Re: [CentOS] SSSD and usermod

2014-01-06 Thread Dimitar Georgievski
Hi MItja, it looks like you are trying to integrate SSSD with FreeIPA. I think the following presentation will help you review the SSSD configuration even if you are trying to use 389DS independently: http://www.freeipa.org/images/7/77/Freeipa30_SSSD_SUDO_Integration.pdf Check the page titled " E

[CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread James B. Byrne
Recently I have been deeply troubled by evidence revealing the degree to which U.S. based corporations (well actually all resident in any of the so-called 5-eyes countries) appear to have rolled over and assumed the position with respect to NSA inspired pressure to cripple public key encryption and

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread m . roth
James B. Byrne wrote: > Recently I have been deeply troubled by evidence revealing the degree to > which U.S. based corporations (well actually all resident in any of the > so-called 5-eyes countries) appear to have rolled over and assumed the position with > respect to NSA inspired pressure to cri

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread Eero Volotinen
I agree, but I just don't know how much in the way of manhours that would > involved. > > However, if you do get it all built, and build packages out of them, there > is an extras? contribs? repo, and I'd encourage you to submit it for that. > RHEL nowdays supports already Elliptic Curve on openss

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread James B. Byrne
> RHEL nowdays supports already Elliptic Curve on openssl. Which complete misses the point. First, the initial settings of the EC are significant in determining the strength of the resulting cipher. There is considerable evidence that suggests that some of these default settings have been propo

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread m . roth
Eero Volotinen wrote: > mark wrote: > I agree, but I just don't know how much in the way of manhours that would >> involved. >> >> However, if you do get it all built, and build packages out of them, >> there is an extras? contribs? repo, and I'd encourage you to submit it for >> that. > > RHEL now

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread Eero Volotinen
Um, I guess you haven't read the news lately - the most used, > POSIX-mandated elliptic curve is backdoored by the US NSA - when the > Well, as you know backdoored EC Dual DBRG is not working at all on openssl: http://marc.info/?l=openssl-announce&m=138747119822324 -- Eero ___

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread m . roth
Eero Volotinen wrote: > Um, I guess you haven't read the news lately - the most used, >> POSIX-mandated elliptic curve is backdoored by the US NSA - when the >> > > Well, as you know backdoored EC Dual DBRG is not working at all on > openssl: > http://marc.info/?l=openssl-announce&m=138747119822324

[CentOS] nfs client kerberos cache

2014-01-06 Thread Darod Zyree
Greetings, Not sure if this is the correct mail list. I have the following test environment set up: - 1x ipa master = ipa1.example.com - 1x nfs server = nfs1.example.com - 1x nfs client = nfsclient1.example.com NFS version 4 is used and the appropriate Kerberos principal has been created in IPA:

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread James B. Byrne
I am doing a bit of investigative work to see just how hard it is to build openssl for myself. The source from openssl.org is readily available and the spec file provided seems fairly usable. However, I am seeing lots of errors similar to this when I try to build it using mock: + /usr/lib/rpm/red

Re: [CentOS] Can we trust RedHAt encryption tools?

2014-01-06 Thread m . roth
James B. Byrne wrote: > I am doing a bit of investigative work to see just how hard it is to build > openssl for myself. The source from openssl.org is readily available and > the > spec file provided seems fairly usable. However, I am seeing lots of > errors > similar to this when I try to build

Re: [CentOS] ZFS on Linux testing effort

2014-01-06 Thread Lists
On 11/30/2013 06:20 AM, Andrew Holway wrote: > Hey, > > http://zfsonlinux.org/epel.html > > If you have a little time and resource please install and report back > any problems you see. > Andrew, I want to run /var on zfs, but when I try to move /var over it won't boot thereafter, with errors ab

Re: [CentOS] ZFS on Linux testing effort

2014-01-06 Thread Cliff Pratt
Grub only needs to know about the filesystems that it uses to boot the system. Mounting of the other file systems including /var is the responsibility of the system that has been booted. I suspect that you have something else wrong if you can't boot with /var/ on ZFS. I may be wrong, but I don't t

Re: [CentOS] ZFS on Linux testing effort

2014-01-06 Thread John R Pierce
On 1/6/2014 3:26 PM, Cliff Pratt wrote: > Grub only needs to know about the filesystems that it uses to boot the > system. Mounting of the other file systems including /var is the > responsibility of the system that has been booted. I suspect that you have > something else wrong if you can't boot w

Re: [CentOS] Odd problems with CR updates

2014-01-06 Thread Ganesh N
Could you please help me to downgrade nss-token..? ___ CentOS mailing list CentOS@centos.org http://lists.centos.org/mailman/listinfo/centos