FreeIPA: Difference between revisions

From Leo's Notes
This page was last edited on 6 March 2022, at 23:19.
Initial content
 
No edit summary
Line 112: Line 112:
}}
}}


==== Troubleshooting ====


==== Error: did not receive Kerberos credentials ====
On the FreeIPA server, run ipa-adtrust-install --add-sids. Ensure  that your hostname is set to the FQDN of the hostname otherwise this process will fail.
 
 
 
== Troubleshooting ==
 
=== Error: did not receive Kerberos credentials ===
Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an <code>ipa: ERROR: did not receive Kerberos credentials</code> error. Fix this by running:
Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an <code>ipa: ERROR: did not receive Kerberos credentials</code> error. Fix this by running:
{{Highlight
{{Highlight
Line 131: Line 136:
03/06/22 14:44:35  03/07/22 14:39:47  krbtgt/STEAMR.COM@STEAMR.COM
03/06/22 14:44:35  03/07/22 14:39:47  krbtgt/STEAMR.COM@STEAMR.COM
| lang = terminal
| lang = terminal
}}
=== Container issues ===
* mounting /var/log causes the install to break. Something about unable to delete a file in /var/log for whatever reason.
* Error with <code>AssertionError: Another instance named 'HOME-STEAMR-COM' may already exist</code>. I can't figure out what's causing lib389 to think there's another instance. I built a container image on top of this image with the assertion patched out. This seemed to have fixed the issue.
* {{Highlight
| code = FROM freeipa/freeipa-server:rocky-8
RUN sed 's/assert_c(len(insts)/# assert_c(len(insts)/' -i /usr/lib/python3.6/site-packages/lib389/instance/setup.py
| lang = text
}}
}}

Revision as of 23:19, 6 March 2022

Installation

Docker

There is an official Docker container that has a complete FreeIPA installation. This container uses systemd to start up FreeIPA along with the other related services such as OpenLDAP, Bind, and Kerberos. See more at: https://github.com/freeipa/freeipa-container

Use the following docker-compose.yml stack to quickly get started with FreeIPA:

version: '3.3'

services:

  freeipa:
    image: freeipa/freeipa-server:rocky-8
    restart: unless-stopped
    tty: true
    stdin_open: true
    hostname: ipa
    domainname: home.steamr.com
    extra_hosts:
      - "ipa.home.steamr.com:10.1.2.12"
    environment:
      - IPA_SERVER_HOSTNAME=ipa.home.steamr.com
      - IPA_SERVER_IP=10.1.2.12
      - DNS=10.1.0.8
      - TZ=America/Edmonton
    command:
      - ipa-server-install
      - --realm=home.steamr.com
      - --domain=home.steamr.com
      - --ds-password=xxxxxxxxxx
      - --admin-password=xxxxxxxxxx
      - --no-host-dns
      - --setup-dns
      - --auto-forwarders
      - --allow-zone-overlap
      - --no-dnssec-validation
      - --unattended
    sysctls:
      - net.ipv6.conf.all.disable_ipv6=0
    volumes:
      - ./data:/data
      - ./logs:/var/logs
      - /sys/fs/cgroup:/sys/fs/cgroup:ro
    tmpfs:
      - /run
      - /var/cache
      - /tmp
    cap_add:
      - SYS_TIME
    ports:
      - "10.1.2.12:80:80/tcp"
      - "10.1.2.12:443:443/tcp"
      # DNS
      - "10.1.2.12:53:53/tcp"
      - "10.1.2.12:53:53/udp"
      # LDAP(S)
      - "10.1.2.12:389:389/tcp"
      - "10.1.2.12:636:636/tcp"
      # Kerberos
      - "10.1.2.12:88:88/tcp"
      - "10.1.2.12:464:464/tcp"
      - "10.1.2.12:88:88/udp"
      - "10.1.2.12:464:464/udp"

Samba integration

The freeipa-client-samba tool will configure samba to use your FreeIPA service using kerberos. Users accessing shares would need to do so from a computer that is also on this FreeIPA domain and capable of using kerberos authentication.

To use password authentication, you will need to configure Samba to use FreeIPA's LDAP server as a passdb backend, similar to how you would do it with plain old LDAP. The nice thing with using FreeIPA is that you can configure it to update the LM and NT password hashes whenever the password is changed.

First, add sambaSAMAccount and sambaGroupMapping as a default user object class and group object class. You can either set this in the FreeIPA web interface under configuration, or run:

# ldapmodify <<EOF
dn: cn=ipaConfig,cn=etc,dc=home,dc=steamr,dc=com
changetype: modify
add: ipaUserObjectClasses
ipaUserObjectClasses: sambaSAMAccount
-
add: ipaGroupObjectClasses
ipaGroupObjectClasses: sambaGroupMapping
EOF

Get the SID of your samba server with net getlocalsid. Run the following on your FreeIPA server (using kerberos tickets generated by first running kinit admin).

ldapadd <<EOF
dn: cn=SambaSid,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
dnatype: sambaSID
dnaprefix: S-1-5-21-2049073866-1371207509-1214748462
dnainterval: 1
dnamagicregen: assign
dnafilter: (|(objectclass=sambasamaccount)(objectclass=sambagroupmapping))
dnascope: dc=home,dc=steamr,dc=com
cn: SambaSid
dnanextvalue: 2

dn: cn=sambaGroupType,cn=Distributed Numeric Assignment Plugin,cn=plugins,cn=config
objectClass: top
objectClass: extensibleObject
cn: sambaGroupType
dnatype: sambaGroupType
dnainterval: 1
dnamagicregen: assign
dnafilter: (objectClass=sambagroupmapping)
dnascope: dc=home,dc=steamr,dc=com
dnanextvalue: 2
EOF


On the FreeIPA server, run ipa-adtrust-install --add-sids. Ensure that your hostname is set to the FQDN of the hostname otherwise this process will fail.


Troubleshooting

Error: did not receive Kerberos credentials

Tools such as 'ipa' uses your session's Kerberos tickets for authentication. If you don't have any tickets or if your tickets expired, you may get an ipa: ERROR: did not receive Kerberos credentials error. Fix this by running:

## Renew/obtain Kerberos tickets for 'admin'
# kinit admin
Password for admin@HOME.STEAMR.COM:  ****

Verify if your tickets are available with klist:

# klist
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: admin@STEAMR.COM

Valid starting     Expires            Service principal
03/06/22 14:44:35  03/07/22 14:39:47  krbtgt/STEAMR.COM@STEAMR.COM

Container issues

  • mounting /var/log causes the install to break. Something about unable to delete a file in /var/log for whatever reason.
  • Error with AssertionError: Another instance named 'HOME-STEAMR-COM' may already exist. I can't figure out what's causing lib389 to think there's another instance. I built a container image on top of this image with the assertion patched out. This seemed to have fixed the issue.
  • FROM freeipa/freeipa-server:rocky-8
    RUN sed 's/assert_c(len(insts)/# assert_c(len(insts)/' -i /usr/lib/python3.6/site-packages/lib389/instance/setup.py