[Freeipa-users] Re: backup & restore - 4.9.11 -> 4.10.1

2023-03-17 Thread Rafael Jeffman via FreeIPA-users
On Fri, Mar 17, 2023 at 3:07 PM Rob Crittenden via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > > lejeczek via FreeIPA-users wrote: > > Hi guys. > > > > I'm trying to migrate IPA from Centos 8 over to Centos 9 but I fail. > > If the path I try is supported & should work then, firs

[Freeipa-users] Re: backup & restore - 4.9.11 -> 4.10.1

2023-03-17 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > Hi guys. > > I'm trying to migrate IPA from Centos 8 over to Centos 9 but I fail. > If the path I try is supported & should work then, first, 'restore' > failed with: > ... > Restoring umask to 18 > CalledProcessError(Command ['/usr/sbin/ipactl', 'start'] return

[Freeipa-users] backup & restore - 4.9.11 -> 4.10.1

2023-03-17 Thread lejeczek via FreeIPA-users
Hi guys. I'm trying to migrate IPA from Centos 8 over to Centos 9 but I fail. If the path I try is supported & should work then, first, 'restore' failed with: ... Restoring umask to 18 CalledProcessError(Command ['/usr/sbin/ipactl', 'start'] returned non-zero exit status 1: 'IPA version error

[Freeipa-users] Re: FreeIPA-Kubernetes Setup

2023-03-17 Thread Alexander Bokovoy via FreeIPA-users
On pe, 17 maalis 2023, Rob Crittenden via FreeIPA-users wrote: Ronald Wimmer via FreeIPA-users wrote: On 14.05.21 11:26, Ronald Wimmer via FreeIPA-users wrote: Hi, are there any plans (or maybe ongoing work already) to let FreeIPA run in a K8s environment? What about tearing all the tightly

[Freeipa-users] access IPA client via ssh does not work

2023-03-17 Thread None via FreeIPA-users
I have a fresh IPA server setup with a trust to an Active Directory. Alls IPA services are working fine, IPA users can connect to IPA client hosts without problems. I now have added an AD user via creating an ID override in the default trust view and added an ssh key for the user. I made the us

[Freeipa-users] Re: Win replication

2023-03-17 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Fri, Mar 17, 2023 at 2:51 PM Алексей Иванов via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Greetings, > > I'm using ipa-replica-manage connect --winsync to create users from > windows to IPA. But it copies all the users from OU. Can I add an LDAP > filter somewhere so t

[Freeipa-users] Win replication

2023-03-17 Thread Алексей Иванов via FreeIPA-users
Greetings, I'm using ipa-replica-manage connect --winsync to create users from windows to IPA. But it copies all the users from OU. Can I add an LDAP filter somewhere so that I will replicate only a subset of users? Regards, Alex Ivanov. ___ FreeIPA-use

[Freeipa-users] Re: keytab file deleted and sssd not starting

2023-03-17 Thread Jeremy Tourville via FreeIPA-users
OK, but how do i get them to match again? Running ipa-getkeytab doesn't fix it. klist just keeps incrementing and kvno stays the same. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users

[Freeipa-users] Need assistance to troubleshoot named not starting

2023-03-17 Thread Jeremy Tourville via FreeIPA-users
This problem started when someone deleted my /etc/krb5.keytab file. I am trying to get the named service working again. I am following the docs: What to do when named with bind-dyndb-ldap cannot start https://docs.pagure.org/bind-dyndb-ldap/BIND9/NamedCannotStart.html 1 Gather logs- A. my s

[Freeipa-users] Re: FreeIPA-Kubernetes Setup

2023-03-17 Thread Rob Crittenden via FreeIPA-users
Ronald Wimmer via FreeIPA-users wrote: > On 14.05.21 11:26, Ronald Wimmer via FreeIPA-users wrote: >> Hi, >> >> are there any plans (or maybe ongoing work already) to let FreeIPA run >> in a K8s environment? > > What about tearing all the tightly coupled parts (389DS, DNS, PKI, > HTTPD, KDC, Samba

[Freeipa-users] Re: keytab file deleted and sssd not starting

2023-03-17 Thread Rob Crittenden via FreeIPA-users
Jeremy Tourville via FreeIPA-users wrote: > I have noted that klist and kvno don't match for the keytab I fetched > earlier. Could this cause issues with named or are those two separate > issues? How do I get them to match? > > [root@gsil-ipa01 data]# klist -ek /etc/krb5.keytab > Keytab name:

[Freeipa-users] Re: keytab file deleted and sssd not starting

2023-03-17 Thread Jeremy Tourville via FreeIPA-users
I have noted that klist and kvno don't match for the keytab I fetched earlier. Could this cause issues with named or are those two separate issues? How do I get them to match? [root@gsil-ipa01 data]# klist -ek /etc/krb5.keytab Keytab name: FILE:/etc/krb5.keytab KVNO Principal

[Freeipa-users] Re: FreeIPA-Kubernetes Setup

2023-03-17 Thread Ronald Wimmer via FreeIPA-users
On 14.05.21 11:26, Ronald Wimmer via FreeIPA-users wrote: Hi, are there any plans (or maybe ongoing work already) to let FreeIPA run in a K8s environment? What about tearing all the tightly coupled parts (389DS, DNS, PKI, HTTPD, KDC, Samba, ...) apart, let them run in K8s and do the coupling