Questions tagged [freeipa]

FreeIPA is an integrated Identity and Authentication solution for Linux/UNIX networked environments. A FreeIPA server provides centralized authentication, authorization and account information by storing data about user, groups, hosts and other objects necessary to manage the security aspects of a network of computers.

FreeIPA is an integrated security information management solution combining Linux (Fedora), 389 Directory Server, MIT Kerberos, NTP, DNS, Dogtag (Certificate System). It consists of a web interface and command-line administration tools.

FreeIPA is an integrated Identity and Authentication solution for Linux/UNIX networked environments. A FreeIPA server provides centralized authentication, authorization and account information by storing data about user, groups, hosts and other objects necessary to manage the security aspects of a network of computers.

FreeIPA is built on top of well known Open Source components and standard protocols with a very strong focus on ease of management and automation of installation and configuration tasks.

Multiple FreeIPA servers can easily be configured in a FreeIPA Domain in order to provide redundancy and scalability. The 389 Directory Server is the main data store and provides a full multi-master LDAPv3 directory infrastructure. Single-Sign-on authentication is provided via the MIT Kerberos KDC. Authentication capabilities are augmented by an integrated Certificate Authority based on the Dogtag project. Optionally Domain Names can be managed using the integrated ISC Bind server.

Security aspects related to access control, delegation of administration tasks and other network administration tasks can be fully centralized and managed via the Web UI or the ipa Command Line tool.

230 questions
4
votes
1 answer

Integrating FreeIPA or RH IdM in an existing MS AD environment

I want to deploy FreeIPA or Red Hat IdM in my existing environment Currently my domain is managed by MS AD which is controlled by a separate group. Assume that changing anything in MS AD is going to be difficult or impossible for political…
xdfil
  • 491
  • 2
  • 7
  • 15
4
votes
1 answer

FreeIPA: command-line tools do not work, 'No Kerberos credentials available'

We have a working FreeIPA installation, it's in production since February. Almost everything works as expected but when we try to run command-line FreeIPA-related tools none of them work: [admin@ipa ~]$ kinit admin Password for admin@EXAMPLE.COM:…
Alex
  • 7,939
  • 6
  • 38
  • 52
4
votes
4 answers

How to reset Keytab for FreeIPA Server and Client

I followed the standard documentation to install FreeIPA server and client on hosts 'SRV' and 'CLT' respectively. I then added a user 'X' to FreeIPA using Web UI. Now when i try to SSH as X to CLT, i get a 'Permission denied, please try again.'…
Quest Monger
  • 189
  • 2
  • 4
  • 12
4
votes
1 answer

Granting sudo access to a SELinux confined user in freeIPA

I'm using freeIPA to define RBAC, HBAC and sudo rules, as well as SELinux user mappings for a domain of a couple hundred virtual machines, where I need to grant different levels of access to several teams (developers, database administrators, system…
dawud
  • 15,096
  • 3
  • 42
  • 61
4
votes
0 answers

How do I add an entryUUID field to the FreeIPA compat schema?

I am trying to add an entryUUID field to groups in the FreeIPA compat schema, but I am struggling to create the required attributeType. My LDIF for creating it is: dn: cn=schema changetype: modify add: attributeTypes attributeTypes: ( entryUUID-oid …
Mutantoe
  • 101
  • 6
4
votes
2 answers

Why does ipa-client-install fail when downloading the CA cert

I want to setup centralized user management. First to grant access to Linux servers and later also to grant access to other services via LDAP. As i'm new to this, I did some research on Google and I think FreeIPA will fit our requirements. I…
CodeNinja
  • 305
  • 1
  • 8
  • 18
3
votes
2 answers

Unable to log in to FreeIPA web ui - "Login failed due to an unknown reason."

After Fedora server update, my Freeipa broke and I am not sure how to deal with it. Does anyone have some ideas what might be the issue? I am unable to log in to web UI nor execute any IPA command. $ journalctl gssproxy[910]: gssproxy[951]: (OID: {…
tmdag
  • 133
  • 1
  • 6
3
votes
1 answer

macOS High Sierra issues mounting Kerberized NFSv4 shares

I'm using FreeIPA for LDAP/Kerberos and I've created a principal for a storage appliance (Dell/EMC UnityVSA VM). I have setup the VSA with a keytab from IPA, I've also setup within the VSA the LDAP configuration and created a NAS with support for…
user3814483
  • 183
  • 1
  • 10
3
votes
0 answers

FreeIPA : Keytab File for Adding Multiple NFS Clients

I'm relatively new to IPA and have been practicing setting up Kerberized NFS. I succeeded in initially sharing a directory from my VM Server1 to Server2. I accomplished the above by adding the NFS service in my IPA Server for server1 and generated…
Mustafa Mujahid
  • 73
  • 1
  • 1
  • 5
3
votes
3 answers

FreeIPA : Installer not resolving domain name from hosts file

I have been having an issue while installing FreeIPA. The problem is that every time I run the installer the FreeIPA application does not read from the host file rather tries to resolve the domain name (my machine's hostname) with a DNS query. I'm…
Mustafa Mujahid
  • 73
  • 1
  • 1
  • 5
3
votes
1 answer

IPA server NFS services adding issue centos 7.2

I'm having an issue with adding NFS services to IPA server (after login to the IPA server and kinit admin). When I execute the line below: [root@ipa ~]# ipa service-add nfs/server1.example.com I'm getting the error ipa: ERROR: Host does not have…
cms 54
  • 31
  • 2
3
votes
0 answers

Is it possible to use Active directory without a trust relationship for FreeIPA passwords?

I am looking to integrate FreeIPA with an Active Directory environment that I do not have full control over and most likely will not be able to get a trust relationship setup with my FreeIPA install. My needs for FreeIPA are simple, just need to use…
user165520
  • 71
  • 2
3
votes
2 answers

Configure Gitlab to use FreeIPA as LDAP server

I'm running in ran into a bit of a trouble and I don't seem to be able to fix it. Please follow the scenario bellow: I have two servers: ONE (10.0.3.10): Ubuntu based, having Gitlab (as deb package) installed with the following…
Dragos Cirjan
  • 31
  • 1
  • 4
3
votes
1 answer

Wrong user mapping in kerberized NFSv4 automounted homedirs

Short problem description This question is about id mapping in NFSv4 going wrong. NFS server: a Synology DS, with DSM 5.2. Client: A regular FC22 machine, which automounts as /home one of the exported folders from above. Both machines are enrolled…
cornuz
  • 437
  • 1
  • 7
  • 17
3
votes
1 answer

LDAP + KERBEROS + NFS. Why do I need idmapd?

What I am trying to do I have a freeIPA domain, with a few clients and a Synology NAS (also enrolled in freeIPA). I created a shared folder on the NAS, with NFSv4 + krb5 support. From the client, I obtain a ticket for LDAP user user1@mydomain.com…
cornuz
  • 437
  • 1
  • 7
  • 17
1
2
3
15 16