Re: new server & old client

Mike Gabriel <[email protected]> Sat, 21 Feb 2026 09:17:34 +0000
Newsgroups gmane.linux.debian.devel.education
Organization DAS-NETZWERKTEAM
Message-ID <20260221091734.Horde.u6GxwxDC67P1wf87EzUX2mg@mail.das-netzwerkteam.de>
This message is in MIME format and has been PGP signed.

--=_VCt4YX0CtOFL4zInrriIOhs
Content-Type: text/plain; charset=utf-8; format=flowed; DelSp=Yes
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi Lorenzo,

On  Fr 20 Feb 2026 23:01:02 CET, Lorenzo Ceriani wrote:

> Hi,
> I had to re-install debian-edu 12 on a new server without the possibility
> of back up ldap configuration; I re-added in gosa2 all users and I was
> going to re-add client workstations too, without re-installing debian-edu
> on them. I repeated the same moves that I did the first time, from
> sitesummary-client on, but it didn't work. No error messages, the client
> name appeared in gosa but login on client wasn't possible and
> /skole/tjener/home0 wasn't mounted.

> In this moment I am re-installing debian-edu on clients too because  in
> that way I am sure that it works, but I can't believe there isn't another
> -simpler and faster - way.

The clients need to be reset regarding LDAP access and Kerberos principals.

OTTOMH, this would be:

For Kerberos client reset:
root@client:~# rm /etc/krb5.keytab
root@client:~# /usr/share/debian-edu-config/tools/copy-host-keytab

And for LDAP SSL cert verification:
root@client:~# rm /etc/ssl/certs/Debian-Edu_rootCA.crt
root@client:~# rm /usr/local/share/ca-certificates/Debian-Edu_rootCA.crt
root@client:~# /usr/share/debian-edu-config/tools/fetch-rootca-cert

Let us know if that works (if you still have clients to test on).

> Have you got any suggestion?

Yes, see above ;-)

> Thanks a lot in advance,

Mike


--=20

mike=20gabriel aka sunweaver (Debian Developer)
mobile: +49 (1520) 1976 148
landline: +49 (4351) 486 14 27

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: [email protected], http://sunweavers.net


--=_VCt4YX0CtOFL4zInrriIOhs
Content-Type: application/pgp-signature
Content-Description: Digitale PGP-Signatur
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIzBAABCgAdFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmmZeCwACgkQmvRrMCV3
GzF6chAAk+lr5IO/r4+TDBl/WgAW08SIo80ZLyQRQ34XCbPvfkNfzhm+u9wXNBVg
EJIhgn4sCOD0qpJNh6NPlQ8lIf4Epywx692JtEe9Pcc4ZrQVF2wnjLHnivQgVorI
I9GK5AvFLTVFPEaMbsgEWZIpfyOu9VIFFdEKmA7hKJN4pHxKMMxR52qhgCptjJiF
4LbbSdpuC4czZm7lJBdtOBAXwBO1UQXZqlRD33bjqhQfHHl4yiDTQK8HXZH7gb27
g9NeOAfugC/PB7lude9sbNiis9bIaXzUlQAeoeW0hQjOAQmh5IeSS4aWE8POb0bG
L2glGqcQIA3lRjJayh+WA0hlPPJWCW4uvLlH+NgQsjwBTHIah73gCI8MKFwyH00k
DtYe2RJ3zpoCqfeapW6NgQixFaSY3O3Bv5xK49LBr65pVZsBCOEx7cVzDQjQTVwy
fubjZFo6ezTFX4sNC2rs9sggB6SGgIOfjOXTR/QRaDOhtAQ4yJUBYfM86Rxlcft5
idfzBpfNkBKc/F2SIPYt9vrgISJBc6m3GgcGsGJixR94iXxqWReEMF92jwb8a6ZV
VDXwfj+NLjdJlY/+Xl+fqHlZrKuIfhfisDocxfrMwSaN3SfF0zfDzFRAWdRd9XUW
4ICUMV7Y7MnrgwAbcJk7A7Xg5q5F5KYDY69jU7bbgjklMmmW3Hs=
=zSor
-----END PGP SIGNATURE-----

--=_VCt4YX0CtOFL4zInrriIOhs--