Questions tagged [freeipa]

FreeIPA is an integrated Identity and Authentication solution for Linux/UNIX networked environments. A FreeIPA server provides centralized authentication, authorization and account information by storing data about user, groups, hosts and other objects necessary to manage the security aspects of a network of computers.

FreeIPA is an integrated security information management solution combining Linux (Fedora), 389 Directory Server, MIT Kerberos, NTP, DNS, Dogtag (Certificate System). It consists of a web interface and command-line administration tools.

FreeIPA is an integrated Identity and Authentication solution for Linux/UNIX networked environments. A FreeIPA server provides centralized authentication, authorization and account information by storing data about user, groups, hosts and other objects necessary to manage the security aspects of a network of computers.

FreeIPA is built on top of well known Open Source components and standard protocols with a very strong focus on ease of management and automation of installation and configuration tasks.

Multiple FreeIPA servers can easily be configured in a FreeIPA Domain in order to provide redundancy and scalability. The 389 Directory Server is the main data store and provides a full multi-master LDAPv3 directory infrastructure. Single-Sign-on authentication is provided via the MIT Kerberos KDC. Authentication capabilities are augmented by an integrated Certificate Authority based on the Dogtag project. Optionally Domain Names can be managed using the integrated ISC Bind server.

Security aspects related to access control, delegation of administration tasks and other network administration tasks can be fully centralized and managed via the Web UI or the ipa Command Line tool.

218 questions
0
votes
2 answers

kadmin cannot list principals "requires list privileges"

I can authenticate fine via kadmin however cannot list principals? [root@server ~]# kadmin -p admin Authenticating as principal admin with password. Password for admin@org.domain.com: kadmin: listprincs get_principals: Operation requires ``list''…
krisdigitx
  • 609
  • 3
  • 18
  • 30
0
votes
1 answer

[root@pcm-ipa-01 tmp]# klist klist: No credentials cache found (ticket cache FILE:/tmp/krb5cc_0)freeipa kadmin admin principal not found

I have installed freeipa on centos and after restarting the service seems to have lost authentication for "kadmin" [root@pcm-ipa-01 ~]# kadmin init Authenticating as principal root/admin@MY.DOMAIN T with password. kadmin: Client not found in…
krisdigitx
  • 609
  • 3
  • 18
  • 30
0
votes
2 answers

FreeIPA 4.1.1 Fedora 21is not working

I am trying to install FreeIPA 4.1.1 on Fedora 21 yum install freeipa-* ipa-server-install Error during the installation: [10/27]: importing CA chain to RA certificate database [error] RuntimeError: Unable to retrieve CA chain: request failed…
Dina Abu-khader
  • 141
  • 2
  • 2
  • 7
0
votes
0 answers

freeipa 4.1.0 on fedora20 not working

Has anyone successfully setup freeipa 4.0.3 on Fedora20 as a server and another fedora20 with freeipa 4.1.0 for the client side? because I can't figure out why im always having the error " user does not exist" when using " su - (user)@ipaserver.com…
Rolf
  • 1
0
votes
2 answers

How to disable Null and Weak Ciphers on 389-Directory-Server

I am running 389-DS on CentOS. Version - '389-ds-base.i686 1.2.11.15-34.el6_5'. Security scans revealed that NullCiphers were found on Port 389 and 636. I tried to disable them by shutting down DS, editing the 'nsSSL3Ciphers' on all…
Quest Monger
  • 189
  • 2
  • 4
  • 12
0
votes
2 answers

Windows domain + Linux Domain on One Network

Currently our network is all tied to Active Directory with both Windows and Linux workstations/servers. We would like to implement a Free IPA server that synchronizes authentication between a Linux domain (eg: linux.my.domain) and an Active…
0
votes
1 answer

FreeIPA/389 DS userPassword

I am connecting to FreeIPA LDAP (386 Directory Server) as admin. I can find a user, and add the userPassword attribute like #!RESULT OK #!CONNECTION ldap://freeipa1.localdomain:389 #!DATE 2014-09-15T20:59:40.323 dn:…
user918176
  • 103
  • 1
  • 4
0
votes
1 answer

MacOS X 10.9 Mavericks Kerberos login w/ FreeIPA

Has anyone successfully set up authentication and authorization between MacOS X and FreeIPA? An old revision of the FreeIPA documentation explains how to get it working in 10.4 and nothing in their current documentation indicates it can't be made…
moof2k
  • 103
  • 1
  • 2
0
votes
1 answer

FreeIPA krb5.conf has example.com entries

I have installed and reinstalled FreeIPA ipa-server-3.0.0-37.el6.x86_64 on a fully updated OEL 6.5 server a couple (3) times now and even if I destroy the existing /etc/krb5.conf file and reinstall ipa-server, the krb5.conf files ends up with this…
mr.zog
  • 902
  • 3
  • 16
  • 36
0
votes
1 answer

Configuring Redhat / CentOS 5 SSH to authenticate to IPA server with public keys

I'm trying to configure some Red Hat/CentOS servers to use an ipa-server on CentOS 6 for SSH authentication with public keys. I'm storing the public keys on the IPA server, which works great on Centos6 using "AuthorizedKeysCommand…
blindsnowmobile
  • 347
  • 5
  • 15
0
votes
0 answers

FreeIPA issue: after ipa1 server kernel panic, not switching to ipa2 failover server

Our setup is as follows. All machines are running under Centos 5.8. We have a gateway machine with a firewall, gw.example.com, through which all external traffic is funneled. Behind it we have 2 FreeIPA servers for remote user authentication,…
Chikipowpow
  • 101
  • 3
0
votes
2 answers

Accidentally disabled the administrator account on IPA server

I'm running ipa-server on Centos 6. I was going through the users disabling accounts and accidentally disabled the "administrator" account. Now I have no access to do anything. Is there any way to restore access to this account? Or to prevent…
dan
  • 323
  • 1
  • 5
  • 16
0
votes
0 answers

How do I sync users and passwords from active directory to FreeIPA?

So I have an active directory domain, call it foo.com. Two server 2019 servers as DCs. I'm trying to move away from windows, to FreeIPA. I have a handful of users who login to a webmail server, which authenticates to the AD domain. All working…
0
votes
0 answers

Free IPA Replica server retrieving two certificates from the IPA master server while installing IPA replica

Master server: aaa01 Replica server1: dir01 (currently installing replica server ) Replica server2: dirus02 (which is a replica server previously that has been removed from replication) As noticed while installing ipa replica server, replica server…
0
votes
1 answer

FreeIPA and Kerberos [Cannot contact any KDC for realm while getting initial credentials]

I hope this is the correct forum to ask. We run a cluster (Centos 7) using FreeIPA for account management. On Sunday the IPA server suddenly restarted and since then, users are no longer able to login via ssh and Kerberos credentials can no longer…
Yannick
  • 1
  • 2