[Freeipa-users] Re: IPA CA request ID reuse issue

2020-09-17 Thread Fraser Tweedale via FreeIPA-users
On Thu, Sep 17, 2020 at 12:41:37PM -, Boris Sukhinin via FreeIPA-users wrote: > I can confirm that rebuilding VLV solved the issue. After restoring > overwritten certificate requests from backup we were able to add new replicas > to the FreeIPA cluster without any problems. > > Fraser, than

[Freeipa-users] Re: Renewing a failed to auto-renewal certificate

2020-09-17 Thread Stuart McRobert via FreeIPA-users
Dear All, Thanks to everyone for their help with this. In summary the problem was an inconsistency between the certificate stored in a file and in ldap, as described at the bottom of flo's blog: https://floblanc.wordpress.com/2017/09/11/troubleshooting-freeipa-pki-tomcatd-fails-to-st

[Freeipa-users] Re: ipa client autofs issue

2020-09-17 Thread Alexander Bokovoy via FreeIPA-users
On to, 17 syys 2020, Ronald Wimmer wrote: On 15.09.20 17:19, Alexander Bokovoy via FreeIPA-users wrote: On ti, 15 syys 2020, Ronald Wimmer via FreeIPA-users wrote: On 15.09.20 16:39, Alexander Bokovoy via FreeIPA-users wrote: On ti, 15 syys 2020, Ronald Wimmer via FreeIPA-users wrote: On 15.0

[Freeipa-users] Re: ipa client autofs issue

2020-09-17 Thread Ronald Wimmer via FreeIPA-users
On 15.09.20 17:19, Alexander Bokovoy via FreeIPA-users wrote: On ti, 15 syys 2020, Ronald Wimmer via FreeIPA-users wrote: On 15.09.20 16:39, Alexander Bokovoy via FreeIPA-users wrote: On ti, 15 syys 2020, Ronald Wimmer via FreeIPA-users wrote: On 15.09.20 15:48, Rob Crittenden via FreeIPA-user

[Freeipa-users] Re: mod_nss fails apache start missing existing certificate.

2020-09-17 Thread Rob Crittenden via FreeIPA-users
Naor Weissmann via FreeIPA-users wrote: > Hi guys. > I understand it is not a pure FreeIPA question but it is supporting > middleware and im out of ideas. > We have an old ipa-server-selinux-3.0.0 on Centos6. > after restart i cant start http service. error log in debug mode points me to > nss.

[Freeipa-users] Re: CROND with IPA user

2020-09-17 Thread Rob Crittenden via FreeIPA-users
Sumit Bose via FreeIPA-users wrote: > On Thu, Sep 17, 2020 at 10:14:37AM +0200, Ronald Wimmer via > FreeIPA-users wrote: >> On 14.09.20 09:07, Ronald Wimmer via FreeIPA-users wrote: >>> I have a script that runs periodically as a CRON job. The user is an >>> IPA user. Everything works perfectly for

[Freeipa-users] BadRequest when using freeipa-python

2020-09-17 Thread Ronald Wimmer via FreeIPA-users
Anyone using freeipa-python here? When I try to use client.host_mod('myserver.mydomain.at', userclass='SomeUserClass') the user class is set correctly on the host above but I do get an Exception: File "./modifyHosts.py", line 34, in client.host_mod('myserver.mydomain.at', userclass='Some

[Freeipa-users] Re: IPA CA request ID reuse issue

2020-09-17 Thread Boris Sukhinin via FreeIPA-users
I can confirm that rebuilding VLV solved the issue. After restoring overwritten certificate requests from backup we were able to add new replicas to the FreeIPA cluster without any problems. Fraser, thank you very much, your help was extremely valuable. Best regards, Boris _

[Freeipa-users] Re: CROND with IPA user

2020-09-17 Thread Sumit Bose via FreeIPA-users
On Thu, Sep 17, 2020 at 10:14:37AM +0200, Ronald Wimmer via FreeIPA-users wrote: On 14.09.20 09:07, Ronald Wimmer via FreeIPA-users wrote: I have a script that runs periodically as a CRON job. The user is an IPA user. Everything works perfectly for a while and at some point in time I am getting

[Freeipa-users] Re: CROND with IPA user

2020-09-17 Thread Ronald Wimmer via FreeIPA-users
On 14.09.20 09:07, Ronald Wimmer via FreeIPA-users wrote: I have a script that runs periodically as a CRON job. The user is an IPA user. Everything works perfectly for a while and at some point in time I am getting log entries like: Sep 14 08:56:02 myServer CROND[24516]: (CRON) ERROR chdir fai