

[Freeipa-users] Best practices on enrolling existing hosts.

2016-06-30 Thread Danila Ladner
on what folks do in the implementation process. Thank you, Danila Ladner. -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Freeipa and sudo

2016-07-05 Thread Danila Ladner
What about /etc/nsswitch.conf? Does it have "sudo: files sss"? On Mon, Jul 4, 2016 at 3:50 AM, Tomas Simecek wrote: > Dear freeipa users/admins, > I'm trying to implement freeipa in our company, so that our Unix admins > can authenticate on Linux servers using their Windows AD account. > Followi

Re: [Freeipa-users] Freeipa and sudo

2016-07-06 Thread Danila Ladner
Yeah, please enable logging in [sudo] section of sssd. On Wed, Jul 6, 2016 at 11:03 AM, Jakub Hrozek wrote: > On Wed, Jul 06, 2016 at 03:22:34PM +0200, Tomas Simecek wrote: > > Hi Danila and other freeipa gurus, > > sorry for my late answer, there is a bank holiday in CZ and I am off work > > th

Re: [Freeipa-users] sudo - differences between Centos 6.5 and Centos 7.0?

2016-07-13 Thread Danila Ladner
Update to this one: It has been running smoothly on 6.5 [root@dev-zlei.sec1 ~]# cat /etc/redhat-release CentOS release 6.5 (Final) [root@dev-zlei.sec1 ~]# rpm -qa | grep sssd sssd-client-1.12.4-47.el6.x86_64 sssd-ldap-1.12.4-47.el6.x86_64 sssd-ad-1.12.4-47.el6.x86_64 python-sssdconfig-1.12.4-47.e