Squeeze Debian-Edu is working more and more.

2011-02-27 Thread Andreas Schockenhoff
Hi, first off all thanks for the good job to integrate gosa into debian-edu! Many things seams to work now. Only the netgroups problem must be fixed in /etc/exports or may be in the ladp tree. I run into this problem. ldapvi --host ldap -ZZ --bind simple --tls allow -D 'cn=super-admin,ou=Peopl

Re: Squeeze Debian-Edu is working more and more.

2011-02-27 Thread Petter Reinholdtsen
[Andreas Schockenhoff] > I run into this problem. > > ldapvi --host ldap -ZZ --bind simple --tls allow -D > 'cn=super-admin,ou=People,dc=skole,dc=skolelinux,dc=no' > ldap_start_tls_s: Connect error (-11) > additional info: TLS: hostname does not match CN in peer certificate You need to use FQD

Re: Squeeze Debian-Edu is working more and more.

2011-02-27 Thread Andreas Schockenhoff
Hi, On Sun, 2011-02-27 at 14:22 +0100, Petter Reinholdtsen wrote: > You need to use FQDN, ie ldap.intern as the --host parameter to avoid > this. Thanks this seams to work partly: ldapvi --host ldap.intern -ZZ --bind simple --tls allow -D 'uid=super-admin,ou=People,dc=skole,dc=skolelinux,dc=no'

Re: Squeeze Debian-Edu is working more and more.

2011-02-27 Thread Mike Gabriel
Hi Petter, hi list, On So 27 Feb 2011 14:22:17 CET Petter Reinholdtsen wrote: [Andreas Schockenhoff] The netgroup is a solution that based on IPs so it is not really secure. Now we have Kerberos running is there an other solution? So may be we do not need the netgroups. Netgroups are used f

Problem handling thin clients' "subnet" within GOsa (was: Re: DNS for the thin client network should be handlet by Gosa)

2011-02-27 Thread Andreas B. Mundt
Hi all, unfortunatelly it looks like we have a little problem with the DNS/GOsa setup. In skolelinux, we have at least two networks: The 10.0.2.-net called main-net and the 192.168.-nets. However, both networks are part of the "intern" domain. Now we need a zone to handle these networks. I pre

Re: Problem handling thin clients' "subnet" within GOsa (was: Re: DNS for the thin client network should be handlet by Gosa)

2011-02-27 Thread Mike Gabriel
Hi Andi, On So 27 Feb 2011 20:56:34 CET "Andreas B. Mundt" wrote: What happens if I ask for the ltspserver's thin-client interface with associated name ltspserver? Well, I can add an A-record in the intern-zone that translates to 192.168.0.254. So far so good. Maybe your problem does not need