<table cellspacing="0" cellpadding="0" border="0" ><tr><td valign="top" style="font: inherit;"><pre>Hi all,<br><br><br>I need help to migrate NIS server to freeipa. What is the way to import ldif<br>file to freeipa?<br><br>Thanks.<br></pre><br><br>--- El <b>lun 10-nov-08, freeipa-users-request@redhat.com <i><freeipa-users-request@redhat.com></i></b> escribió:<br><blockquote style="border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5px;">De: freeipa-users-request@redhat.com <freeipa-users-request@redhat.com><br>Asunto: Freeipa-users Digest, Vol 4, Issue 6<br>A: freeipa-users@redhat.com<br>Fecha: lunes, 10 noviembre, 2008, 5:00 pm<br><br><pre>Send Freeipa-users mailing list submissions to<br> freeipa-users@redhat.com<br><br>To subscribe or unsubscribe via the World Wide Web, visit<br> https://www.redhat.com/mailman/listinfo/freeipa-users<br>or, via email, send a message with subject or body 'help' to<br>
freeipa-users-request@redhat.com<br><br>You can reach the person managing the list at<br> freeipa-users-owner@redhat.com<br><br>When replying, please edit your Subject line so it is more specific<br>than "Re: Contents of Freeipa-users digest..."<br><br><br>Today's Topics:<br><br> 1. Re: Freeipa-users Digest, Vol 4, Issue 5 (luis lugo)<br> 2. GSSAPI Failure (Konstantin Kozlov)<br><br><br>----------------------------------------------------------------------<br><br>Message: 1<br>Date: Sun, 9 Nov 2008 18:01:04 -0800 (PST)<br>From: luis lugo <luis_lugo74@yahoo.com><br>Subject: [Freeipa-users] Re: Freeipa-users Digest, Vol 4, Issue 5<br>To: freeipa-users@redhat.com<br>Message-ID: <100913.40731.qm@web38601.mail.mud.yahoo.com><br>Content-Type: text/plain; charset="utf-8"<br><br>Hi all,<br><br><br>I need help to migrate NIS server to freeipa. What is the way to import ldif<br>file to freeipa?<br><br><br>Thanks.<br><br>--- El vie 7-nov-08,
freeipa-users-request@redhat.com<br><freeipa-users-request@redhat.com> escribió:<br>De: freeipa-users-request@redhat.com <freeipa-users-request@redhat.com><br>Asunto: Freeipa-users Digest, Vol 4, Issue 5<br>A: freeipa-users@redhat.com<br>Fecha: viernes, 7 noviembre, 2008, 5:00 pm<br><br>Send Freeipa-users mailing list submissions to<br> freeipa-users@redhat.com<br><br>To subscribe or unsubscribe via the World Wide Web, visit<br> https://www.redhat.com/mailman/listinfo/freeipa-users<br>or, via email, send a message with subject or body 'help' to<br> freeipa-users-request@redhat.com<br><br>You can reach the person managing the list at<br> freeipa-users-owner@redhat.com<br><br>When replying, please edit your Subject line so it is more specific<br>than "Re: Contents of Freeipa-users digest..."<br><br><br>Today's Topics:<br><br> 1. Re: Need help with Solaris Host Based access control<br> (Christian Horn)<br> 2. Re: Windows clients
problem (Konstantin Kozlov)<br> 3. Re: Windows clients problem (Konstantin Kozlov)<br> 4. Re: [Freeipa-devel] Re: [Freeipa-users] Need help with<br> Solaris Host Based access control (Dmitri Pal)<br><br><br>----------------------------------------------------------------------<br><br>Message: 1<br>Date: Fri, 7 Nov 2008 09:13:30 +0100<br>From: Christian Horn <chorn@fluxcoil.net><br>Subject: Re: [Freeipa-users] Need help with Solaris Host Based access<br> control<br>To: Dmitri Pal <dpal@redhat.com><br>Cc: freeipa-devel <freeipa-devel@redhat.com>, freeipa-users@redhat.com<br>Message-ID: <20081107081330.GA13820@fluxcoil.net><br>Content-Type: text/plain; charset=us-ascii<br><br>Mornings,<br><br>On Wed, Nov 05, 2008 at 03:49:07PM -0500, Dmitri Pal wrote:<br>> <br>> The instructions are based on the ability of the pam_access PAM module <br>> to check the access control rules specified in the access.conf.<br>> The
group information can be retrieved from the IPA server via nss_ldap.<br>> <br>> We tried to find similar functionality on other OS's. We spotted PAM <br>> modules on HP-UX and AIX that are responsible for the similar <br>> authorization checks.<br>> <br>> But we are stuck with Solaris. All our investigations about similar <br>> functionality in Solaris bear no fruits. We saw pam_roles and <br>> pam_unix_account on Solaris but they do not seem to accomplish what we <br>> are trying to do.<br>> <br>> We are looking for some help and advice from Solaris experts on this <br>> functionality.<br><br>Checked with solaris-guys, this is in use for pure ldap-authentication/<br>authorization.<br>Apparently just after hooking up a solaris-box to an ldap no user<br>is allowed to login.<br><br>The permissions to login are handled by this:<br><br>a) entries in /etc/passwd, containing names of NIS-netgroups<br> whose members are
allowed to log in, i.e.<br><br> +@netgroup1::::::<br><br>b) entries in /etc/shadow, containing names of NIS-netgroups<br> whose members are allowed to log in, i.e.<br><br> +@netgroup1::::::::<br> (thats 8 colons vs. 6 on the /etcx/passwd-entries)<br><br>c) entries in /etc/nsswitch.conf for this to work:<br><br> passwd: compat<br> passwd_compat: ldap [NOTFOUND=return]<br><br><br>I dont use this myself on Solaris-boxen but should be enough to see<br>the Solaris-way to handle those login-authorizations.<br><br><br>Christian<br><br><br><br>------------------------------<br><br>Message: 2<br>Date: Fri, 07 Nov 2008 14:32:04 +0300<br>From: Konstantin Kozlov <kozlov@spbcas.ru><br>Subject: Re: [Freeipa-users] Windows clients problem<br>To: freeipa-users@redhat.com<br>Message-ID: <49142734.4000008@spbcas.ru><br>Content-Type: text/plain; charset=KOI8-R; format=flowed<br><br>Hello,<br><br>Johan Venter wrote:<br>> Konstantin Kozlov
wrote:<br>>> WinXP machine asks to login to Kerberos realm at login screen, but <br>>> doesn't let me in. The krb5 log file on IPA server shows that<br>ticket <br>>> was issued. I can get ticket with MIT Kerberos from WinXP machine but <br>>> I can't access samba share.<br>> <br>> I had to add -e des-cbc-crc to the ipa-getkeytab command line I used to <br>> generate the Windows host principal and set the password before Windows <br>> login to the Kerberos realm would work.<br>> <br>> Windows XP/Server 2003 doesn't support useful encryption mechanisms.<br>> <br><br>I did that also and that didn't work. Do I need to install the keytab on <br>WinXP machine? If yes, how?<br><br>Thank you,<br><br>-- <br>Konstantin Kozlov<br>Department of Computational Biology,<br>Center for Advanced Studies,<br>SPb State Polytechnical University,<br>195251, Polytechnicheskaya ul., 29,<br>bld 4, office 204,<br>St.Petersburg,
Russia.<br><br>Tel./fax: +7 812 596 2831<br><br><br><br>------------------------------<br><br>Message: 3<br>Date: Fri, 07 Nov 2008 14:54:34 +0300<br>From: Konstantin Kozlov <kozlov@spbcas.ru><br>Subject: Re: [Freeipa-users] Windows clients problem<br>To: freeipa-users@redhat.com<br>Message-ID: <49142C7A.5010508@spbcas.ru><br>Content-Type: text/plain; charset=KOI8-R; format=flowed<br><br>Thank you for the help!<br><br>After another round of googling I've found that XP uses rc4-hmac...I'll<br><br>try that next day.<br><br>Johan Venter wrote:<br>> Konstantin Kozlov wrote:<br>>> Hello,<br>>><br>>> Johan Venter wrote:<br>>>> Konstantin Kozlov wrote:<br>>>>> WinXP machine asks to login to Kerberos realm at login screen,<br>but <br>>>>> doesn't let me in. The krb5 log file on IPA server shows<br>that ticket <br>>>>> was issued. I can get ticket with MIT Kerberos from WinXP<br>machine
<br>>>>> but I can't access samba share.<br>>>><br>>>> I had to add -e des-cbc-crc to the ipa-getkeytab command line I<br>used <br>>>> to generate the Windows host principal and set the password before<br><br>>>> Windows login to the Kerberos realm would work.<br>>>><br>>>> Windows XP/Server 2003 doesn't support useful encryption<br>mechanisms.<br>>>><br>>><br>>> I did that also and that didn't work. Do I need to install the<br>keytab <br>>> on WinXP machine? If yes, how?<br>>><br>> <br>> Hmm .. I had to use the latest version of ipa-getkeytab (which supported <br>> the password option - I compiled my own RPMs for CentOS) and between <br>> that, then -e option and ksetup /setcomputerpassword it finally worked <br>> on my Windows Server 2003 machines.<br>> <br>> Maybe there is something different with XP machines, all I can suggest
<br>> is try the different encryption types and see what works (DES generally, <br>> no AES or SHA hashes).<br>> <br>> Johan<br>> <br><br><br>-- <br>Konstantin Kozlov<br>Department of Computational Biology,<br>Center for Advanced Studies,<br>SPb State Polytechnical University,<br>195251, Polytechnicheskaya ul., 29,<br>bld 4, office 204,<br>St.Petersburg, Russia.<br><br>Tel./fax: +7 812 596 2831<br><br><br><br>------------------------------<br><br>Message: 4<br>Date: Fri, 07 Nov 2008 09:27:00 -0500<br>From: Dmitri Pal <dpal@redhat.com><br>Subject: Re: [Freeipa-devel] Re: [Freeipa-users] Need help with<br> Solaris Host Based access control<br>To: Christian Horn <chorn@fluxcoil.net><br>Cc: freeipa-devel <freeipa-devel@redhat.com>, freeipa-users@redhat.com<br>Message-ID: <49145034.8030409@redhat.com><br>Content-Type: text/plain; charset=ISO-8859-1; format=flowed<br><br>Thank you Christian!<br>I will dig more into
it.<br><br>Dmitri<br><br>Christian Horn wrote:<br>> Mornings,<br>><br>> On Wed, Nov 05, 2008 at 03:49:07PM -0500, Dmitri Pal wrote:<br>> <br>>> The instructions are based on the ability of the pam_access PAM module<br><br>>> to check the access control rules specified in the access.conf.<br>>> The group information can be retrieved from the IPA server via<br>nss_ldap.<br>>><br>>> We tried to find similar functionality on other OS's. We spotted<br>PAM <br>>> modules on HP-UX and AIX that are responsible for the similar <br>>> authorization checks.<br>>><br>>> But we are stuck with Solaris. All our investigations about similar <br>>> functionality in Solaris bear no fruits. We saw pam_roles and <br>>> pam_unix_account on Solaris but they do not seem to accomplish what we<br><br>>> are trying to do.<br>>><br>>> We are looking for some help and advice from
Solaris experts on this <br>>> functionality.<br>>> <br>><br>> Checked with solaris-guys, this is in use for pure ldap-authentication/<br>> authorization.<br>> Apparently just after hooking up a solaris-box to an ldap no user<br>> is allowed to login.<br>><br>> The permissions to login are handled by this:<br>><br>> a) entries in /etc/passwd, containing names of NIS-netgroups<br>> whose members are allowed to log in, i.e.<br>><br>> +@netgroup1::::::<br>><br>> b) entries in /etc/shadow, containing names of NIS-netgroups<br>> whose members are allowed to log in, i.e.<br>><br>> +@netgroup1::::::::<br>> (thats 8 colons vs. 6 on the /etcx/passwd-entries)<br>><br>> c) entries in /etc/nsswitch.conf for this to work:<br>><br>> passwd: compat<br>> passwd_compat: ldap [NOTFOUND=return]<br>><br>><br>> I dont use this myself on Solaris-boxen but should be
enough to see<br>> the Solaris-way to handle those login-authorizations.<br>><br>><br>> Christian<br>><br>> _______________________________________________<br>> Freeipa-devel mailing list<br>> Freeipa-devel@redhat.com<br>> https://www.redhat.com/mailman/listinfo/freeipa-devel<br>><br>><br>> <br><br><br><br>------------------------------<br><br>_______________________________________________<br>Freeipa-users mailing list<br>Freeipa-users@redhat.com<br>https://www.redhat.com/mailman/listinfo/freeipa-users<br><br>End of Freeipa-users Digest, Vol 4, Issue 5<br>*******************************************<br><br><br><br> <br>____________________________________________________________________________________<br>¡Todo sobre Amor y Sexo!<br>La guía completa para tu vida en Mujer de Hoy. <br>http://mujerdehoy.telemundo.yahoo.com/<br>-------------- next part --------------<br>An HTML attachment was
scrubbed...<br>URL:<br>https://www.redhat.com/archives/freeipa-users/attachments/20081109/2e5fc195/attachment.html<br><br>------------------------------<br><br>Message: 2<br>Date: Mon, 10 Nov 2008 16:53:08 +0300<br>From: Konstantin Kozlov <kozlov@spbcas.ru><br>Subject: [Freeipa-users] GSSAPI Failure<br>To: freeipa-users@redhat.com<br>Message-ID: <49183CC4.6070209@spbcas.ru><br>Content-Type: text/plain; charset=KOI8-R; format=flowed<br><br>Hello,<br><br>I have the following problem.<br><br>On the ipaserver after reboot I get the following error:<br><br># kinit admin<br># ipa-finduser admin<br>Connection to database failed: Invalid credentials: SASL(-13): <br>authentication failure: GSSAPI Failure: gss_accept_sec_context<br><br>However it is possible to login to ipaclient with ipauser.<br><br>Before reboot it worked.<br><br>Does anybody have any ideas what is wrong?<br><br>Thank you in advance,<br><br>-- <br>Konstantin Kozlov<br>Department of
Computational Biology,<br>Center for Advanced Studies,<br>SPb State Polytechnical University,<br>195251, Polytechnicheskaya ul., 29,<br>bld 4, office 204,<br>St.Petersburg, Russia.<br><br>Tel./fax: +7 812 596 2831<br><br><br><br>------------------------------<br><br>_______________________________________________<br>Freeipa-users mailing list<br>Freeipa-users@redhat.com<br>https://www.redhat.com/mailman/listinfo/freeipa-users<br><br>End of Freeipa-users Digest, Vol 4, Issue 6<br>*******************************************<br></pre></blockquote></td></tr></table><br>
<hr size=1><br><font face="Verdana" size="-2">Premios MTV 2008<br>¡En exclusiva! Fotos, nominados, videos, y mucho más!br>Mira aquí http://mtvla.yahoo.com/</font>