[Freeipa-users] Password change rights

2016-09-02 Thread Mike Driscoll
Hello. I want to script the new user creation process. I read in section 9.4 that "any user who has password change rights can change a password and no password policies are applied, but the other user must reset the password at the next login.” I want to create an account with this limited

[Freeipa-users] Server replication stopped working

2016-09-23 Thread Mike Driscoll
Hello. I have four IPA servers replicating in full mesh. All four servers are running ipa-server-4.2.0-15.0.1.el7_2.19.x86_64. This was working for some time but now I see that no replication is occurring automatically at present. When I update a user attribute on an IPA server, I see errors

[Freeipa-users] DNS search timeouts and incomplete results

2016-11-28 Thread Mike Driscoll
I'm running: # rpm -qa | grep ipa-server ipa-server-4.4.0-12.0.1.el7.x86_64 ipa-server-dns-4.4.0-12.0.1.el7.noarch ipa-server-common-4.4.0-12.0.1.el7.noarch Searching DNS for all hostnames containing "qa" times out in the GUI. Setting aside the option to change server defaults, this cli command

Re: [Freeipa-users] DNS search timeouts and incomplete results

2016-12-13 Thread Mike Driscoll
LDAP side. To verify, check > > ldapsearch -D 'cn=directory manager' -W -b cn=config cn=config | grep > nsslapd-sizelimit > > If you really need to increase this size limit, you will have to modify the > nsslapd-sizelimit in cn=config. > > """ > > M

[Freeipa-users] DNS search timeouts and incomplete results

2016-12-13 Thread Mike Driscoll
Any thoughts about this sizelimit bug? Mike > On Nov 28, 2016, at 14:44, Mike Driscoll <mike.drisc...@oracle.com> wrote: > > I'm running: > # rpm -qa | grep ipa-server > ipa-server-4.4.0-12.0.1.el7.x86_64 > ipa-server-dns-4.4.0-12.0.1.el7.noarch > ipa-server-com