Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Natxo Asenjo
On Fri, Apr 19, 2013 at 1:08 PM, Sumit Bose wrote: > On Fri, Apr 19, 2013 at 12:47:47PM +0200, Natxo Asenjo wrote: > > hi, > > > > just a little 'but'. > > > > when verifying the trust (point 12 > > > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Mana

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Sumit Bose
On Fri, Apr 19, 2013 at 12:47:47PM +0200, Natxo Asenjo wrote: > hi, > > just a little 'but'. > > when verifying the trust (point 12 > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/trust-diff-dns-domains.html) > > > # kinit user > Pa

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Sumit Bose
On Fri, Apr 19, 2013 at 12:37:30PM +0200, Natxo Asenjo wrote: > I modified /etc/sysconfig/network > HOSTNAME=kdc.ipa.asenjo.nx > > rebooted the host. Re-ran > > # smbclient -L kdc.ipa.asenjo.nx -klp_load_ex: changing to config backend > registry > Domain=[IPA] OS=[Unix] Server=[Samba 4.0.0rc4] >

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Natxo Asenjo
hi, just a little 'but'. when verifying the trust (point 12 https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/trust-diff-dns-domains.html) # kinit user Password for nase...@ipa.asenjo.nx: [root@kdc ~]# kvno host/host.ipa.asenjo...@ipa.a

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Natxo Asenjo
I modified /etc/sysconfig/network HOSTNAME=kdc.ipa.asenjo.nx rebooted the host. Re-ran # smbclient -L kdc.ipa.asenjo.nx -klp_load_ex: changing to config backend registry Domain=[IPA] OS=[Unix] Server=[Samba 4.0.0rc4] Sharename Type Comment - ---

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Sumit Bose
On Fri, Apr 19, 2013 at 11:45:47AM +0200, Natxo Asenjo wrote: > I saw there is a log in /var/log/samba/log.wb-IPA > > The log complains about missing keys for the spn for the hostname (not the > fqdn, just the hostname): > > Connection to LDAP server failed for the 15 try! > [2013/04/19 11:39:22

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Natxo Asenjo
I saw there is a log in /var/log/samba/log.wb-IPA The log complains about missing keys for the spn for the hostname (not the fqdn, just the hostname): Connection to LDAP server failed for the 15 try! [2013/04/19 11:39:22.352522, 0] ipa_sam.c:3689(bind_callback_cleanup) kerberos error: code=-1

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Natxo Asenjo
On Fri, Apr 19, 2013 at 11:27 AM, Sumit Bose wrote: > On Fri, Apr 19, 2013 at 11:03:02AM +0200, Natxo Asenjo wrote: > > hi, > > > > while following the instructions in > > > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/trust-diff-dns

Re: [Freeipa-users] problems with trust with AD (2 different domains

2013-04-19 Thread Sumit Bose
On Fri, Apr 19, 2013 at 11:03:02AM +0200, Natxo Asenjo wrote: > hi, > > while following the instructions in > https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Identity_Management_Guide/trust-diff-dns-domains.html > > I run step 9: > > smbclient -L kdc.ipa.asenjo