[Freeipa-users] Re: sudo policy doesn't work since host is installed with CNAME

2017-08-30 Thread Jakub Hrozek via FreeIPA-users
On Wed, Aug 30, 2017 at 08:51:24PM +, Z D wrote: > > Does ipa_hostname in sssd.conf point to cname (or, the hostname registered > > with IPA) ? > > > It points to the DNS A record, the one that is registered with IPA. Pavel, is a setup with a machne where the hostname in IPA doesn't match t

[Freeipa-users] Re: sudo policy doesn't work since host is installed with CNAME

2017-08-30 Thread Z D via FreeIPA-users
> Does ipa_hostname in sssd.conf point to cname (or, the hostname registered > with IPA) ? It points to the DNS A record, the one that is registered with IPA. From: Jakub Hrozek via FreeIPA-users Sent: Wednesday, August 30, 2017 12:26:40 PM To: freeipa-users@li

[Freeipa-users] Re: sudo policy doesn't work since host is installed with CNAME

2017-08-30 Thread Jakub Hrozek via FreeIPA-users
On Wed, Aug 30, 2017 at 07:21:11PM +, Z D via FreeIPA-users wrote: > Hi there, > > we're using ipa-server-4.4.0 (without its own DNS) and are facing the > situation with A/CNAME host. > > Basically a host is installed with CNAME as the OS, and IPA is aware of only > A record since host is j

[Freeipa-users] sudo policy doesn't work since host is installed with CNAME

2017-08-30 Thread Z D via FreeIPA-users
Hi there, we're using ipa-server-4.4.0 (without its own DNS) and are facing the situation with A/CNAME host. Basically a host is installed with CNAME as the OS, and IPA is aware of only A record since host is joined to IPA domain with its A record. The A record is member of proper host group a

[Freeipa-users] Re: Freeipa Certficates issues

2017-08-30 Thread Julien Honore via FreeIPA-users
Hi Flo, When I try to apply the command. the result is: ipa-getkeytab --principal=host/$vltws01.vit@vit.lan Usage: ipa-getkeytab [-qPr?] [-q|--quiet] [-s|--server=Server Name] [-p|--principal=Kerberos Service Principal Name] [-k|--keytab=Keytab File Name] [-e|--enctyp

[Freeipa-users] kerbores nfs client problem

2017-08-30 Thread San Zhang via FreeIPA-users
I set up a kerberos-aware nfs server and some clients. I mount with "-o sec=krb5" successfully first time. For some reason, I change the krb5.keytab by copying a backup keytab and rerunnig ipa-getkeytab command, and then reboot the nfs server. Now the client mounting succesfully before is un

[Freeipa-users] nfs server with multiple IP addresses

2017-08-30 Thread San Zhang via FreeIPA-users
I have a ipa server (ipa.example.com) with DNS service and a kerberos-aware nfs server (nfs.example.com). The nfs server has two IP addresses: 192.168.2.10, 192.168.3.10. The two networks 192.168.2.0/24 and 192.168.3.0/24 are not connected to each other directly. I hope the DNS server resolve nf

[Freeipa-users] Re: Freeipa Certficates issues

2017-08-30 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/29/2017 06:43 PM, Julien Honore wrote: Hi Florence, Thank you for the reply. When I execute the command sudo kinit -kt /etc/krb5.keytab the result is : kinit: Clients credentials have been revoked while getting initial credentials When I try the command ipa-getkeytab, I don't have the sa

[Freeipa-users] Re: Kvno error on validating one-way trust: "kvno: Decrypt integrity check failed while getting credentials"

2017-08-30 Thread Alexander Bokovoy via FreeIPA-users
On ti, 22 elo 2017, bogusmaster--- via FreeIPA-users wrote: Hi All, I am setting up a one-way trust from FreeIPA server to AD domain with a pre-shared key. This is currently not working due to chicken/egg problem: in order to turn trust into an active one, you need to validate it. We do not hav

[Freeipa-users] Re: Kvno error on validating one-way trust: "kvno: Decrypt integrity check failed while getting credentials"

2017-08-30 Thread Sumit Bose via FreeIPA-users
On Wed, Aug 30, 2017 at 10:45:11AM -, bogusmaster--- via FreeIPA-users wrote: > Behavior that I described above pertains to Windows 2008 R2. When I attempt > at doing exactly the same with AD set up on top of Windows 2012, it works > flawlessly. Unfortunately, environment I have to set up tr

[Freeipa-users] Re: Kvno error on validating one-way trust: "kvno: Decrypt integrity check failed while getting credentials"

2017-08-30 Thread bogusmaster--- via FreeIPA-users
Behavior that I described above pertains to Windows 2008 R2. When I attempt at doing exactly the same with AD set up on top of Windows 2012, it works flawlessly. Unfortunately, environment I have to set up trust with uses Windows 2008 R2. I am wondering what might be the difference between these

[Freeipa-users] Re: [CentOS 7.5] error message during LDAP backup

2017-08-30 Thread Jochen Hein via FreeIPA-users
Ludwig Krispenz via FreeIPA-users writes: > This is issue: https://pagure.io/389-ds-base/issue/49334 Thanks for the info. I like the documentation and analysis in the tickets (not only this one) - well done! Jochen -- This space is intentionally left blank. __

[Freeipa-users] Re: Help: Suddenly not possible to mount nfs4 shares with sec=krb5i

2017-08-30 Thread Detlev Habicht via FreeIPA-users
Thank you all for your answers! Well, it seemed, i make a great mistake here (mixing minor versions …). But now i have to setup everything new and the real answer i will know in a few weeks … But thank you again! Detlev -- Detlev | Institut fuer Mikroelektronische Systeme Habicht | D-3016

[Freeipa-users] Re: [CentOS 7.5] error message during LDAP backup

2017-08-30 Thread Ludwig Krispenz via FreeIPA-users
This is issue: https://pagure.io/389-ds-base/issue/49334 On 08/30/2017 09:01 AM, Jochen Hein via FreeIPA-users wrote: I've upgraded my FreeIPA servers to CentOS 7.5 (CR). After that I have the following new messages during backup: Aug 30 01:34:34 freeipa1 ns-slapd: [30/Aug/2017:01:34:34.2259321

[Freeipa-users] [CentOS 7.5] error message during LDAP backup

2017-08-30 Thread Jochen Hein via FreeIPA-users
I've upgraded my FreeIPA servers to CentOS 7.5 (CR). After that I have the following new messages during backup: Aug 30 01:34:34 freeipa1 ns-slapd: [30/Aug/2017:01:34:34.225932118 +0200] - ERR - dblayer_copy_directory - Backend instance "cldb" does not exist; Instance path /var/lib/dirsrv/slapd