Back to bug 1389434

Who When What Removed Added
Jan Cholasta 2016-11-01 10:44:50 UTC Status NEW POST
CC jcholast
Jan Cholasta 2016-11-01 16:46:43 UTC Status POST MODIFIED
Fixed In Version ipa-4.4.0-14.el7_3
errata-xmlrpc 2016-11-01 16:53:28 UTC Status MODIFIED ON_QA
Marc Muehlfeld 2016-11-08 13:40:06 UTC CC mmuehlfe
Flags needinfo?(jcholast)
Jan Cholasta 2016-11-08 13:57:39 UTC Doc Text Cause: A bug in 389-ds-base caused replication with a remote server with older 389-ds-base installed to sometimes fail.

Consequence: ipa-replica-install would fail against a RHEL 6 master.

Fix: Require 389-ds-base version with a fix for bug 1384785.

Result: ipa-replica-install works correctly against a RHEL 6 master.
Doc Type If docs needed, set a value Bug Fix
Flags needinfo?(jcholast)
Kaleem 2016-11-10 05:46:41 UTC Status ON_QA VERIFIED
Marc Muehlfeld 2016-11-11 14:34:50 UTC Docs Contact mmuehlfe
Marc Muehlfeld 2016-11-16 06:57:39 UTC Doc Text Cause: A bug in 389-ds-base caused replication with a remote server with older 389-ds-base installed to sometimes fail.

Consequence: ipa-replica-install would fail against a RHEL 6 master.

Fix: Require 389-ds-base version with a fix for bug 1384785.

Result: ipa-replica-install works correctly against a RHEL 6 master.
Previously, after running the ipa-replica-install command to set up a new Identity Management (IdM) replica in domain level 1, the certificate authority (CA) certificate was not published. As a consequence, users were not able to download the certificate from the replica to, for example, import into certificate it in the web browser. The CA certificate publishing process has been enhanced and is now independent of the IdM domain level. As a result, the CA certificate is now correctly stored in the "/usr/share/ipa/html/ca.crt" file and users are able to download it from the web server.
Flags needinfo?(jcholast)
Marc Muehlfeld 2016-11-16 07:07:39 UTC Doc Text Previously, after running the ipa-replica-install command to set up a new Identity Management (IdM) replica in domain level 1, the certificate authority (CA) certificate was not published. As a consequence, users were not able to download the certificate from the replica to, for example, import into certificate it in the web browser. The CA certificate publishing process has been enhanced and is now independent of the IdM domain level. As a result, the CA certificate is now correctly stored in the "/usr/share/ipa/html/ca.crt" file and users are able to download it from the web server. A bug in the Identity Management (IdM) LDAP server caused replication to fail in certain scenarios with a replica that ran an older version of the 389-ds-base package. Consequently, the "ipa-replica-install" command failed when the replication partner on Red Hat Enterprise Linux 6. The problem has been fixed and as a result, the "ipa-replica-install" command no longer fails when the replication partner runs an older version of the 389-ds-base package.
Martin Bašti 2016-11-16 11:37:13 UTC CC mbasti
Flags needinfo?(jcholast)
errata-xmlrpc 2016-12-06 00:22:50 UTC Status VERIFIED RELEASE_PENDING
errata-xmlrpc 2016-12-06 17:03:13 UTC Status RELEASE_PENDING CLOSED
Resolution --- ERRATA
Last Closed 2016-12-06 12:03:13 UTC

Back to bug 1389434