openSUSE Project Management Tool: Issueshttps://progress.opensuse.org/https://progress.opensuse.org/themes/openSUSE/favicon/favicon.ico?15829177842020-02-20T07:36:54ZopenSUSE Project Management Tool
Redmine invisAD-setup - action #63634 (New): We should publish a list with the expiry dates of all VPN cl...https://progress.opensuse.org/issues/636342020-02-20T07:36:54Zflaccostefan@invis-server.org
<p>The VPN client certs we create have a 24 month time to live. Actually the users have no information about this, the don't know when there clients certs epxire. More than once this caused problems in practice.</p>
invisAD-setup - action #63631 (Closed): We should publish the CRL expiration date via invis portalhttps://progress.opensuse.org/issues/636312020-02-20T07:32:14Zflaccostefan@invis-server.org
<p>Our CRL (Certification Revocation List) expires 6 month after creation. We should publish this date via invis-Portal.</p>
invisAD-setup - action #54389 (New): DNS-Updates via DHCP-Server should be possiblehttps://progress.opensuse.org/issues/543892019-07-18T06:37:55Zflaccostefan@invis-server.org
<p>In our setup every try to update DNS-Records dynamically fails:</p>
<p>Unable to add forward map from LANCOM_884_VOIP.baettenhausen.local to 192.168.1.205: REFUSED</p>
<p>This should be possible.</p>
<p>How to setup: <a href="https://wiki.samba.org/index.php/BIND9_DLZ_DNS_Back_End#Setting_up_BIND" class="external">https://wiki.samba.org/index.php/BIND9_DLZ_DNS_Back_End#Setting_up_BIND</a></p>
invisAD-setup - action #52019 (Closed): invis-Portal: Add a new function-sitehttps://progress.opensuse.org/issues/520192019-05-27T08:25:26Zflaccostefan@invis-server.org
<p>It should be possible to execute some administrative shell-scripts via invis-portal.</p>
invisAD-setup - action #51920 (Closed): invis-Server Setup Test with openSUSE Leap 15.1https://progress.opensuse.org/issues/519202019-05-23T10:05:12Zflaccostefan@invis-server.org
<p>We should build invis-Server 14.1 on base of Leap 15.1</p>
invisAD-setup - action #51869 (Closed): Build new own Samba-packageshttps://progress.opensuse.org/issues/518692019-05-22T16:22:30Zflaccostefan@invis-server.org
<p>Caused by problems with the MIT-Kerberos implementation and it's "experimental" state, we must build again own Samba-packages with Heimdal-Kerberos and switch our setup back to these own packages.</p>
invisAD-setup - action #51386 (Closed): invis-Server should be compatile with Btrfs.https://progress.opensuse.org/issues/513862019-05-12T07:25:07Zflaccostefan@invis-server.org
<p>First testinstallation with Btrfs on the Root-Volume shows that it was impossible to boot the server after setup with sine2.</p>
invisAD-setup - action #51383 (Closed): invis-Portal: Filter for Hostlisthttps://progress.opensuse.org/issues/513832019-05-12T07:21:37Zflaccostefan@invis-server.org
<p>It should be possible to filter the elements of the hostlist by type like we do it in the userlist.</p>
invisAD-setup - action #47072 (Closed): Check our DHCP-LDAP Schemahttps://progress.opensuse.org/issues/470722019-02-03T10:47:39Zflaccostefan@invis-server.org
<p>During an Upgrade from Samba 4.6 to 4.7 with MIT Kerberos, it is necessary to run "samba-tool dbcheck --cross-ncs --fix".</p>
<p>dbcheck throws some errors related to our dhcpd-LDAP Schema. We have to check this.</p>
<p>Errors:</p>
<hr>
<p>ERROR: Normalisation error for attribute mayContain in CN=iscDhcpClass,CN=Schema,CN=Configuration,DC=140-net,DC=loc<br>
value 'iscDhcpSubClassesDN' should be 'iscDhcpSubclassesDN'<br>
Not fixing attribute mayContain<br>
ERROR: Duplicate values for attribute 'mayContain' in 'CN=iscDhcpClass,CN=Schema,CN=Configuration,DC=140-net,DC=loc'<br>
Values contain a duplicate: [iscDhcpSubClassesDN,iscDhcpOptionsDN,iscDhcpStatements,iscDhcpComments,iscDhcpOption]/[iscDhcpSubClassesDN]!<br>
Not fixing attribute 'mayContain'<br>
ERROR: Not fixing missing 'name' on 'CN=iscDhcpClass,CN=Schema,CN=Configuration,DC=140-net,DC=loc'<br>
ERROR: Normalisation error for attribute mustContain in CN=iscDhcpFailOverPeer,CN=Schema,CN=Configuration,DC=140-net,DC=loc<br>
value 'iscDhcpFailoverPrimaryPort' should be 'iscDhcpFailOverPrimaryPort'<br>
Not fixing attribute mustContain<br>
ERROR: Duplicate values for attribute 'mustContain' in 'CN=iscDhcpFailOverPeer,CN=Schema,CN=Configuration,DC=140-net,DC=loc'<br>
Values contain a duplicate: [cn,iscDhcpFailOverPrimaryServer,iscDhcpFailOverSecondaryServer,iscDhcpFailoverPrimaryPort,iscDhcpFailOverSecondaryPort]/[iscDhcpFailOverPrimaryServer,iscDhcpFailoverPrimaryPort,cn,iscDhcpFailOverSecondaryServer]!<br>
Not fixing attribute 'mustContain'<br>
ERROR: Not fixing missing 'name' on 'CN=iscDhcpFailOverPeer,CN=Schema,CN=Configuration,DC=140-net,DC=loc'<br>
ERROR: incorrect DN SID component for member in object CN=Domain Users,CN=Users,DC=140-net,DC=loc - ;;;;;;;;CN=<a href="mailto:postmaster@140-net.loc">postmaster@140-net.loc</a>,CN=Users,DC=140-net,DC=loc<br>
Not fixing SID component mismatch</p>
<hr>
invisAD-setup - action #39161 (Closed): Build a new invisAD-setup Version 13.5https://progress.opensuse.org/issues/391612018-08-05T10:29:18Zflaccostefan@invis-server.org
<p>13.5 is a kind of intermediate version to prepare an upgrade to upcoming leap15 based Versions.</p>
<ul>
<li>This Version uses PHP7 and corNAz is already integrated in our invis-Portal.</li>
<li>It should support PHP7 based Kopano 8.6 packages and ownCloud 10.</li>
</ul>
invisAD-setup - action #37414 (In Progress): Implementation of SingleSignOnhttps://progress.opensuse.org/issues/374142018-06-15T07:57:23Zflaccostefan@invis-server.org
<p>Step by step we should implement SSO for as much applications as possible. First step would be to fit the apache2 setup for SSO.</p>
invisAD-setup - action #36514 (Closed): ntp was removed from minimal server based setuphttps://progress.opensuse.org/issues/365142018-05-24T21:07:57Zflaccostefan@invis-server.org
<p>We have to add it to our setup (first test was negative, ntpd didn't start. Error was: blocking_getaddrinfo can not queue response / <a href="https://lists.opensuse.org/opensuse-factory/2017-06/msg00774.html" class="external">https://lists.opensuse.org/opensuse-factory/2017-06/msg00774.html</a>) or he have to check if it is possible to substitute ntpd with systemd functions or ntpsec.</p>
invisAD-setup - action #29909 (Closed): Upgrade to PHP7https://progress.opensuse.org/issues/299092018-01-02T09:29:18Zflaccostefan@invis-server.org
<p>We have to upgrade the invis-server to php7. The now used Version 5.5. is out of maintenance and newer openSUSE Versions possibly ship only php7.</p>
<p>I think that the most wepapps we have included in invis-server still support php7. Biggest problem could be the invis-portal.</p>
invisAD-setup - action #27090 (Resolved): ldb library conflicthttps://progress.opensuse.org/issues/270902017-10-28T09:08:44Zflaccostefan@invis-server.org
<p>Since one of the last upgrades of the package ldb to version 1.2.x in our samba AD repos, sssd refuces to start after setup. After installing the original openSUSE 42.3 package ldb in version 1.1.29 everything works.</p>
<p>The problem is that our own samba packages are build against the newer ldb package.</p>
<p>I've no idea how we can fix this. Just installing the older package couldn't be the right way, this may cause other dependency problems.</p>
invisAD-setup - action #25198 (Rejected): invis-Server Upgrade Systemhttps://progress.opensuse.org/issues/251982017-09-12T05:53:59Zflaccostefan@invis-server.org
<p>We should build an upgrade System or Script for invis-Server to support minor-release jumps.</p>
<p>Such a system has to do only the projectable things like adding new stuff (schema addons, data) to Active-Directory or setting new Versionnumbers. To do the whole upgrades automatically is impossible in my opinion. </p>
<p>Any suggestions to this topic?</p>