DocumentationPortal
FreeIPA Documentation Portal
Welcome to the FreeIPA Documentation Portal.
This page provides access to all of the documentation developed for the FreeIPA project
Released
- IPA Frequently Asked Questions
- FreeIPA 2.2.0 Guide for F17
- Available in HTML format
- FreeIPA 2.1.3 Guide for F15
- Available in HTML format
- FreeIPA v1.2.1
- Available in HTML and PDF formats
- Extending IPA
In Progress
- FreeIPA v2 Development Progress
- Includes links to design pages.
- FreeIPA vNext Development Progress
- Includes links to design pages.
HOW TOs
- Implementing FreeIPA in a mixed Environment (Windows/Linux) - Step by step
- Windows authentication against FreeIPA
- Using third party Certificates
- Setting up MediaWiki to run against FreeIPA
- FreeIPA demonstration tools
- Dovecot Integration
- Squid Integration with FreeIPA using Single Sign On
- Dovecot IMAPS Integration with FreeIPA using Single Sign On
- NIS accounts migration preserving Passwords
- Zimbra Collaboration Server 7.2 Authentication and GAL lookups against FreeIPA
- eJabberd Integration with FreeIPA using LDAP Group memberships
- Authenticating libvirt (with VNC) against IPA
- Implementing SNI on Apache with IPA for certificate management and Kerberos Authentication
- YubiRadius integration with group-validated FreeIPA Users using LDAPS
- Samba 3 Integration -- guide involves patching the code!
- Introduction to certmonger
FAQs and Troubleshooting
- When trying to enroll a v2 client I get the error
Joining realm failed because of failing XML-RPC request. This error may be caused by incompatible server/client major versions.
- CVE-2011-2192 caused libcurl to drop support for delegating Kerberos tickets. Without a delegated ticket IPA cannot perform actions on the behalf of the user so enrollment fails. There are a number of bugs filed to resolve this (RHEL 5, RHEL 6 and Fedora). A change is also going to be required for xmlrpc-c to take advantage of the new curl API.
- Logging in to webUI as administrator fails after upgrading from freeIPA 1.0 -> 1.2.1
- After upgrading from version 1.0-x to 1.2.1, attempting to log in as administrator on the webUI always fails, with a "Permission Denied", "Kerberos login failed" error.
- If you log in as an unprivileged user the webUI works, and logging in to the CLI works as expected.
- This behavior has been observed on Fedora 9, but will probably occur on other versions of Fedora on which the same upgrade process occurs.
- A solution for this behavior has been found and is available here
- See our Troubleshooting guide
- Troubleshooting chapter of the Admin guide.
Presentations
- Slides of the IPA presentation at the Red Hat Summit 2011
- Slides of the FreeIPA presentation at FOSDEM 2009
