Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Matt .
Hi Alexander, This doc is really great. I have added the delegation target but we still get an err=50 on when running our add_user script on the webserver. On the IPA server we see a keytab file configured in the php.ini and on the webserver we don't. Configs are quite the same here actually.

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Alexander Bokovoy
On Tue, 30 Jul 2013, Matt . wrote: Hi Alexander, This doc is really great. I have added the delegation target but we still get an err=50 on when running our add_user script on the webserver. On the IPA server we see a keytab file configured in the php.ini and on the webserver we don't.

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Dmitri Pal
On 07/29/2013 03:02 PM, Alexander Bokovoy wrote: Hi! On Mon, 29 Jul 2013, Matt . wrote: Hi Alexander, That is great! I hope that someone can find this topic and use it as reference as it tool us some time to find the other one :) You can find my blog post here:

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Matt .
Hi Dimitri, It's a good tuturial but I'm kinda stuck (and new to that part) What we seem to need is: A - B - C - D A= user(running one) B= Webserver C=IPAserver D= LDAP on IPAserver I thought we didn't need the C - D part because this is what IPA does. We actually need the A - B - C part

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Dmitri Pal
On 07/30/2013 08:17 AM, Matt . wrote: Hi Dimitri, It's a good tuturial but I'm kinda stuck (and new to that part) What we seem to need is: A - B - C - D A= user(running one) B= Webserver C=IPAserver D= LDAP on IPAserver I thought we didn't need the C - D part because this is what IPA

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Alexander Bokovoy
On Tue, 30 Jul 2013, Dmitri Pal wrote: On 07/30/2013 08:17 AM, Matt . wrote: Hi Dimitri, It's a good tuturial but I'm kinda stuck (and new to that part) What we seem to need is: A - B - C - D A= user(running one) B= Webserver C=IPAserver D= LDAP on IPAserver I thought we didn't need the C -

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-30 Thread Martin Kosek
On 07/30/2013 05:52 PM, Alexander Bokovoy wrote: On Tue, 30 Jul 2013, Dmitri Pal wrote: On 07/30/2013 08:17 AM, Matt . wrote: Hi Dimitri, It's a good tuturial but I'm kinda stuck (and new to that part) What we seem to need is: A - B - C - D A= user(running one) B= Webserver C=IPAserver

[Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-29 Thread Matt .
Hi all, Refering to this topic: https://www.redhat.com/archives/freeipa-users/2013-July/msg00318.html We are no able to do a show_user from a webserver on an IPA server, but user_add gives a problem in rights. On the IPA server there is added to the services:

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-29 Thread Alexander Bokovoy
Hi Matt, On Mon, 29 Jul 2013, Matt . wrote: Hi all, Refering to this topic: https://www.redhat.com/archives/freeipa-users/2013-July/msg00318.html We are no able to do a show_user from a webserver on an IPA server, but user_add gives a problem in rights. On the IPA server there is added to

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-29 Thread Matt .
Hi Alexander, That is great! I hope that someone can find this topic and use it as reference as it tool us some time to find the other one :) Thanks! Cheers, Matt 2013/7/29 Alexander Bokovoy aboko...@redhat.com Hi Matt, On Mon, 29 Jul 2013, Matt . wrote: Hi all, Refering to this

Re: [Freeipa-users] User_show works from webserver, user_add ipa: ERROR: Insufficient access

2013-07-29 Thread Alexander Bokovoy
Hi! On Mon, 29 Jul 2013, Matt . wrote: Hi Alexander, That is great! I hope that someone can find this topic and use it as reference as it tool us some time to find the other one :) You can find my blog post here: http://vda.li/en/posts/2013/07/29/Setting-up-S4U2Proxy-with-FreeIPA/index.html