[Freeipa-users] could not get zone keys for secure dynamic update

2017-10-02 Thread r3pek via FreeIPA-users
Hi list! I'm trying to understand why my DNS zone refuses to get updated/signed. After an "rndc reload" I get this in the named-pkcs11 logs: <> failed to parse RR entry: resource record DN 'idnsname=mail._domainkey,idnsname=example.com.,cn=dns,dc=example,dc=com' <> update_record (syncre

[Freeipa-users] Re: IPA Server Upgrade Error

2017-10-02 Thread Charles Hedrick via FreeIPA-users
Note that the —rename option of certutil doesn’t seem to work for this format of files. Extract the cert, delete and and add it back with the new nickname. e.g. certutil -L -d /etc/httpd/alias -n ‘CN=…...' -a -o ~/krb1.cert certutil -D -d /etc/httpd/alias -n ‘CN=…..' certutil -A -d /etc/httpd/

[Freeipa-users] OTP Failure For LDAP Bind 4.5

2017-10-02 Thread Callum Guy via FreeIPA-users
Hi All, We are experiencing a strange fault since updating to CentOS 7.4 / FreeIPA 4.5. All users on the system require password+OTP authentication. This works normally for all logins however when authenticating over an interim LDAP bind (used between our Cisco ASA and FreeIPA) the authentication

[Freeipa-users] Re: IPA Server Upgrade Error

2017-10-02 Thread Florence Blanc-Renaud via FreeIPA-users
On 09/28/2017 11:51 AM, Alka Murali via FreeIPA-users wrote: Hi Florence, Thanks for the email. I am on CentOS 7 system and would like to use yum to go for the Upgrade. I beleive dnf is intended for Fedora. Can you please provide me a solution for CentOS on the Upgrade process. Regards, Alk

[Freeipa-users] Re: sudo not working with hostgroups

2017-10-02 Thread Przemysław Orzechowski via FreeIPA-users
On all ubuntu flavours simple solution is to install sudo from its developement page sudo included in system does not work with groups correctly. Up to Ubuntu 16.04 From what i have seen if user is in a group that is in different group sudo on Ubuntu does not recognize the second group ( that