[Freeipa-users] Re: Grant sudo to users only on their own workstations

2022-12-20 Thread Alexander Bokovoy via FreeIPA-users
On ti, 20 joulu 2022, Ranbir wrote: On Tue, 2022-12-20 at 08:22 +0200, Alexander Bokovoy via FreeIPA-users wrote: FreeIPA does not provide generation capabilities in itself. These things are specific to individual deployments and their logic is impossible to automate in a generic way without exp

[Freeipa-users] LDAP error after re-initializing replica server

2022-12-20 Thread Hirata, Tyler via FreeIPA-users
I’m testing out IPA and wanted to see how restoring backups work. I successfully restored an older backup to my master node, but when I hop on my replica nodes and run the re-initialization command, I get an LDAP error. I was wondering if anyone has experienced this? ipa-replica-manage re-initi

[Freeipa-users] Re: Grant sudo to users only on their own workstations

2022-12-20 Thread Entrepreneur AJ via FreeIPA-users
Not sure if this helps but I've found on my fedora machines installing Spotify via lpf requires adding my user to the pkg-build group. When I do that it seems to persist on that machine without effecting groups on other machines.  Maybe worth a shot. Might be best to do it then clear sss cache

[Freeipa-users] Re: Grant sudo to users only on their own workstations

2022-12-20 Thread Ranbir via FreeIPA-users
On Tue, 2022-12-20 at 08:22 +0200, Alexander Bokovoy via FreeIPA-users wrote: > FreeIPA does not provide generation capabilities in itself. These > things > are specific to individual deployments and their logic is impossible > to > automate in a generic way without exposing some kind of a general

[Freeipa-users] Re: ipa: ERROR: Failed to authenticate to CA REST API

2022-12-20 Thread junhou he via FreeIPA-users
Hi , [20/Dec/2022:08:49:29.637099418 +0800] conn=2892 op=9 UNBIND [20/Dec/2022:08:49:29.637145006 +0800] conn=2892 op=9 fd=124 closed error - U1 [20/Dec/2022:08:49:32.043506909 +0800] conn=27 op=3410 SRCH base="ou=sessions,ou=Security Domain,o=ipaca" scope=2 filter="(objectClass=securityDomainSes