<div dir="ltr"><div class="gmail_extra"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div style="background-color:rgb(255,255,255)"><div>Great! That worked. </div><div>Thank you so much Rob. Your help is highly appreciated. </div></div></div></div></div></div>
<br><div class="gmail_quote">On Thu, Aug 25, 2016 at 3:49 PM, Rob Crittenden <span dir="ltr"><<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">Linov Suresh wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
I ran ldapsearch -Y GSSAPI, what we are seeing is IPA server 2, ipa02<br>
is missing on both master and replica servers. Do we need to add IPA<br>
server 2, ipa02 on both master and replica?<br>
</blockquote>
<br></span>
No, it should replicate. I find it very strange that these are missing. I wonder what else wasn't setup when the replica was created.<br>
<br>
In any case, this will add the entries:<br>
<br>
# ldapmodify -Y GSSAPI<br>
dn: cn=ipa-http-delegation,cn=s4u2<wbr>proxy,cn=etc,dc=teloip,dc=net<br>
changetype: modify<br>
add: memberPrincipal<br>
memberPrincipal: HTTP/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<br>
^D<br>
<br>
# ldapmodify -Y GSAPI<br>
dn: cn=ipa-ldap-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
hangetype: modify<br>
add: memberPrincipal<br>
memberPrincipal: ldap/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<br>
^D<br>
<br>
rob<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
*[root@ipa01 ~]# ldapsearch -Y GSSAPI -H ldap://<a href="http://ipa01.teloip.net" rel="noreferrer" target="_blank">ipa01.teloip.net</a><br>
<<a href="http://ipa01.teloip.net" rel="noreferrer" target="_blank">http://ipa01.teloip.net</a>> -b "cn=s4u2proxy,cn=etc,dc=teloip<wbr>,dc=net"*<br>
SASL/GSSAPI authentication started<br>
SASL username: <a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a> <mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>><span class=""><br>
SASL SSF: 56<br>
SASL data security layer installed.<br>
# extended LDIF<br>
#<br>
# LDAPv3<br>
# base <cn=s4u2proxy,cn=etc,dc=teloip<wbr>,dc=net> with scope subtree<br>
# filter: (objectclass=*)<br>
# requesting: ALL<br>
#<br>
<br></span>
# s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a> <<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=s4u2proxy,cn=etc,dc=teloip,<wbr>dc=net<br>
objectClass: nsContainer<br>
objectClass: top<br>
cn: s4u2proxy<br>
<br></span>
# ipa-http-delegation, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a> <<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=ipa-http-delegation,cn=s4u2<wbr>proxy,cn=etc,dc=teloip,dc=net<br>
objectClass: ipaKrb5DelegationACL<br>
objectClass: groupOfPrincipals<br>
objectClass: top<br>
ipaAllowedTarget:<br>
cn=ipa-ldap-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
ipaAllowedTarget:<br>
cn=ipa-cifs-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br></span>
*memberPrincipal: HTTP/<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOI<wbr>P.NET</a>>*<span class=""><br>
cn: ipa-http-delegation<br>
<br>
# ipa-cifs-delegation-targets, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a><br></span>
<<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=ipa-cifs-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
objectClass: groupOfPrincipals<br>
objectClass: top<br>
cn: ipa-cifs-delegation-targets<br>
<br>
# ipa-ldap-delegation-targets, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a><br></span>
<<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=ipa-ldap-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
objectClass: groupOfPrincipals<br>
objectClass: top<br></span>
*memberPrincipal: ldap/<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOI<wbr>P.NET</a>>*<span class=""><br>
cn: ipa-ldap-delegation-targets<br>
<br>
# search result<br>
search: 4<br>
result: 0 Success<br>
<br>
# numResponses: 5<br>
# numEntries: 4<br>
[root@ipa01 ~]#<br>
<br></span>
*[root@ipa02 ~]# ldapsearch -Y GSSAPI -H ldap://<a href="http://ipa02.teloip.net" rel="noreferrer" target="_blank">ipa02.teloip.net</a><br>
<<a href="http://ipa02.teloip.net" rel="noreferrer" target="_blank">http://ipa02.teloip.net</a>> -b "cn=s4u2proxy,cn=etc,dc=teloip<wbr>,dc=net"*<br>
SASL/GSSAPI authentication started<br>
SASL username: <a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a> <mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>><span class=""><br>
SASL SSF: 56<br>
SASL data security layer installed.<br>
# extended LDIF<br>
#<br>
# LDAPv3<br>
# base <cn=s4u2proxy,cn=etc,dc=teloip<wbr>,dc=net> with scope subtree<br>
# filter: (objectclass=*)<br>
# requesting: ALL<br>
#<br>
<br></span>
# s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a> <<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=s4u2proxy,cn=etc,dc=teloip,<wbr>dc=net<br>
cn: s4u2proxy<br>
objectClass: nsContainer<br>
objectClass: top<br>
<br></span>
# ipa-http-delegation, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a> <<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><br>
dn: cn=ipa-http-delegation,cn=s4u2<wbr>proxy,cn=etc,dc=teloip,dc=net<br>
cn: ipa-http-delegation<br>
*memberPrincipal: HTTP/<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOI<wbr>P.NET</a>>*<span class=""><br>
ipaAllowedTarget:<br>
cn=ipa-ldap-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
ipaAllowedTarget:<br>
cn=ipa-cifs-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
objectClass: ipaKrb5DelegationACL<br>
objectClass: groupOfPrincipals<br>
objectClass: top<br>
<br>
# ipa-cifs-delegation-targets, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a><br></span>
<<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><span class=""><br>
dn: cn=ipa-cifs-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
cn: ipa-cifs-delegation-targets<br>
objectClass: groupOfPrincipals<br>
objectClass: top<br>
<br>
# ipa-ldap-delegation-targets, s4u2proxy, etc, <a href="http://teloip.net" rel="noreferrer" target="_blank">teloip.net</a><br></span>
<<a href="http://teloip.net" rel="noreferrer" target="_blank">http://teloip.net</a>><br>
dn: cn=ipa-ldap-delegation-targets<wbr>,cn=s4u2proxy,cn=etc,dc=<wbr>teloip,dc=net<br>
cn: ipa-ldap-delegation-targets<br>
*memberPrincipal: ldap/<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa01.teloip.net@TELOIP.NET" target="_blank">ipa01.teloip.net@TELOI<wbr>P.NET</a>>*<span class=""><br>
objectClass: groupOfPrincipals<br>
objectClass: top<br>
<br>
# search result<br>
search: 4<br>
result: 0 Success<br>
<br>
# numResponses: 5<br>
# numEntries: 4<br>
[root@ipa02 ~]#<br>
<br>
Appreciate your help,<br>
<br>
Linov Suresh.<br>
<br>
<br>
<br>
On Wed, Aug 24, 2016 at 4:32 PM, Rob Crittenden <<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a><br></span><span class="">
<mailto:<a href="mailto:rcritten@redhat.com" target="_blank">rcritten@redhat.com</a>>> wrote:<br>
<br>
Linov Suresh wrote:<br>
<br>
Look like our issue is discussed here, and *is **missing one or more<br>
memberPrincipal*.<br>
<br>
<a href="https://www.redhat.com/archives/freeipa-users/2013-April/msg00228.html" rel="noreferrer" target="_blank">https://www.redhat.com/archive<wbr>s/freeipa-users/2013-April/<wbr>msg00228.html</a><br>
<<a href="https://www.redhat.com/archives/freeipa-users/2013-April/msg00228.html" rel="noreferrer" target="_blank">https://www.redhat.com/archiv<wbr>es/freeipa-users/2013-April/<wbr>msg00228.html</a>><br>
<br>
When I tried to add the Principal, I'm getting error,<br>
<br>
<br>
You didn't follow the instructions in the e-mail thread. The problem<br>
isn't a principal that doesn't exist, it is a principal not in the<br>
delegation list. Do the ldapsearch's and see what is missing (and<br>
you'll need to use -Y GSSAPI instead of -x) then add it using<br>
ldapmodify.<br>
<br>
Only under very specific circumstances would I ever recommend using<br>
kadmin.local.<br>
<br>
rob<br>
<br>
<br>
<br>
[root@ipa01 ~]# kadmin.local<br>
Authenticating as principal admin/<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a><br>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>><br></span>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a> <mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>>> with password.<span class=""><br>
kadmin.local: addprinc -randkey<br>
HTTP/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>><br>
WARNING: no policy specified for<br>
HTTP/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>>; defaulting to no policy<br>
add_principal: Principal or policy already exists while creating<br>
"HTTP/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.<wbr>NET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>>"<br>
<br>
[root@ipa01 ~]# kadmin.local<br>
Authenticating as principal admin/<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a><br>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>><br></span>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a> <mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>>> with password.<span class=""><br>
kadmin.local: addprinc -randkey<br>
ldap/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>><br>
WARNING: no policy specified for<br>
ldap/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>>; defaulting to no policy<br>
add_principal: Principal or policy already exists while creating<br>
"ldap/<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOIP.<wbr>NET</a><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>><br></span>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a><span class=""><br>
<mailto:<a href="mailto:ipa02.teloip.net@TELOIP.NET" target="_blank">ipa02.teloip.net@TELOI<wbr>P.NET</a>>>".<br>
<br>
Could you please help us to fix the "*KDC returned error string:<br>
NOT_ALLOWED_TO_DELEGATE*" error?<br>
<br>
<br>
[root@caer ~]# kadmin.local<br>
Authenticating as principal admin/<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a><br>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>><br></span>
<mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a> <mailto:<a href="mailto:admin@TELOIP.NET" target="_blank">admin@TELOIP.NET</a>>> with password.<span class=""><br>
kadmin.local: addprinc -randkey HTTP/<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP.NE<wbr>T</a><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>><br></span>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a><span class=""><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>>><br>
WARNING: no policy specified for HTTP/<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP.NE<wbr>T</a><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>><br></span>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a><span class=""><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>>>; defaulting to no policy<br>
add_principal: Principal or policy already exists while creating<br>
"HTTP/<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP.N<wbr>ET</a><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>><br></span>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a><span class=""><br>
<mailto:<a href="mailto:neit.teloip.net@TELOIP.NET" target="_blank">neit.teloip.net@TELOIP<wbr>.NET</a>>>"<br>
<br>
<br>
<br>
<br>
<br>
<br>
On Tue, Aug 16, 2016 at 7:58 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a><br>
<mailto:<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>><br></span><span class="">
<mailto:<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a> <mailto:<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>>>> wrote:<br>
<br>
On 08/16/2016 09:25 AM, Petr Spacek wrote:<br>
> On 15.8.2016 20:18, Linov Suresh wrote:<br>
>> We have IPA replica set up in RHEL 6.4 and is FreeIPA 3.0.0<br>
>><br>
>><br>
>> We can only add the clients from IPA Server 01, not from<br>
IPA Server 02.<br>
>> When I tried to add the client from IPA Server 02,<br>
getting the error,<br>
>><br>
>><br>
>> ipa: ERROR: Insufficient access: SASL(-1): generic<br>
failure: GSSAPI Error:<br>
>> Unspecified GSS failure. Minor code may provide more<br>
information (KDC<br>
>> returned error string: NOT_ALLOWED_TO_DELEGATE)<br>
>><br>
>> SASL/GSSAPI authentication started<br>
>><br>
>> SASL <a href="mailto:username%3Avpham@EXAMPLE.NET" target="_blank">username:vpham@EXAMPLE.NET</a><br></span>
<mailto:<a href="mailto:username%253Avpham@EXAMPLE.NET" target="_blank">username%3Avpham@EXAMP<wbr>LE.NET</a>> <mailto:<a href="mailto:vpham@EXAMPLE.NET" target="_blank">vpham@EXAMPLE.NET</a><span class=""><br>
<mailto:<a href="mailto:vpham@EXAMPLE.NET" target="_blank">vpham@EXAMPLE.NET</a>>><br>
>><br>
>> SASL SSF: 56<br>
>><br>
>> SASL data security layer installed.<br>
>><br>
>> ldap_modify: No such object (32)<br>
>><br>
>> additional info: Range Check error<br>
>><br>
>> modifying entry "fqdn=<a href="http://cpe-5061747522f9.example.net" rel="noreferrer" target="_blank">cpe-5061747522f9.example<wbr>.net</a><br>
<<a href="http://cpe-5061747522f9.example.net" rel="noreferrer" target="_blank">http://cpe-5061747522f9.examp<wbr>le.net</a>><br></span>
<<a href="http://cpe-5061747522f9.example.net" rel="noreferrer" target="_blank">http://cpe-5061747522f9.examp<wbr>le.net</a><div><div class="h5"><br>
<<a href="http://cpe-5061747522f9.example.net" rel="noreferrer" target="_blank">http://cpe-5061747522f9.examp<wbr>le.net</a>>><br>
>> ,cn=computers,cn=accounts,dc=e<wbr>xample,dc=net"<br>
>><br>
>><br>
>> Could you please help us to fix this?<br>
><br>
> We need to see exact steps you did before we can give<br>
you any<br>
meaningful advice.<br>
><br>
> Please have a look at<br>
> <a href="http://www.chiark.greenend.org.uk/~sgtatham/bugs.html" rel="noreferrer" target="_blank">http://www.chiark.greenend.org<wbr>.uk/~sgtatham/bugs.html</a><br>
<<a href="http://www.chiark.greenend.org.uk/~sgtatham/bugs.html" rel="noreferrer" target="_blank">http://www.chiark.greenend.or<wbr>g.uk/~sgtatham/bugs.html</a>><br>
<<a href="http://www.chiark.greenend.org.uk/~sgtatham/bugs.html" rel="noreferrer" target="_blank">http://www.chiark.greenend.o<wbr>rg.uk/~sgtatham/bugs.html</a><br>
<<a href="http://www.chiark.greenend.org.uk/~sgtatham/bugs.html" rel="noreferrer" target="_blank">http://www.chiark.greenend.or<wbr>g.uk/~sgtatham/bugs.html</a>>><br>
><br>
> It is a very nice document which describes general bug<br>
reporting<br>
procedure and<br>
> best practices.<br>
><br>
> We will certainly have a look but we need first see the<br>
information :-)<br>
><br>
<br>
Also, using IPA on RHEL-6.4 is discouraged. This is a<br>
really old<br>
release and<br>
there are known issues (in cert renewals for example). Using at<br>
least RHEL-6.8<br>
or, even better, RHEL-7.2 is preferred and would help you avoid<br>
known issues<br>
and deficiencies (and the newer FreeIPA versions are way<br>
cooler anyway).<br>
<br>
<br>
<br>
<br>
<br>
<br>
</div></div></blockquote>
<br>
</blockquote></div><br></div></div>