[Freeipa-users] Stuck at DNS install process

2016-11-03 Thread Raul Dias
Hello, I am trying to setup a test environment for FreeIPA. I have installed Fedora Server 24 in a VMWare Workstation machine and updated it. There are 2 ethernets: 1 - ens33 -> bridge to the host (dhcp) 2 - ens34 -> Internal (vmware) network for testing the ens34 has: 3: ens34: mtu 1500

Re: [Freeipa-users] Stuck at DNS install process

2016-11-03 Thread Raul Dias
Yes. It worked! Thanks. -rsd On 03/11/2016 12:12, Martin Basti wrote: On 03.11.2016 14:48, Raul Dias wrote: Hello, I am trying to setup a test environment for FreeIPA. I have installed Fedora Server 24 in a VMWare Workstation machine and updated it. There are 2 ethernets: 1 - ens33

[Freeipa-users] FreeIPA + DHCP-LDAP - Fedora 24 - broken

2016-11-05 Thread Raul Dias
Hello, It seems that DHCP with LDAP on Fedora 24 (FreeIPA) is broken. Can anyone confirm? Doing an strace -e trace=network does not show any attempt to connect to the ldap server. OTOH, the same config on a Ubuntu 16.10 works fine. -rsd -- Manage your subscription for the Freeipa-users mai

Re: [Freeipa-users] FreeIPA + DHCP-LDAP - Fedora 24 - broken

2016-11-07 Thread Raul Dias
thoritative Using the same config on a ubuntu host, it works fine, which makes me wonder that dhcpd in Fedora 24 does not work at all with LDAP. Or maybe this is a reflection of some FreeIPA server way of life configuration, like sssd. -rsd On 07/11/2016 05:10, Petr Spacek wrote: On 6.11.2

Re: [Freeipa-users] FreeIPA + DHCP-LDAP - Fedora 24 - broken

2016-11-09 Thread Raul Dias
Do you mean that dhcpd on Ubuntu is configured against the very same FreeIPA server? yes. Testing both on VMs with a private network. Are you sure that dhcpd is using the same credentials to BIND to LDAP? There might be an access control issue if different hosts use different credentials or s

[Freeipa-users] IPA DNS Server and DNSMasq

2016-12-05 Thread Raul Dias
eries are fine (with answers). If I explicit change nameserver to ipa IP, the queries are fine. So, the problem is between dnsmasq and ipa bind. Has anyone seen anything like this? This is a Ubuntu 16.10 not a member of the ipa. -rsd -- Att. Raul Dias -- Manage your subscription fo

[Freeipa-users] Windows Server can't use FreeIPA's DNS server

2017-01-14 Thread Raul Dias
Hello, I am migrating a network to FreeIPA. LDAP, NFS, no Active Directory. A Windows Server 2008 R2, cannot use FreeIPAs bind to resolve DNS query. This server works fine with my old bind server, google's dns server (8.8.8.8), but not FreeIPA's. Using wireshark, I can see the the response gets

Re: [Freeipa-users] Windows Server can't use FreeIPA's DNS server

2017-01-15 Thread Raul Dias
as an plain DNS server. Note that there is another windows server (2008) that works fine. This one is 2008 r2 (if it matters). Is the IPA server hostname/domain name the same as a previous windows host? If so that is probably not good. On Sat, Jan 14, 2017 at 12:01 PM, Raul Dias <mailt

Re: [Freeipa-users] Windows Server can't use FreeIPA's DNS server

2017-01-15 Thread Raul Dias
On 15/01/2017 19:15, Brian Candler wrote: On FreeIPA host: tcpdump -i eth0 -nnv -s0 port 53 and host x.x.x.x where x.x.x.x is IP address of the 2008R2 server, and assuming eth0 is the NIC. See if any DNS queries arrive at the FreeIPA server. If no: then the problem is with the 2008R2 serve

Re: [Freeipa-users] Windows Server can't use FreeIPA's DNS server

2017-01-16 Thread Raul Dias
) Time to live: 172792 Data length: 4 Address: 216.239.38.10 -rsd On 16/01/2017 06:31, Brian Candler wrote: On 16/01/2017 00:52, Raul Dias wrote: The packets are getting back That has being stablished already. With Wireshark at the 2008R2 end? I am looking for

Re: [Freeipa-users] Windows Server can't use FreeIPA's DNS server

2017-01-16 Thread Raul Dias
Ok, Found the issue. I believe it is a Fedora (25) issue, but not sure yet. So, registering here for the archives. My IPA is on a FC25 on a LXC container (2.0.6) on a Jessie host. The IPA container ethernet is on a private bridge (not attached to any real one). The FC container was confi

[Freeipa-users] client in many IPA domains

2017-02-03 Thread Raul Dias
Hello, Can ipa-client (e.g., anotebook) be in more than one realm? e.g. depending on the network where it is connected. -rsd -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the pro

[Freeipa-users] Bind Journal errors

2017-02-15 Thread Raul Dias
Hello, My IPA's named daemon start to show this dyndb journal logs: error: malformed transaction: dyndb-ldap/ipa/master/17.10.10.in-addr.arpa/raw.jnl last serial 1484327694 != transaction first serial 1484327693 restarting it did not help. What should I do? Thanks -rsd -- Manage your s