Re: [Freeipa-users] Firewalling IPA 2

2012-02-01 Thread Steven Jones
Hi Thanks, useful tip..though I assume most sites will also use DNS and NTP regards Steven Jones Technical Specialist - Linux RHCE Victoria University, Wellington, NZ 0064 4 463 6272 8><- In terms of your firewall rules, you only want to allow access on port 389 for your hos

Re: [Freeipa-users] Firewalling IPA 2

2012-02-01 Thread Simo Sorce
On Wed, 2012-02-01 at 07:33 -0500, Stephen Gallagher wrote: > On Wed, 2012-02-01 at 07:56 +0100, Jakub Hrozek wrote: > > On Wed, Feb 01, 2012 at 03:31:15PM +1100, Craig T wrote: > Hi, > > I'd > > like to restict which hosts have access to port 389 on the IPA server. > > > How does SSSD connect to

Re: [Freeipa-users] Firewalling IPA 2

2012-02-01 Thread Stephen Gallagher
On Wed, 2012-02-01 at 07:56 +0100, Jakub Hrozek wrote: > On Wed, Feb 01, 2012 at 03:31:15PM +1100, Craig T wrote: > Hi, > > I'd > like to restict which hosts have access to port 389 on the IPA server. > > How does SSSD connect to the IPA 2.x server for user name queries? I > half expected it to ne

Re: [Freeipa-users] Firewalling IPA 2

2012-01-31 Thread Jakub Hrozek
On Wed, Feb 01, 2012 at 03:31:15PM +1100, Craig T wrote: > Hi, > > I'd like to restict which hosts have access to port 389 on the IPA server. > How does SSSD connect to the IPA 2.x server for user name queries? I half > expected it to need port 389 or 636 open on the server, but my testing is >