Thank you all for your input. I am still unable to get this working but I am
going to ask one of our Solaris admins to take a look at the config as I am no
Solaris expert.
We do have sudo packages
installed:libintl-3.4.0-sol10-x86-local.pkglibiconv-1.14-sol10-x86-local.pkglibgcc-3.4.6-sol10-x86-local.pkgsudo-1.8.5p2-sol10-x86-local.pkg
and I modified the ldapclient init to include:
NS_LDAP_SERVICE_SEARCH_DESC=sudoers:cn=sysaccounts,cn=etc,dc=example,dc=com
And added this line to nsswitch.confsudoers: files ldap
I set the NIS domainname as suggested
here:http://www.freeipa.org/page/ConfiguringUnixClients#Client_Configuration_Files
- echo “example.com” > /etc/defaultdomain
- domainname `cat /etc/defaultdomain`
/etc/ldap.conf does not exist so I tried adding that as well following
this:http://www.freeipa.org/docs/1.2/Client_Setup_Guide/en-US/html/chap-Client_Configuration_Guide-Configuring_Solaris_as_an_IPA_Client.html
And when none of these work I did follow Ajeet's instructions for using the
opencsw packages but to no avail.
I saw several posts about changing pam.conf but any time I followed those
suggestions freeipa shell logins did not work. I do understand we are on an old
version of IPA but can't change all our servers to run rhel7 at this time.
On Monday, January 19, 2015 11:42 AM, "[email protected]"
<[email protected]> wrote:
Send Freeipa-users mailing list submissions to
[email protected]
To subscribe or unsubscribe via the World Wide Web, visit
https://www.redhat.com/mailman/listinfo/freeipa-users
or, via email, send a message with subject or body 'help' to
[email protected]
You can reach the person managing the list at
[email protected]
When replying, please edit your Subject line so it is more specific
than "Re: Contents of Freeipa-users digest..."
Today's Topics:
1. Re: Having trouble running FreeIPA with SRV records on
externally managed DNS (Petr Spacek)
2. freeipa managed sudoers on Solaris 10 (sipazzo)
3. Re: freeipa managed sudoers on Solaris 10 (Dmitri Pal)
4. Re: freeipa managed sudoers on Solaris 10
(Murty, Ajeet (US - Arlington))
----------------------------------------------------------------------
Message: 1
Date: Mon, 19 Jan 2015 18:04:25 +0100
From: Petr Spacek <[email protected]>
To: [email protected]
Subject: Re: [Freeipa-users] Having trouble running FreeIPA with SRV
records on externally managed DNS
Message-ID: <[email protected]>
Content-Type: text/plain; charset=windows-1252
On 19.1.2015 16:54, [email protected] wrote:
> Hi all,
>
> I have successfully set up a test FreeIPA server and run it for a while, but
> the time has come to move towards a production service. I am currently
> running ipa-server version 3.0.0-25 on Scientific Linux 6.4 (if you don't
> know it, Scientific Linux is basically a rebuild of RedHat, much like
> CentOS). Yes, I know this is an older FreeIPA, but I am going through the
> path of least resistance given our site's current standard configuration.
>
> On our site there is a central DNS service and it is unlikely we will be
> allowed to run our own DNS service (other than as a slave/cacheing NS).
>
> I have been trying to set up SRV records for the FreeIPA server by providing
> the autogenerated zone file to our DNS manager, who has incorporated the
> configuration. When we deployed these changes, I used dig to confirm that
> SRV queries were giving appropriate responses, which they appear to be.
>
> I then tried setting up a client using ipa-client-install and got an error:
>
> Failed to verify that freeipa01.<munged.domain> is an IPA Server.
> This may mean that the remote server is not up or is not reachable due to
> network or firewall settings.
>
> The install worked on a client before deploying the SRV records, using manual
> specification of the server. I disabled iptables on the server to eliminate
> potential problems there, and got the same result. If we disable the SRV
> records, I am able to do the manual set-up again.
>
> So it looks like the problem is at the DNS end of things, so maybe our zone
> configuration is missing something.
>
> The zone config we currently have in place is as follows (we changed
> hostnames in the sample file to fqdns for this attempt, but the same symptoms
> came from bare hostnames)...
>
> ; ldap servers
> _ldap._tcp.my.domain. IN SRV 0 100 389 freeipa01.my.domain.
> ;
> ; kerberos realm
> _kerberos.my.domain. IN TXT my.domain.
> ;
> ; kerberos servers
> _kerberos._tcp.my.domain. IN SRV 0 100 88 freeipa01.my.domain.
> _kerberos._udp.my.domain. IN SRV 0 100 88 freeipa01.my.domain.
> _kerberos-master._tcp.my.domain. IN SRV 0 100 88 freeipa01.my.domain.
> _kerberos-master._udp.my.domain. IN SRV 0 100 88 freeipa01.my.domain.
> _kpasswd._tcp.my.domain. IN SRV 0 100 464 freeipa01.my.domain.
> _kpasswd._udp.my.domain. IN SRV 0 100 464 freeipa01.my.domain.
> ;
> ; ntp server
> _ntp._udp.my.domain. IN SRV 0 100 123 freeipa01.my.domain.
>
>
> ...So that is where I am. I was hoping that someone could give me a pointer
> or two as to how I might debug this problem and actually get service
> discovery working.
>
> Many thanks for reading this far!
Interesting. Please provide us with information listed on
http://www.freeipa.org/page/Troubleshooting#Client_Installation
Additionally not-obfuscated output from dig could help too.
Also, please keep in mind that:
1) Log obfuscation will make debugging harder for us.
2) Obfuscating DNS names does not bring any real security.
Did you read your e-mail headers? DNS domain EXCHMBX01.fed.cclrc.ac.uk is in
there ...
Have a nice day!
--
Petr^2 Spacek
------------------------------
Message: 2
Date: Mon, 19 Jan 2015 18:50:11 +0000 (UTC)
From: sipazzo <[email protected]>
To: "[email protected]" <[email protected]>
Subject: [Freeipa-users] freeipa managed sudoers on Solaris 10
Message-ID:
<759625883.2039340.1421693411249.javamail.ya...@jws100202.mail.ne1.yahoo.com>
Content-Type: text/plain; charset="utf-8"
I am having trouble finding relevant documentation on using freeipa to manage
sudoers for a Solaris client. Has anyone successfully set this up without
adding a bunch of non-standard packages? I am running freeipa 3.0.0-42 and any
help is appreciated.
-------------- next part --------------
An HTML attachment was scrubbed...
URL:
<https://www.redhat.com/archives/freeipa-users/attachments/20150119/10a3021b/attachment.html>
------------------------------
Message: 3
Date: Mon, 19 Jan 2015 14:01:53 -0500
From: Dmitri Pal <[email protected]>
To: [email protected]
Subject: Re: [Freeipa-users] freeipa managed sudoers on Solaris 10
Message-ID: <[email protected]>
Content-Type: text/plain; charset="iso-8859-1"; Format="flowed"
On 01/19/2015 01:50 PM, sipazzo wrote:
> I am having trouble finding relevant documentation on using freeipa to
> manage sudoers for a Solaris client. Has anyone successfully set this
> up without adding a bunch of non-standard packages? I am running
> freeipa 3.0.0-42 and any help is appreciated.
>
>
AFAIR Solaris does not carry sudo packages so if you plan to use sudo
you would need to get packages from upstream.
Other than that it is not different from using SUDO from a Linux client
that does not have SSSD.
--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL:
<https://www.redhat.com/archives/freeipa-users/attachments/20150119/300c69b7/attachment.html>
------------------------------
Message: 4
Date: Mon, 19 Jan 2015 19:24:56 +0000
From: "Murty, Ajeet (US - Arlington)" <[email protected]>
To: "[email protected]" <[email protected]>, "[email protected]"
<[email protected]>
Subject: Re: [Freeipa-users] freeipa managed sudoers on Solaris 10
Message-ID:
<[email protected]>
Content-Type: text/plain; charset="us-ascii"
We had to use OpenCSW packages.
run this on cmd-line -
pkgadd -d http://get.opencsw.org/now
/opt/csw/bin/pkgutil -y -i CSWbdb4 CSWcommon CSWlibnet CSWosslutils
CSWsasl CSWsudo-common CSWsudoldap cswpki gcc4core gcc4g++ gmake libssl_dev
openldap_client openldap_dev
optional one pkg at a time install -
/opt/csw/bin/pkgutil -y -i CSWbdb4
/opt/csw/bin/pkgutil -y -i CSWcommon
/opt/csw/bin/pkgutil -y -i CSWlibnet
/opt/csw/bin/pkgutil -y -i CSWosslutils
/opt/csw/bin/pkgutil -y -i CSWsasl
/opt/csw/bin/pkgutil -y -i CSWsudo-common
/opt/csw/bin/pkgutil -y -i CSWsudoldap
/opt/csw/bin/pkgutil -y -i cswpki
Ajeet Murty
Deloitte & Touche LLP
Tel: +1 571 882 5614 | Mobile: +1 704 421 8756
[email protected]<mailto:[email protected]> | www.deloitte.com
This message (including any attachments) contains confidential information
intended for a specific individual and purpose, and is protected by law. If you
are not the intended recipient, you should delete this message and any
disclosure, copying, or distribution of this message, or the taking of any
action based on it, by you is strictly prohibited.
v.E.1
From: [email protected]
[mailto:[email protected]] On Behalf Of Dmitri Pal
Sent: Monday, January 19, 2015 2:02 PM
To: [email protected]
Subject: Re: [Freeipa-users] freeipa managed sudoers on Solaris 10
On 01/19/2015 01:50 PM, sipazzo wrote:
I am having trouble finding relevant documentation on using freeipa to manage
sudoers for a Solaris client. Has anyone successfully set this up without
adding a bunch of non-standard packages? I am running freeipa 3.0.0-42 and any
help is appreciated.
AFAIR Solaris does not carry sudo packages so if you plan to use sudo you would
need to get packages from upstream.
Other than that it is not different from using SUDO from a Linux client that
does not have SSSD.
--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL:
<https://www.redhat.com/archives/freeipa-users/attachments/20150119/963cd0df/attachment.html>
------------------------------
_______________________________________________
Freeipa-users mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/freeipa-users
End of Freeipa-users Digest, Vol 78, Issue 74
*********************************************
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go To http://freeipa.org for more info on the project