I have connected my FreeIPA server with an AD in trust. Is it possible
to assign special permissions (sudo) to some AD users? I noticed that
the policies can only be set to AD group.
Thanks in advance,
Is that any configuration where I can set up 2 or 3 master replication in multi site and each of those master have different domain such as ipa.example-site1.com, ida.example2-site2.com?
Is this possible using the ida-server-replication?
Thanks in advance
I have a working trust between my IPA server and an AD domain, I can lookup accounts and login to the IPA-server using AD accounts. I am however unable to to do the same when I connect a client to the IPA-server, the local IPA-accounts are available such as admin, but not AD accounts. I have tried to to a realm join and also using the ipa-client-install directly without success. Are there any additional steps that needs to be done to access accounts over the trust? I have some debug output on pastebin also: https://pastebin.com/xy9SbCw4 <https://pastebin.com/xy9SbCw4>
One of my staff made a typo in his shell in “ipa user-mod —shell” It can be hard to recover from, since you can’t login.
Is there a way to restrict what they can use? Traditionally only shells in /etc/shells were valid.
Any one has such exp ,certomonger always fail after reboot.
Dbus service / other service seem working fine. Any systemctl cannot run
Also it is not cluster any hints.
Error getting authority: Error initializing authority: Error calling
StartServiceByName for org.freedesktop.PolicyKit1:
GDBus.Error:org.freedesktop.DBus.Error.TimedOut: Activation of
org.freedesktop.PolicyKit1 timed out (g-dbus-error-quark, 20)
Failed to execute operation: Connection timed out
VERSION: 4.5.0, API_VERSION: 2.228
At some point in the WebUI Freeipa, the last known type of user
authorization is used.
Changing the type of authorization of the user does not change anything.
For example, if the user has set the OTP authorization type and change it
to a password, FreeIPA WebUI ignores this and waits for OTP input. And vice
If the user has set the password authorization type and change it to OTP,
logon only by password will work.
kinit and everything else works correctly.
I did not find any error messages in logs. (httpd, krb5, slapd)
Does anyone know how to fix this?
P.S. The official demo has the same problem.
I have added my own userattribute which works perfectly fine from the webgui and the cli but not using the API where I get this error from as response:
3005 Unknown option: <myAttrName>
I thought this would lineup easily, what goes wrong ?