[Freeipa-users] Re: Announcing freeIPA 4.7.0

2018-08-17 Thread Anthony Joseph Messina via FreeIPA-users
On Friday, August 17, 2018 1:34:03 PM CDT Rob Crittenden wrote: > Anthony Joseph Messina via FreeIPA-users wrote: > > I have two full (DNS, CA, KRA) FreeIPA instances still running F27 for > > stability based on the recommendations at the time of the F28 release. Is > > *this[1]* FreeIPA release r

[Freeipa-users] Re: Passync AD *and* trust?

2018-08-17 Thread Rob Crittenden via FreeIPA-users
Pieter Baele via FreeIPA-users wrote: > Hi, > > Would it somehow be possible to - partially - sync AD users (max 200) > with IPA while still using a trust with the same domain? No. > Logically this sounds like a bad idea, but my colleagues would really > really like to use IPA also for AIX. The

[Freeipa-users] Re: Announcing freeIPA 4.7.0

2018-08-17 Thread Rob Crittenden via FreeIPA-users
Anthony Joseph Messina via FreeIPA-users wrote: > I have two full (DNS, CA, KRA) FreeIPA instances still running F27 for > stability based on the recommendations at the time of the F28 release. Is > *this[1]* FreeIPA release recommended for a full OS dnf upgrade from F27 to > F28? Yes, we push

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-08-17 Thread Jokinen Eemeli via FreeIPA-users
Hi! Date: 20-03-2018 Services running (certmonger, dirsrv, httpd, pki-tomcatd) -- ipa-getcert resubmit -i 20170425122557 Resubmitting "20170425122557" to "dogtag-ipa-ca-renew-agent". getcert list |grep -A 1 20170425122557 Request ID '20170425122557': status: CA_UNREACHABLE -- Certmonger

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-08-17 Thread Florence Blanc-Renaud via FreeIPA-users
On 08/17/2018 12:59 PM, Jokinen Eemeli via FreeIPA-users wrote: Hi! Yes, seems like there was "security: off" but that doesn't seem to do it, I think I have ended up in the situation that I need to recreate some certificates, because: I check the renewal dates. -- getcert list |grep expires:

[Freeipa-users] Re: Problems after IPA upgrade: ipa-server-upgrade doesn't complete, pki-tomcatd won't start

2018-08-17 Thread Jokinen Eemeli via FreeIPA-users
Hi! Yes, seems like there was "security: off" but that doesn't seem to do it, I think I have ended up in the situation that I need to recreate some certificates, because: I check the renewal dates. -- getcert list |grep expires: expires: 2018-03-21 09:42:04 UTC expires: 2036-03

[Freeipa-users] Passync AD *and* trust?

2018-08-17 Thread Pieter Baele via FreeIPA-users
Hi, Would it somehow be possible to - partially - sync AD users (max 200) with IPA while still using a trust with the same domain? Logically this sounds like a bad idea, but my colleagues would really really like to use IPA also for AIX. The biggest limitation is that the AIX client doesn't work

[Freeipa-users] Re: Announcing freeIPA 4.7.0

2018-08-17 Thread Alexander Bokovoy via FreeIPA-users
On to, 16 elo 2018, Anthony Joseph Messina via FreeIPA-users wrote: I have two full (DNS, CA, KRA) FreeIPA instances still running F27 for stability based on the recommendations at the time of the F28 release. Is *this[1]* FreeIPA release recommended for a full OS dnf upgrade from F27 to F28? [

[Freeipa-users] Re: Changing domain name

2018-08-17 Thread Angus Clarke via FreeIPA-users
You might find some useful tips here: https://www.redhat.com/archives/freeipa-users/2014-May/msg00158.html Not sure if they did drop their other scripts into github (as suggested two thirds down) Regards Angus On 17 August 2018 at 10:09, Alfredo De Luca via FreeIPA-users < freeipa-users@lists.

[Freeipa-users] Re: Changing domain name

2018-08-17 Thread Alfredo De Luca via FreeIPA-users
Hi Rob. It worked. Thanks. It was confusing for me the name *migrated *thinking was the new host rather than the *"old"* . Now users/groups are there and whoever has the password needs to connect to the new server in order to recreate their password with kerberos. I guess who has the ssh keys don't