[Freeipa-users] Re: FreeIPA Bastion

2021-05-19 Thread Harry G. Coin via FreeIPA-users
While you're at it, you will catch further bugs (including likely named crashing) if your tests enable dnssec on several domains at the same time, then test them all.  It's not enough to just turn on dnssec on one domain and test it then call it 'ok'. HC On 5/19/21 11:50 AM, Ernedin Zajko via Fr

[Freeipa-users] Re: FreeIPA Bastion

2021-05-19 Thread Ernedin Zajko via FreeIPA-users
Hi there, Maybe something like this: https://github.com/aker-gateway/Aker On Wed, May 19, 2021, 17:24 G Col via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Hello Team, > > I was wondering how I can configure FreeIPA as a bastion server when I ssh > other hosts. > Basically Free

[Freeipa-users] FreeIPA Bastion

2021-05-19 Thread G Col via FreeIPA-users
Hello Team, I was wondering how I can configure FreeIPA as a bastion server when I ssh other hosts. Basically FreeIPA would be in the middle of the ssh approval to access to the specific server via ssh. Is a functionality that FreeIPA has at the moment? Thank you for your help, gcol ___

[Freeipa-users] Re: Removal of host certificates

2021-05-19 Thread Fraser Tweedale via FreeIPA-users
On Wed, May 19, 2021 at 11:54:03AM +, Gerrard Geldenhuis via FreeIPA-users wrote: > Hi > I am trying to remove old host certificates. > > I generated a list using: > ipa cert-find --sizelimit 0 > > One of the certs are: > Issuing CA: ipa > Subject: CN=server.example.com,O=COMPANY.COM > Issue

[Freeipa-users] Removal of host certificates

2021-05-19 Thread Gerrard Geldenhuis via FreeIPA-users
Hi I am trying to remove old host certificates. I generated a list using: ipa cert-find --sizelimit 0 One of the certs are: Issuing CA: ipa Subject: CN=server.example.com,O=COMPANY.COM Issuer: CN=Certificate Authority,O=COMPANY.COM Not Before: Fri May 20 15:56:37 2016 UTC Not After: Mon May 21 15

[Freeipa-users] Removal of host certificates

2021-05-19 Thread Gerrard Geldenhuis via FreeIPA-users
Hi I am trying to remove old host certificates. I generated a list using: ipa cert-find --sizelimit 0 One of the certs are: Issuing CA: ipa Subject: CN=server.example.com,O=COMPANY.COM Issuer: CN=Certificate Authority,O=COMPANY.COM Not Before: Fri May 20 15:56:37 2016 UTC Not After: Mon May 21 15