[Freeipa-users] Re: IPA CA Broken due to expired ocspSigningCert

2025-04-15 Thread Mark Selby via FreeIPA-users
Thank you very much for your response. I have done some further debugging and have more info in out situation and what the genesis of the issue is. I am hoping you have some suggestions on a resolution I am in a bit of a pickle (1) We have nightly full backups of IPA but they have been running

[Freeipa-users] Re: Keytabs for multiple domains

2025-04-15 Thread Alexander Bokovoy via FreeIPA-users
On Пан, 14 кра 2025, Entrepreneur AJ via FreeIPA-users wrote: I am a little confused on best way to make this work. I have a fresh install of both the latest FreeIPA server and Keycloak server, my laptop is enrolled with FreeIPA client. My browser is configured to login to my ipa domain via ker

[Freeipa-users] Re: Keytabs for multiple domains

2025-04-15 Thread Entrepreneur AJ via FreeIPA-users
Thanks for the information Alexander, I managed to get it working for reference for others in the future I did the following: 1) Enrolled the keycloak server with FreeIPA using ipa-client-install then rebooted. 2) On the FreeIPA gui under the identity tab and services sub tab i created 3 new se

[Freeipa-users] Re: FW: First login takes ages

2025-04-15 Thread Ronald Wimmer via FreeIPA-users
On 10.04.25 00:15, Ronald Wimmer via FreeIPA-users wrote: On 09.04.25 23:22, Larkin, Patrick wrote: > Are you using Automount? No. > Also, do you have lots of groups? No. > And are these identities part of an AD trust or completely internal to IPA/IDM? IPA only. I am aware of problems comin