[Freeipa-users] Re: cannot login on FreeIPA web GUI: Your session has expired. Please log in again.

2024-01-24 Thread Jochen Kellner via FreeIPA-users
Alexander Bokovoy via FreeIPA-users writes: > As discussions on this mailing list show, there are plenty of edge > cases, mostly around 'legacy' UID/GIDs and missing ID ranges that would > have covered those IDs. Or ID ranges missing SID-specific attributes > (base RID and secondary base RID) tha

[Freeipa-users] Re: Cannot login to FreeIPA as 'admin' user...

2024-01-24 Thread Tom Spettigue via FreeIPA-users
Password isn't expired, I can `kinit admin` and I am not prompted to change my password. Further, running `ipa-cert-fix` updated the certificate at `/var/kerberos/krb5kdc/kdc.crt`, but that did not solve the login issue. I get the following in the logs: [Wed Jan 24 10:58:58.693971 2024] [:error

[Freeipa-users] Re: Is it possible to install FreeIPA on different disk than ('/')

2024-01-24 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 24 сту 2024, Ronald Wimmer via FreeIPA-users wrote: On 24.01.24 15:35, Finn Fysj via FreeIPA-users wrote: Currently our installation of FreeIPA is done on root ('/'). Is it possible to install FreeIPA on different disk & mount path wihtout causing too much issues? FreeIPA consists of

[Freeipa-users] Re: Is it possible to install FreeIPA on different disk than ('/')

2024-01-24 Thread Ronald Wimmer via FreeIPA-users
On 24.01.24 15:35, Finn Fysj via FreeIPA-users wrote: Currently our installation of FreeIPA is done on root ('/'). Is it possible to install FreeIPA on different disk & mount path wihtout causing too much issues? FreeIPA consists of several components (389DS, Apache, Dogtag, Samba, DNS, ...).

[Freeipa-users] Is it possible to install FreeIPA on different disk than ('/')

2024-01-24 Thread Finn Fysj via FreeIPA-users
Currently our installation of FreeIPA is done on root ('/'). Is it possible to install FreeIPA on different disk & mount path wihtout causing too much issues? -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send

[Freeipa-users] Re: cannot login on FreeIPA web GUI: Your session has expired. Please log in again.

2024-01-24 Thread Harald Dunkel via FreeIPA-users
Hi Alex, On 2024-01-24 10:00:42, Alexander Bokovoy via FreeIPA-users wrote: KCS https://access.redhat.com/articles/7027037 describes a lot of those details, so I would recommend reading through it and investigating your ID range configuration based on those details. We also have upstream docum

[Freeipa-users] Re: FreeIPA or RHEL IdM with Amazon Cognito

2024-01-24 Thread Carlos Lopez via FreeIPA-users
Many thanks Alexander This is what I am looking for ... Best regards, C. L. Martinez From: Alexander Bokovoy Sent: 24 January 2024 12:35 To: FreeIPA users list Cc: Carlos Lopez Subject: Re: [Freeipa-users] FreeIPA or RHEL IdM with Amazon Cognito On

[Freeipa-users] Re: FreeIPA or RHEL IdM with Amazon Cognito

2024-01-24 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 24 сту 2024, Carlos Lopez via FreeIPA-users wrote: Hi all, I need to integrate authentication and role access for a few users between Amazon Cognito and FreeIPA/IdM. The idea is that the user logs in with Cognito but the access validation, password changes, roles, etc. are hosted in Free

[Freeipa-users] FreeIPA or RHEL IdM with Amazon Cognito

2024-01-24 Thread Carlos Lopez via FreeIPA-users
Hi all, I need to integrate authentication and role access for a few users between Amazon Cognito and FreeIPA/IdM. The idea is that the user logs in with Cognito but the access validation, password changes, roles, etc. are hosted in FreeIPA. The resources where users login are outside of Amazon

[Freeipa-users] Re: freeipa.py plugin for AWX dynamic inventory not available

2024-01-24 Thread slek kus via FreeIPA-users
Hi Rafael, I use ansible automation platform (redhat downstream of awx). The Ansible version is 2.15.6. The error is expected as (as you mention) no plugin is provided with the ansible-freeipa collection. A dynamic inventory plugin would be so helpful with the Ansible collection. Currently, I n

[Freeipa-users] Re: cannot login on FreeIPA web GUI: Your session has expired. Please log in again.

2024-01-24 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 24 сту 2024, Harald Dunkel wrote: Hi Alex, On 2024-01-24 08:13:44, Alexander Bokovoy wrote: On Аўт, 23 сту 2024, Harald Dunkel wrote: I found one problem by now: Regular UIDs start with 501 in my environment, for historical reasons. The GIDs are >=1000. When we migrated from good ol' y

[Freeipa-users] Re: Different ID ranges cannot login to samba

2024-01-24 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 24 сту 2024, Rui Gomes via FreeIPA-users wrote: Hello Everyone, We are experiencing a strange error, where we have 2 ID ranges. The default one always worked well with samba, we have add a second ID range that works perfectly for everything but no user in that range can login to samba.

[Freeipa-users] Re: cannot login on FreeIPA web GUI: Your session has expired. Please log in again.

2024-01-24 Thread Harald Dunkel via FreeIPA-users
Hi Alex, On 2024-01-24 08:13:44, Alexander Bokovoy wrote: On Аўт, 23 сту 2024, Harald Dunkel wrote: I found one problem by now: Regular UIDs start with 501 in my environment, for historical reasons. The GIDs are >=1000. When we migrated from good ol' yellow pages to FreeIPA there was no problem

[Freeipa-users] Different ID ranges cannot login to samba

2024-01-24 Thread Rui Gomes via FreeIPA-users
Hello Everyone, We are experiencing a strange error, where we have 2 ID ranges. The default one always worked well with samba, we have add a second ID range that works perfectly for everything but no user in that range can login to samba. All the users in the default ID range can authenticate wit