Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-16 Thread DiOrio, Max
t: Thursday, March 15, 2018 6:39:19 PM Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication It seems like it would be trivial to add quick logic that if the user creation is coming from PAM, to automatically “check the box” for Use PAM in the database. Manually having t

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-16 Thread Alexandru Raceanu
:40 AM To: spacewalk-list@redhat.com Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Well... That part doesn't work at the moment as far as I can see and never managed to get it working on SW 2.5/2.6/2.7. I've already opened a bug report over

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-15 Thread DiOrio, Max
t;mailto:spacewalk-list@redhat.com> Sent: Wednesday, March 14, 2018 9:52:15 PM Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Sorry – one more issue I’m running into. Looks like anything that communicates via XMLPRC can’t authenticate. # spacewalk-channel --add -

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-15 Thread Alexandru Raceanu
y input on this part, feel free to comment, i'm also interested in fixing this. /Alex From: "DiOrio, Max" To: spacewalk-list@redhat.com Sent: Wednesday, March 14, 2018 9:52:15 PM Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Sorry – one mo

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-15 Thread DiOrio, Max
spacewalk-list-boun...@redhat.com<mailto:spacewalk-list-boun...@redhat.com> [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of DiOrio, Max Sent: Tuesday, March 13, 2018 2:35 PM To: spacewalk-list@redhat.com<mailto:spacewalk-list@redhat.com> Subject: Re: [Spacewalk-list] Spacewalk and AD/SSS

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-15 Thread DiOrio, Max
March 13, 2018 2:35 PM To: spacewalk-list@redhat.com Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Got it! Had to uncomment the following line in lookup_identity.conf # LookupUserGroupsIter AJP_REMOTE_USER_GROUP Seems to work perfectly now! Now to document a

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-13 Thread DiOrio, Max
[mailto:spacewalk-list-boun...@redhat.com] On Behalf Of DiOrio, Max Sent: Tuesday, March 13, 2018 1:55 PM To: spacewalk-list@redhat.com Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Thanks Alex – I’m almost there! I can now successfully log into Spacewalk as a user

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-13 Thread DiOrio, Max
[mailto:spacewalk-list-boun...@redhat.com] On Behalf Of Alexandru Raceanu Sent: Monday, March 12, 2018 2:58 PM To: spacewalk-list@redhat.com Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Try to go trough the SW/FreeIPA documentation (https://github.com/spacewalkproject

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-12 Thread Alexandru Raceanu
e spacewalk or other time consuming questions. /Alex From: "DiOrio, Max" To: spacewalk-list@redhat.com Sent: Monday, March 12, 2018 7:44:07 PM Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication SW 2.7 on RHEL 7.4 The HTTPD conf files are either

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-12 Thread DiOrio, Max
Administrator From: spacewalk-list-boun...@redhat.com [mailto:spacewalk-list-boun...@redhat.com] On Behalf Of Alexandru Raceanu Sent: Monday, March 12, 2018 2:08 PM To: spacewalk-list@redhat.com Subject: Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication Spacewalk version and

Re: [Spacewalk-list] Spacewalk and AD/SSSD Based User Authentication

2018-03-12 Thread Alexandru Raceanu
Spacewalk version and OS please... Also log entries except the tomcat would be helpful. What's the content of following: /etc/httpd/conf.d/intercept_form_submit.conf /etc/httpd/conf.d/ authnz_pam.conf /etc/httpd/conf.d/ auth_kerb.conf I don't think that you need to create the user if you do