[Freeipa-users] IPA Error 4301: CertificateOperationError

2016-08-22 Thread Z D
Hello, There is the error on ver 4.2 while viewing certs: "IPA Error 4301: CertificateOperationError", next it read " Certificate operation cannot be completed: Unable to communicate with CMS ([Errno 113] No route to host)". I suspect you'll be asking for below two commands, here are results.

[Freeipa-users] The 3rd party cert for IPA Web GUI

2016-08-23 Thread Z D
Hi there, is it possible to have a cert (say from VeriSign) for a IPA host and use it for httpd (Web GUI), without breaking anything else? I've acquired one and added it to nssdb (/etc/httpd/alias). # certutil -L -d /etc/httpd/alias Certificate Nickname

Re: [Freeipa-users] Automount location design

2017-03-24 Thread Z D
OS is EL7.3 and ipa-serveris 4.4.0 From: Z D Sent: Friday, March 24, 2017 2:23:59 PM To: freeipa-users@redhat.com Subject: Automount location design Hi there, We've been looking to add indirect maps for users home directories, and did the next. 1

[Freeipa-users] Automount location design

2017-03-24 Thread Z D
Hi there, We've been looking to add indirect maps for users home directories, and did the next. 1. There is the automount location (named "global") with one map "auto_home", it has keys (they are username) and mount info is :/path 2. The idea is that this is "global location" 3. Another

[Freeipa-users] IPA domain level is 1, so replica prepare fails (new installation)

2017-03-21 Thread Z D
Hallo, I have a problem to prepare the replica. Environment: OS: Newly installed EL7.3 IPA Server: Newly installed ipa-server 4.4.0 The error: # ipa-replica-prepare Replica creation using 'ipa-replica-prepare' to generate replica file is supported only in 0-level IPA domain. The current IPA

Re: [Freeipa-users] IPA domain level is 1, so replica prepare fails (new installation)

2017-03-22 Thread Z D
Thank you David. From: David Kupka <dku...@redhat.com> Sent: Wednesday, March 22, 2017 12:06 AM To: Z D Cc: freeipa-users@redhat.com Subject: Re: [Freeipa-users] IPA domain level is 1, so replica prepare fails (new installation) On Wed, Mar 22, 2017 at

[Freeipa-users] EL5 sudo and IdM

2017-05-01 Thread Z D
Hi, we've been using the IdM server 4.4.0 but still have some EL5 (build system) we'd like to be ipa-clients. The ipa-client v2.1.3 has been installed, that works well. And I believe that with EL5, there is no sssd support for sudo, hence it's configured via /etc/ldap.conf The situation I