[Freeipa-users] TLS: hostname does not match CN in peer certificate

2011-06-23 Thread Pieter Baele
Probably, this question is been asked before I try to register an IPA client but get the following error. (primary kerberos are AD hosts, so I use --server etc) What can be wrong? The necessary firewall ports are opened ipa-client-install --server testclient03 --domain example.org root

Re: [Freeipa-users] TLS: hostname does not match CN in peer certificate

2011-06-23 Thread Pieter Baele
Solved. --server also needs FQDN I've to think twice before posting ;-) ___ Freeipa-users mailing list Freeipa-users@redhat.com https://www.redhat.com/mailman/listinfo/freeipa-users

[Freeipa-users] kinit working, but ipa-client-install not (client not found)

2011-06-23 Thread Pieter Baele
My new freeipa installation is working (server + kinit on a host where I configured krb5.conf manually) but ipa-client-install gives the typical Kerberos error: kinit: Client not found in Kerberos database while getting initial credentials Both hosts are resolvable __

Re: [Freeipa-users] kinit working, but ipa-client-install not (client not found)

2011-06-24 Thread Pieter Baele
On Thu, Jun 23, 2011 at 19:59, Rob Crittenden wrote: > Pieter Baele wrote: >> >> My new freeipa installation is working (server + kinit on a host where >> I configured krb5.conf manually) >> but ipa-client-install gives the typical Kerberos error: >> >&

[Freeipa-users] Migrate from SunONE DS5.2 - UnicodeDecodeError

2012-09-20 Thread Pieter Baele
Hi, I have a known problem when using the migration tool. Is there already a solution for this? As in: https://www.redhat.com/archives/freeipa-users/2012-January/msg00200.html ipa migrate-ds ldap://x.x.x.x:389 --base-dn=xxx --group-container=ou=People --continue Password: ipa: ERROR: an internal

Re: [Freeipa-users] Migrate from SunONE DS5.2 - UnicodeDecodeError

2012-09-21 Thread Pieter Baele
On Thu, Sep 20, 2012 at 3:49 PM, Martin Kosek wrote: > Since an Internal error was returned, there should at least be a traceback in > /var/log/httpd/error_log. This should help us narrow down the root cause of > this issue. > > Martin > Oops, I only sent to Rob. So that's temporarily cop

[Freeipa-users] FreeIPA 3 rc1 sslget error

2012-09-27 Thread Pieter Baele
Hi, Two problems with FreeIPA 3 on an updated fedora 17 (updates-testing enabled) 1) dependency error for libsss_sudo Error: Package: sudo-1.8.3p1-7.fc17.x86_64 (@updates) Requires: libsss_sudo.so.0(EXPORTED)(64bit) Removing: libsss_sudo-1.8.4-14.fc17.x86_64 (@updates)

[Freeipa-users] FreeIPA integration within enterprise AD domain - ca sub or root?

2017-04-28 Thread Pieter Baele
conclude: own rootCA, or subordinate CA signed by the existing MS Certificate Services PKI Sincerely, Pieter Baele -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project