[Freeipa-users] Re: ipaserver.ipa.1017.abc can not serve DNS for 1017.abc

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 09 жні 2023, Alan Latteri via FreeIPA-users wrote: Thank you for the reply. What is the proper way to approach setting up a fresh IPA environment, trying to following best practices of having IPA and AD in separate subdomains? I'm a bit confused on how to approach, if I'd like to be abl

[Freeipa-users] Re: Finding users with missing field entries

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Чцв, 10 жні 2023, Ali Sobhi via FreeIPA-users wrote: How do I search for logins where --departmentnumber value is null? Use LDAP searches directly. 'ipa -find' commands do not allow to search for an absence of an attribute. $ kinit admin $ BASEDN=$(ipa env basedn|cut -d: -f2-|tr -d ' ') $ l

[Freeipa-users] Finding users with missing field entries

2023-08-09 Thread Ali Sobhi via FreeIPA-users
How do I search for logins where --departmentnumber value is null? ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct: https://docs.fedo

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Thierry Bordaz via FreeIPA-users
On 8/9/23 21:13, Harry G Coin wrote: On 8/9/23 12:05, Thierry Bordaz wrote: On 8/9/23 18:55, Harry G Coin wrote: Theirry asked for a recap summary below, so forgive the 'top post'.  Here it is: 4.9.10 default install on two systems call them primary (with kasp.db) and secondary but other

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Harry G Coin via FreeIPA-users
On 8/9/23 12:05, Thierry Bordaz wrote: On 8/9/23 18:55, Harry G Coin wrote: Theirry asked for a recap summary below, so forgive the 'top post'.  Here it is: 4.9.10 default install on two systems call them primary (with kasp.db) and secondary but otherwise multi-master, 1g link between them

[Freeipa-users] Re: ipaserver.ipa.1017.abc can not serve DNS for 1017.abc

2023-08-09 Thread Alan Latteri via FreeIPA-users
Thank you for the reply. What is the proper way to approach setting up a fresh IPA environment, trying to following best practices of having IPA and AD in separate subdomains? I'm a bit confused on how to approach, if I'd like to be able to serve apex domain from IPA. According to best pract

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Thierry Bordaz via FreeIPA-users
On 8/9/23 18:55, Harry G Coin wrote: Theirry asked for a recap summary below, so forgive the 'top post'.  Here it is: 4.9.10 default install on two systems call them primary (with kasp.db) and secondary but otherwise multi-master, 1g link between them, modest/old cpu, drives, 5Gmemory, with

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Harry G Coin via FreeIPA-users
Theirry asked for a recap summary below, so forgive the 'top post'.  Here it is: 4.9.10 default install on two systems call them primary (with kasp.db) and secondary but otherwise multi-master, 1g link between them, modest/old cpu, drives, 5Gmemory, with dns/dnssec and adtrust (aimed at local

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Thierry Bordaz via FreeIPA-users
On 8/9/23 17:15, Harry G Coin wrote: On 8/9/23 01:00, Alexander Bokovoy wrote: On Аўт, 08 жні 2023, Harry G Coin wrote: Thanks for your help.  Details below. The problem 'moved' in I hope a diagnositcally useful way, but the system remains broken. On 8/8/23 08:54, Alexander Bokovoy wrote:

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Harry G Coin via FreeIPA-users
On 8/9/23 01:00, Alexander Bokovoy wrote: On Аўт, 08 жні 2023, Harry G Coin wrote: Thanks for your help.  Details below.  The problem 'moved' in I hope a diagnositcally useful way, but the system remains broken. On 8/8/23 08:54, Alexander Bokovoy wrote: On Аўт, 08 жні 2023, Harry G Coin wrot

[Freeipa-users] Re: IPA sub-domain in a lab?

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 09 жні 2023, Amos via FreeIPA-users wrote: We currently use (Free)IPA (what's provided by Redhat) in a forest trust relationship with our Active Directory domains. All accounts are defined in AD with the necessary POSIX attributes. The only things locally defined within IPA are the automo

[Freeipa-users] Re: Visibility/access of Freeipa users to windows on trusted AD

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 09 жні 2023, Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: On 2023-02-07 08:20, Alexander Bokovoy via FreeIPA-users wrote: On ma, 06 helmi 2023, Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: Hi, I have searched this everywhere, but can't find it. I want to gra

[Freeipa-users] Re: In FreeIPA AD trust environment add AD user to local group

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 09 жні 2023, Sameer Gurung wrote: On Mon, 31 Jul, 2023, 12:53 Alexander Bokovoy, wrote: On Пан, 31 ліп 2023, Sameer Gurung via FreeIPA-users wrote: >On Sun, Jul 30, 2023 at 10:20 PM Ronald Wimmer via FreeIPA-users < >freeipa-users@lists.fedorahosted.org> wrote: > >> The referenced thre

[Freeipa-users] IPA sub-domain in a lab?

2023-08-09 Thread Amos via FreeIPA-users
We currently use (Free)IPA (what's provided by Redhat) in a forest trust relationship with our Active Directory domains. All accounts are defined in AD with the necessary POSIX attributes. The only things locally defined within IPA are the automounter maps, sudo rules, and HBAC rules. (I must say,

[Freeipa-users] Re: After "writeback to ldap failed" -- silent total freeipa failure / deadlock.

2023-08-09 Thread Mark Reynolds via FreeIPA-users
On 8/9/23 2:00 AM, Alexander Bokovoy wrote: On Аўт, 08 жні 2023, Harry G Coin wrote: Thanks for your help.  Details below.  The problem 'moved' in I hope a diagnositcally useful way, but the system remains broken. On 8/8/23 08:54, Alexander Bokovoy wrote: On Аўт, 08 жні 2023, Harry G Coin wr

[Freeipa-users] Re: In FreeIPA AD trust environment add AD user to local group

2023-08-09 Thread Sameer Gurung via FreeIPA-users
On Mon, 31 Jul, 2023, 12:53 Alexander Bokovoy, wrote: > On Пан, 31 ліп 2023, Sameer Gurung via FreeIPA-users wrote: > >On Sun, Jul 30, 2023 at 10:20 PM Ronald Wimmer via FreeIPA-users < > >freeipa-users@lists.fedorahosted.org> wrote: > > > >> The referenced thread is about merging local and IPA g

[Freeipa-users] Re: Visibility/access of Freeipa users to windows on trusted AD

2023-08-09 Thread Francis Augusto Medeiros-Logeay via FreeIPA-users
On 2023-02-07 08:20, Alexander Bokovoy via FreeIPA-users wrote: On ma, 06 helmi 2023, Francis Augusto Medeiros-Logeay via FreeIPA-users wrote: Hi, I have searched this everywhere, but can't find it. I want to grant access to a FreeIPA user to a Windows machine. When I try to grant the user

[Freeipa-users] Re: ipaserver.ipa.1017.abc can not serve DNS for 1017.abc

2023-08-09 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 09 жні 2023, Alan Latteri via FreeIPA-users wrote: OKbut why is this? It is a very clean and standard install of FreeIPA, the domains are added via standard methods in the GUI. Everything but apex domain of the IPA server works totally fine. No reason this should not work. What is