ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    FreeIPA Server & Client

    IT Discussion
    4
    47
    6.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stacksofplatesS
      stacksofplates
      last edited by

      Looks fairly normal. What's in your /etc/nsswitch.conf file?

      1 Reply Last reply Reply Quote 0
      • stacksofplatesS
        stacksofplates
        last edited by

        Also, if you log into the system with a different user, can you do a kinit ldapuser to get a kerberos ticket?

        AlyRagabA 1 Reply Last reply Reply Quote 1
        • AlyRagabA
          AlyRagab @stacksofplates
          last edited by

          @stacksofplates the " /etc/nsswitch.conf "

          passwd: files sss
          shadow: files sss
          group: files sss
          #initgroups: files

          #hosts: db files nisplus nis dns
          hosts: files mdns4_minimal [NOTFOUND=return] dns myhostname

          Example - obey only what nisplus tells us...

          #services: nisplus [NOTFOUND=return] files
          #networks: nisplus [NOTFOUND=return] files
          #protocols: nisplus [NOTFOUND=return] files
          #rpc: nisplus [NOTFOUND=return] files
          #ethers: nisplus [NOTFOUND=return] files
          #netmasks: nisplus [NOTFOUND=return] files

          bootparams: nisplus [NOTFOUND=return] files

          ethers: files
          netmasks: files
          networks: files
          protocols: files
          rpc: files
          services: files sss

          netgroup: files sss

          publickey: nisplus

          automount: files sss
          aliases: files nisplus
          sudoers: files sss

          ==============
          also what make the case is very strange is that i can do kinit ldapuser normally and su - user
          also getent passwd user
          but can not login as ssh or GUI

          1 Reply Last reply Reply Quote 0
          • AlyRagabA
            AlyRagab
            last edited by

            i think the main question here is : how can we allow the Enterprise Login ?

            1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates
              last edited by

              Did you change the password for the user after you set it?

              Can you log into the IPA web interface with that user?

              AlyRagabA 1 Reply Last reply Reply Quote 0
              • AlyRagabA
                AlyRagab @stacksofplates
                last edited by

                @stacksofplates said in FreeIPA Server & Client:

                Did you change the password for the user after you set it?

                Can you log into the IPA web interface with that user?

                the password is changed in the first login
                and also i can access the IPA web interface with that user

                1 Reply Last reply Reply Quote 0
                • stacksofplatesS
                  stacksofplates
                  last edited by

                  It really sounds like it's something to do with pam. You can try doing an authconfig --update and see if that helps. If not, I'd just reinstall the ipa-client.

                  1 Reply Last reply Reply Quote 1
                  • stacksofplatesS
                    stacksofplates
                    last edited by

                    Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                    AlyRagabA 1 Reply Last reply Reply Quote 0
                    • stacksofplatesS
                      stacksofplates
                      last edited by

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • stacksofplatesS
                        stacksofplates
                        last edited by

                        This post is deleted!
                        1 Reply Last reply Reply Quote 0
                        • AlyRagabA
                          AlyRagab @stacksofplates
                          last edited by

                          @stacksofplates said in FreeIPA Server & Client:

                          Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                          the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                          [root@client ~]# ipa user-find --all
                          ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                          stacksofplatesS 1 Reply Last reply Reply Quote 0
                          • stacksofplatesS
                            stacksofplates @AlyRagab
                            last edited by stacksofplates

                            @AlyRagab said in FreeIPA Server & Client:

                            @stacksofplates said in FreeIPA Server & Client:

                            Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                            the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                            [root@client ~]# ipa user-find --all
                            ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                            That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                            Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @stacksofplates
                              last edited by

                              @stacksofplates said in FreeIPA Server & Client:

                              @AlyRagab said in FreeIPA Server & Client:

                              @stacksofplates said in FreeIPA Server & Client:

                              Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                              the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                              [root@client ~]# ipa user-find --all
                              ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                              That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                              Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                              What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.

                              stacksofplatesS 1 Reply Last reply Reply Quote 0
                              • stacksofplatesS
                                stacksofplates @scottalanmiller
                                last edited by stacksofplates

                                @scottalanmiller said in FreeIPA Server & Client:

                                @stacksofplates said in FreeIPA Server & Client:

                                @AlyRagab said in FreeIPA Server & Client:

                                @stacksofplates said in FreeIPA Server & Client:

                                Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                                the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                                [root@client ~]# ipa user-find --all
                                ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                                That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                                Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                                What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.It

                                I like fedora a lot. But I had CentOS workstation for a long time after 7 came out. It's rock solid, like you have to try to break it. I've had some weird issues with fedora, both 23 and 24 that seemed a little buggy. In my experience Fedora with Gnome has been slower than CentOS with Gnome. Ive only ever found one thing I couldn't run on CentOS and that was FreeCAD, but it didn't run super well on Fedora either.

                                Plus there is the not needing to reinstall every 6 months or whatever the release schedule is.

                                And the fact I work with RHEL 7 WS every day, it feels comfortable.

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @stacksofplates
                                  last edited by

                                  @stacksofplates said in FreeIPA Server & Client:

                                  @scottalanmiller said in FreeIPA Server & Client:

                                  @stacksofplates said in FreeIPA Server & Client:

                                  @AlyRagab said in FreeIPA Server & Client:

                                  @stacksofplates said in FreeIPA Server & Client:

                                  Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                                  the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                                  [root@client ~]# ipa user-find --all
                                  ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                                  That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                                  Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                                  What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.It

                                  I like fedora a lot. But I had CentOS workstation for a long time after 7 came out. It's rock solid, like you have to try to break it. I've had some weird issues with fedora, both 23 and 24 that seemed a little buggy. In my experience Fedora with Gnome has been slower than CentOS with Gnome. Ive only ever found one thing I couldn't run on CentOS and that was FreeCAD, but it didn't run super well on Fedora either.

                                  Plus there is the not needing to reinstall every 6 months or whatever the release schedule is.

                                  I'm stuck with Ubuntu 16.10 on the laptop but run Korora 24 in a VM.

                                  stacksofplatesS 1 Reply Last reply Reply Quote 1
                                  • stacksofplatesS
                                    stacksofplates @scottalanmiller
                                    last edited by

                                    @scottalanmiller said in FreeIPA Server & Client:

                                    @stacksofplates said in FreeIPA Server & Client:

                                    @scottalanmiller said in FreeIPA Server & Client:

                                    @stacksofplates said in FreeIPA Server & Client:

                                    @AlyRagab said in FreeIPA Server & Client:

                                    @stacksofplates said in FreeIPA Server & Client:

                                    Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                                    the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                                    [root@client ~]# ipa user-find --all
                                    ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                                    That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                                    Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                                    What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.It

                                    I like fedora a lot. But I had CentOS workstation for a long time after 7 came out. It's rock solid, like you have to try to break it. I've had some weird issues with fedora, both 23 and 24 that seemed a little buggy. In my experience Fedora with Gnome has been slower than CentOS with Gnome. Ive only ever found one thing I couldn't run on CentOS and that was FreeCAD, but it didn't run super well on Fedora either.

                                    Plus there is the not needing to reinstall every 6 months or whatever the release schedule is.

                                    I'm stuck with Ubuntu 16.10 on the laptop but run Korora 24 in a VM.

                                    I haveKorora 24 Gnome on my laptop currently. Its ok, I still prefer stock Fedora with Gnome though.

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @stacksofplates
                                      last edited by

                                      @stacksofplates said in FreeIPA Server & Client:

                                      @scottalanmiller said in FreeIPA Server & Client:

                                      @stacksofplates said in FreeIPA Server & Client:

                                      @scottalanmiller said in FreeIPA Server & Client:

                                      @stacksofplates said in FreeIPA Server & Client:

                                      @AlyRagab said in FreeIPA Server & Client:

                                      @stacksofplates said in FreeIPA Server & Client:

                                      Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                                      the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                                      [root@client ~]# ipa user-find --all
                                      ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                                      That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                                      Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                                      What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.It

                                      I like fedora a lot. But I had CentOS workstation for a long time after 7 came out. It's rock solid, like you have to try to break it. I've had some weird issues with fedora, both 23 and 24 that seemed a little buggy. In my experience Fedora with Gnome has been slower than CentOS with Gnome. Ive only ever found one thing I couldn't run on CentOS and that was FreeCAD, but it didn't run super well on Fedora either.

                                      Plus there is the not needing to reinstall every 6 months or whatever the release schedule is.

                                      I'm stuck with Ubuntu 16.10 on the laptop but run Korora 24 in a VM.

                                      I haveKorora 24 Gnome on my laptop currently. Its ok, I still prefer stock Fedora with Gnome though.

                                      I use it with Cinnamon, that's the cool bit 🙂

                                      stacksofplatesS 1 Reply Last reply Reply Quote 0
                                      • stacksofplatesS
                                        stacksofplates @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in FreeIPA Server & Client:

                                        @stacksofplates said in FreeIPA Server & Client:

                                        @scottalanmiller said in FreeIPA Server & Client:

                                        @stacksofplates said in FreeIPA Server & Client:

                                        @scottalanmiller said in FreeIPA Server & Client:

                                        @stacksofplates said in FreeIPA Server & Client:

                                        @AlyRagab said in FreeIPA Server & Client:

                                        @stacksofplates said in FreeIPA Server & Client:

                                        Another thing to try, do you have the ipa-admintools package installed on your client? If you do, what output do you get if you kinit and then run ipa user-find --all?

                                        the admintools package is installed , but when i tried to run " ipa user-find --all " it shows this error :
                                        [root@client ~]# ipa user-find --all
                                        ipa: ERROR: 2.114 client incompatible with 2.112 server at 'https://ipa.server.local/ipa/xml'

                                        That's what I feared. I think to be able to run the IPA client on Fedora you will need to run the IPA server on Fedora server, not CentOS.

                                        Or go the opposite and use CentOS 7 workstation instead of Fedora. I actually prefer the CentOS 7 workstation to Fedora, and I'm going to be switching back on my home laptop.

                                        What about CentOS 7 workstation are you liking? I'm a Fedora fan and like Korora's mix of it the most.It

                                        I like fedora a lot. But I had CentOS workstation for a long time after 7 came out. It's rock solid, like you have to try to break it. I've had some weird issues with fedora, both 23 and 24 that seemed a little buggy. In my experience Fedora with Gnome has been slower than CentOS with Gnome. Ive only ever found one thing I couldn't run on CentOS and that was FreeCAD, but it didn't run super well on Fedora either.

                                        Plus there is the not needing to reinstall every 6 months or whatever the release schedule is.

                                        I'm stuck with Ubuntu 16.10 on the laptop but run Korora 24 in a VM.

                                        I haveKorora 24 Gnome on my laptop currently. Its ok, I still prefer stock Fedora with Gnome though.

                                        I use it with Cinnamon, that's the cool bit 🙂

                                        Ah ya, I use Gnome 3 for the extensions.

                                        1 Reply Last reply Reply Quote 0
                                        • AlyRagabA
                                          AlyRagab
                                          last edited by

                                          So what about Ubuntu , i have a client with a lot of ubuntu 14.04 as workstations , do i need to install the FreeIPA on a Ubuntu Server to be compatible with ubuntu workstations ?.

                                          brianlittlejohnB scottalanmillerS stacksofplatesS 3 Replies Last reply Reply Quote 0
                                          • brianlittlejohnB
                                            brianlittlejohn @AlyRagab
                                            last edited by

                                            @AlyRagab I have connected Linux Mint, to a CentOS freeIPA server.

                                            AlyRagabA stacksofplatesS 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post