Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-27 Thread Simo Sorce
On Wed, 2013-11-27 at 15:24 +1000, Matt Bryant wrote: Hmm just upgraded to 3 so thought I woudl give it a go ... but (aint there always one of those :() can't seem to add the principle .. kadmin.local: add_principal krbtgt/OLD-REALM@IPA-REALM WARNING: no policy specified for

Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-27 Thread Matt Bryant
Simo, Have added the following into bugzilla .. Bug 1035494 https://bugzilla.redhat.com/show_bug.cgi?id=1035494 has been added to the database seems strange but whilst listprincs/getprinc works getpols and the addprinc (at least in this use case) doesnt... ie kadmin.local: add_principal

Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-27 Thread Simo Sorce
On Thu, 2013-11-28 at 08:29 +1000, Matt Bryant wrote: Simo, Have added the following into bugzilla .. Bug 1035494 has been added to the database seems strange but whilst listprincs/getprinc works getpols and the addprinc (at least in this use case) doesnt... addprinc not working for

Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-27 Thread Matt Bryant
Simo, Thanks for that .. using that switch the principle is now created on to see it it works as expected .. rgds Matt B. On 11/28/2013 09:10 AM, Simo Sorce wrote: On Thu, 2013-11-28 at 08:29 +1000, Matt Bryant wrote: Simo, Have added the following into bugzilla .. Bug 1035494 has been

[Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-26 Thread Matt Bryant
All, Is there any documentation anywhere that describes whether this can be done and how to do it ?? Would like to set up a one way trust between a new IPA realm and a legacy kerberos realm. The doco explicitly says dont use kadmin/kadmin.local so not sure how to get the

Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-26 Thread Rob Crittenden
Matt Bryant wrote: All, Is there any documentation anywhere that describes whether this can be done and how to do it ?? Would like to set up a one way trust between a new IPA realm and a legacy kerberos realm. The doco explicitly says dont use kadmin/kadmin.local so not sure how to get the

Re: [Freeipa-users] Trust between IPA and another MIT Kerberos Realm

2013-11-26 Thread Matt Bryant
Hmm just upgraded to 3 so thought I woudl give it a go ... but (aint there always one of those :() can't seem to add the principle .. kadmin.local: add_principal krbtgt/OLD-REALM@IPA-REALM WARNING: no policy specified for krbtgt/OLD-REALM@IPA-REALM; defaulting to no policy Enter password for