[Freeipa-users] Re: VMware vCenter Single Sign-On

2020-02-04 Thread Christopher Young via FreeIPA-users
I gotta say, the unwillingness of large organizations like RedHat to even consider this functionality is pretty amazing to see since there was a bug filed 12 years ago to add properly support for RFC 4530 entryUUID. At some point, it should be a matter of pride for the directory services to add fu

[Freeipa-users] Re: Command to export sub-ca certificate

2020-02-04 Thread Fraser Tweedale via FreeIPA-users
On Tue, Feb 04, 2020 at 01:51:43PM -0500, Rob Crittenden via FreeIPA-users wrote: > Jakob Ackermann via FreeIPA-users wrote: > > The client is joined to the IPA domain and gets a certificate from the > > sub-ca `puppet` with `ipa-getcert request -x puppet`. In order to have > > the puppet agent to

[Freeipa-users] Re: pki-tomcat doesn't start, it can't update certificate

2020-02-04 Thread Rob Crittenden via FreeIPA-users
Serge Barkov via FreeIPA-users wrote: > It seems that the reason of the problem is in > "404...The requested resource is not available" when ipa tryies to renew the > certificate with request > https://ipa0.domain.com:8443/ca/agent/ca/profileReview > When I try it certificate is good but the resul

[Freeipa-users] VMware vCenter Single Sign-On

2020-02-04 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
Reference Links: 12/19/2006 https://bugzilla.redhat.com/show_bug.cgi?id=220222 Bug 220222 - [RFE] support for RFC 4530 entryUUID attribute [NEEDINFO] Product: Red Hat Enterprise Linux 8 Reported:2006-12-19 19:40 UTC by Victoriano Giralt Modified:2020-01-17 05:

[Freeipa-users] Re: Command to export sub-ca certificate

2020-02-04 Thread Rob Crittenden via FreeIPA-users
Jakob Ackermann via FreeIPA-users wrote: > The client is joined to the IPA domain and gets a certificate from the > sub-ca `puppet` with `ipa-getcert request -x puppet`. In order to have > the puppet agent to be able to talk to puppet server I need the puppet > sub-ca certificate. > > How can I di

[Freeipa-users] Re: Does anyone use phpldapadmin on FreeIPA/RH-IdM ?

2020-02-04 Thread Grant Janssen via FreeIPA-users
I use ApacheDirectoryStudio - grant This e-mail and any attachments are intended only for use by the addressee(s) named herein and may contain confidential information. If you are not the intended recipient of this e-mail, you are hereby notified any dissemination, distribution or copying of th

[Freeipa-users] Re: Does anyone use phpldapadmin on FreeIPA/RH-IdM ?

2020-02-04 Thread Rob Crittenden via FreeIPA-users
White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users wrote: > I am just curious to browse the LDAP information. > > Contrarywise, does anyone have any suggestions for a free, lightweight > way to browse LDAP information in FreeIPA/RH-IdM ? A lot of people use Apache studio. https://directory.ap

[Freeipa-users] Does anyone use phpldapadmin on FreeIPA/RH-IdM ?

2020-02-04 Thread White, Daniel E. (GSFC-770.0)[NICS] via FreeIPA-users
I am just curious to browse the LDAP information. Contrarywise, does anyone have any suggestions for a free, lightweight way to browse LDAP information in FreeIPA/RH-IdM ? __ Daniel E. White daniel.e.wh...

[Freeipa-users] Re: FreeIPA 4.8.1 on Fedora 31 (upgraded from F30) fails to start

2020-02-04 Thread Florence Blanc-Renaud via FreeIPA-users
On 2/3/20 9:07 AM, Jochen Demmer via FreeIPA-users wrote: Hi, unfortunately currently there's is no other node, which is why I'm trying to update to Fedora 31. I used to replicate between two machines but on got lost. I installed a new machine which is supposed to work as my new replica but t

[Freeipa-users] Command to export sub-ca certificate

2020-02-04 Thread Jakob Ackermann via FreeIPA-users
The client is joined to the IPA domain and gets a certificate from the sub-ca `puppet` with `ipa-getcert request -x puppet`. In order to have the puppet agent to be able to talk to puppet server I need the puppet sub-ca certificate. How can I distribute the sub-ca certificate to the client? Runni

[Freeipa-users] Re: Framework Use of GSS Proxy

2020-02-04 Thread Alexander Bokovoy via FreeIPA-users
On ma, 03 helmi 2020, TC Johnson via FreeIPA-users wrote: Hi, I'm looking to understand a little better how the framework is using GSS Proxy to authenticate the user who is accessing the tools. The information here (https://www.freeipa.org/page/Troubleshooting/PrivilegeSeparation) is nice and I'

[Freeipa-users] Re: shouldn't freeipa work by default?

2020-02-04 Thread Harald Dunkel via FreeIPA-users
On 2020-01-31 10:02, François Cami wrote: We'd rather fail early and print that warning which lets the admin fix the issue. You can see the rationale in the upstream ticket: https://pagure.io/freeipa/issue/5887 As an admin I won't touch user settings, esp. not the locale variables. All I can d