Re: [ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2017-04-21 Thread Paul
Hi Ondra, It is over a year since the last message, so I thought let's give this a new try. Did setup a new test environment with latest versions, all RH-family (Centos 7.3 with ovirt 4.1) Ovirt engine works fine with IPA, in the console I can log in with credentials. But SSO still does not work

Re: [ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2016-03-20 Thread Paul
Hi Ondra, Bug 1316135 was new to me and sounds very similar to my issue "(0, 17, ) [Success (Failure setting user credentials)]" Proposed work-around with "authconfig --enablenis --update" worked for me, although this creates an issue with the keyring authentication. I can live with this for the

Re: [ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2016-03-19 Thread Ondra Machacek
Hi Paul, ok, thanks for info, then there is an issue in pam configuration, most probably. There is open issue for it on rhel7, please try read this comment[1] if it helps to you. Ondra [1] https://bugzilla.redhat.com/show_bug.cgi?id=1316135#c3 On 03/17/2016 06:07 PM, Paul wrote: Hi Ondra,

Re: [ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2016-03-19 Thread Paul
Hi Ondra, Thanks for your reply, unfortunately this does not resolve the issue. I had already seen this bug and tried it without the -authz appendix(maybe should have mentioned that). I also (may be wrongfully) assumed that the "ovirt-engine-extension-aaa-ldap-setup" would not have this

Re: [ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2016-03-19 Thread Ondra Machacek
Hi, your authz name should match kerberos name. So please change your authz name from 'DOMAIN-authz' to 'DOMAIN' Please see this bz[1] for more detail. Ondra [1] https://bugzilla.redhat.com/show_bug.cgi?id=1133137#c7 On 03/17/2016 04:22 PM, Paul wrote: Hi, I am having an issue with getting

[ovirt-users] Hosted engine Single Sign-On to VM with freeIPA not working

2016-03-19 Thread Paul
Hi, I am having an issue with getting SSO to work when a standard user(UserRole) logs in to the UserPortal. The user has permission to use only this VM, so after login the console is automatically opened for that VM. Problem is that it doesn't login on the VM system with the provided