<div dir="ltr">HI<div><br></div><div>Thanks for the information. When i run ipa-advise, i am getting below output, which advice i need to choose. all of them are pointing to linux based</div><div><br></div><div><div>[root@kwtpocpbis01 ~]# ipa-advise</div><div>----------------------------------------------------------------------</div><div>List of available advices</div><div>----------------------------------------------------------------------</div><div> config-fedora-authconfig : Authconfig instructions for</div><div> configuring Fedora 18/19 client with</div><div> IPA server without use of SSSD.</div><div> config-freebsd-nss-pam-ldapd : Instructions for configuring a</div><div> FreeBSD system with nss-pam-ldapd.</div><div> config-generic-linux-nss-pam-ldapd : Instructions for configuring a system</div><div> with nss-pam-ldapd. This set of</div><div> instructions is targeted for linux</div><div> systems that do not include the</div><div> authconfig utility.</div><div> config-generic-linux-sssd-before-1-9 : Instructions for configuring a system</div><div> with an old version of SSSD (1.5-1.8)</div><div> as a FreeIPA client. This set of</div><div> instructions is targeted for linux</div><div> systems that do not include the</div><div> authconfig utility.</div><div> config-redhat-nss-ldap : Instructions for configuring a system</div><div> with nss-ldap as a FreeIPA client.</div><div> This set of instructions is targeted</div><div> for platforms that include the</div><div> authconfig utility, which are all Red</div><div> Hat based platforms.</div><div> config-redhat-nss-pam-ldapd : Instructions for configuring a system</div><div> with nss-pam-ldapd as a FreeIPA</div><div> client. This set of instructions is</div><div> targeted for platforms that include</div><div> the authconfig utility, which are all</div><div> Red Hat based platforms.</div><div> config-redhat-sssd-before-1-9 : Instructions for configuring a system</div><div> with an old version of SSSD (1.5-1.8)</div><div> as a FreeIPA client. This set of</div><div> instructions is targeted for</div><div> platforms that include the authconfig</div><div> utility, which are all Red Hat based</div><div> platforms.</div><div><br></div><div><br></div><div>thanks & Regards,</div><div>Ben</div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jan 5, 2015 at 6:54 PM, Dmitri Pal <span dir="ltr"><<a href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<div text="#000000" bgcolor="#FFFFFF"><span class="">
<div>On 01/05/2015 10:51 AM, Dmitri Pal
wrote:<br>
</div>
<blockquote type="cite">
<div>On 01/04/2015 10:30 PM, Ben .T.George
wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr">HI
<div><br>
</div>
<div>yes you are right. Linux clients working and IPA is in
trust relationship with AD.</div>
<div><br>
</div>
<div>currently i am using 3.3.3 i guess i didn't tryed
ipa-advice tool yet. I am not aware about this tool. can you
please give right directions regarding this tool, so that i
can try on it.</div>
<div><br>
</div>
<div>regarding manuals and tutorials:</div>
<div><br>
</div>
<div><a href="http://www.freeipa.org/page/ConfiguringUnixClients#Solaris_8.2F9.2F10" target="_blank">http://www.freeipa.org/page/ConfiguringUnixClients#Solaris_8.2F9.2F10</a><br>
</div>
<div><a href="http://www.freeipa.org/docs/1.2/Client_Setup_Guide/en-US/html/chap-Client_Configuration_Guide-Configuring_Solaris_as_an_IPA_Client.html" target="_blank">http://www.freeipa.org/docs/1.2/Client_Setup_Guide/en-US/html/chap-Client_Configuration_Guide-Configuring_Solaris_as_an_IPA_Client.html</a><br>
</div>
<div><a href="http://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_Solaris.html" target="_blank">http://docs.fedoraproject.org/en-US/Fedora/17/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_Solaris.html</a><br>
</div>
<div><a href="http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_Solaris.html" target="_blank">http://docs.fedoraproject.org/en-US/Fedora/15/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_Solaris.html</a><br>
</div>
</div>
</blockquote>
<br>
I think this should help:<br>
<a href="http://www.freeipa.org/images/0/0d/FreeIPA33-legacy-clients.pdf" target="_blank">http://www.freeipa.org/images/0/0d/FreeIPA33-legacy-clients.pdf</a><br>
It mentions the tool too.<br>
</blockquote>
<br></span>
You need to point your Solaris clients to compat tree.<div><div class="h5"><br>
<br>
<blockquote type="cite"> <br>
<blockquote type="cite">
<div dir="ltr">
<div><br>
</div>
<div>Regards,Ben</div>
<div><br>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Mon, Jan 5, 2015 at 12:34 AM,
Dmitri Pal <span dir="ltr"><<a href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<div text="#000000" bgcolor="#FFFFFF"><span>
<div>On 01/04/2015 01:19 PM, Ben .T.George wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr"><br>
<div class="gmail_extra">HI</div>
<div class="gmail_extra"><br>
</div>
<div class="gmail_extra">Thanks for the
replay.</div>
<div class="gmail_extra"><br>
</div>
<div class="gmail_extra">i was trying to
achieve just LDAP authentication only. If
possible Role based access and Host based
access. but most priority is to authenticate
solaris against Active Directory/IPA</div>
<div class="gmail_extra"><br>
</div>
<div class="gmail_extra">The tutorials/Guides
are not clear actually as i tried many
times. My IPA server is working fine. bcoz i
tested by adding linux(centos) as IPA client
by using client ass ipa commands.</div>
</div>
</blockquote>
<br>
</span> OK, so let me make sure I get you right: you
have IPA and it is in trust relations with AD,
right? You tested it from Linux clients and it works
but not with Solaris client, right? Which version of
IPA are you using? Have you looked at ipa-advise
tool?<br>
Which manuals and tutorials you tried?
<div>
<div><br>
<br>
<blockquote type="cite">
<div dir="ltr">
<div class="gmail_extra"><br>
</div>
<div class="gmail_extra">Regards,</div>
<div class="gmail_extra">Ben</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Sun, Jan 4,
2015 at 7:11 PM, Dmitri Pal <span dir="ltr"><<a href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<div text="#000000" bgcolor="#FFFFFF"><span>
<div>On 01/04/2015 02:10 AM, Ben
.T.George wrote:<br>
</div>
<blockquote type="cite">
<div dir="ltr">HI
<div><br>
</div>
<div>This is i am struggling
to get this working on
Solaris x86 client. as i did
many things based on many
tutorials. \i am wondering
why people who achieved this
already not sharing this
information about
configuring Solaris as IPA
client .</div>
</div>
</blockquote>
<br>
</span> Solaris can be configured to
be a client of IPA so it seems that
there is some misalignment of the
expectations.<br>
What is your goal? What kind of
integration for Solaris client you
want to achieve? Just LDAP
authentication would work following
the instructions.<br>
I suspect that something that you
are trying to accomplish is either
done differently or have not been a
priority for others and thus have
not been explored.
<div>
<div><br>
<br>
<blockquote type="cite">
<div dir="ltr">
<div><br>
</div>
<div>Regards,</div>
<div>Ben<br>
<div class="gmail_extra"><br>
<div class="gmail_quote">On
Mon, Dec 29, 2014 at
11:59 PM, Dmitri Pal <span dir="ltr"><<a href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><span>On
12/21/2014 07:50
PM, Fraser
Tweedale wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
On Sun, Dec 21,
2014 at
09:03:17AM
+0300, Ben
.T.George wrote:<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
Hi List<br>
<br>
how can i
configure
solaris 10
sparc and x86
as ipa
clients.<br>
<br>
Regards,<br>
Ben<br>
</blockquote>
Hi Ben,<br>
<br>
Please follow
the Solaris
8/9/10
instructions on
the wiki:<br>
<a href="http://www.freeipa.org/page/ConfiguringUnixClients#Solaris_8.2F9.2F10" target="_blank">http://www.freeipa.org/page/ConfiguringUnixClients#Solaris_8.2F9.2F10</a><br>
<br>
Let us know if
run into
difficulties or
if there are
error or<br>
omissions in the
instructions.<br>
</blockquote>
<br>
</span> Also see <a href="https://fedorahosted.org/freeipa/ticket/4633" target="_blank">https://fedorahosted.org/freeipa/ticket/4633</a><span><br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
<br>
Cheers,<br>
<br>
Fraser<br>
<br>
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex">
-- <br>
Manage your
subscription
for the
Freeipa-users
mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go To <a href="http://freeipa.org" target="_blank">http://freeipa.org</a> for
more info on
the project<br>
</blockquote>
</blockquote>
<br>
<br>
</span><span><font color="#888888">
-- <br>
Thank you,<br>
Dmitri Pal<br>
<br>
Sr. Engineering
Manager IdM
portfolio<br>
Red Hat, Inc.</font></span>
<div>
<div><br>
<br>
-- <br>
Manage your
subscription for
the
Freeipa-users
mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go To <a href="http://freeipa.org" target="_blank">http://freeipa.org</a> for
more info on the
project<br>
</div>
</div>
</blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
</div>
</div>
</div>
</blockquote>
<br>
<br>
<pre cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
</div>
</div>
</div>
</blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
<div>
<div dir="ltr">
<div><span style="border-collapse:collapse"><font size="1" face="'courier new',
monospace"><font color="#ff9900"><br>
</font></font></span></div>
</div>
</div>
</div>
</div>
</blockquote>
<br>
<br>
<pre cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
</div>
</div>
</div>
</blockquote>
</div>
<br>
<br clear="all">
<div><br>
</div>
</div>
</div>
</div>
</blockquote>
<br>
<br>
<pre cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
<br>
<fieldset></fieldset>
<br>
</blockquote>
<br>
<br>
<pre cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
</div></div></div>
<br>--<br>
Manage your subscription for the Freeipa-users mailing list:<br>
<a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
Go To <a href="http://freeipa.org" target="_blank">http://freeipa.org</a> for more info on the project<br></blockquote></div><br><div class="gmail_signature"><div dir="ltr"><div><span style="border-collapse:collapse"><font face="'courier new', monospace" size="1"><font color="#ff9900"><br></font></font></span></div></div></div>
</div></div></div>