Bug 1216017

Summary: [RFE] add Active Directory provider for realm feature via adcli
Product: Red Hat Satellite Reporter: Jan Pazdziora (Red Hat) <jpazdziora>
Component: ProvisioningAssignee: satellite6-bugs <satellite6-bugs>
Status: CLOSED WONTFIX QA Contact: Kedar Bidarkar <kbidarka>
Severity: medium Docs Contact:
Priority: medium    
Version: 6.1.0CC: bkearney, kbidarka, shbharad, susalvi, wpinheir
Target Milestone: UnspecifiedKeywords: FutureFeature, Reopened, Triaged
Target Release: Unused   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-11-04 14:03:06 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1119871    

Description Jan Pazdziora (Red Hat) 2015-04-28 11:31:05 UTC
Description of problem:

Currently, the realm feature in Satellite 6 as documented at

https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/6.0/html/User_Guide/Configuring_Identity_Management_in_Red_Hat_Satellite.html

only supports the setup when the Satellite (Capsule) machine is IPA-enrolled and provisioned machines will get identity in IdM.

It'd be good to be able to create the identity in Active Directory as well, presumably with adcli.

Version-Release number of selected component (if applicable):

Satellite 6.0 and 6.1.

How reproducible:

Deterministic.

Steps to Reproduce:
1. Try to setup identity management with Active Directory and have the newly provisioned machine joined to the AD domain, similar to the realm feature that works with IdM.

Actual results:

Currently not supported.

Expected results:

Supported by Satellite.

Additional info:

A more generic RFE to relax the IPA-enrollment which might be prerequisite for this work was filed as bug 1216016.

Comment 4 Bryan Kearney 2016-07-08 20:45:06 UTC
Per 6.3 planning, moving out non acked bugs to the backlog

Comment 7 Bryan Kearney 2018-05-03 17:33:50 UTC
Thank you for your interest in Satellite 6. We have evaluated this request, and we do not expect this to be implemented in product in the forseeable future. We are therefore closing this out as WONTFIX. If you have any concerns about this, please feel free to contact Rich Jerrido or Bryan Kearney. Thank you.

Comment 8 Surjeet Salvi 2019-09-20 20:35:25 UTC
Hello Team,
 
Cu has logged the Case - 02473744 for a similar issue " How to configure Satellite 6 environment to automatically register newly provisioned servers to our Active Directory realm"
 
Version-Release for the Satellite - satellite-6.5

I have found a similar issue in the upstream which is resolved.
 -- https://projects.theforeman.org/issues/4917

Cu has the query if we can use this feature in the Satellite environment. If yes, need the document for the same.

Under product documentation, I found the document for IDM but not the AD.

- https://access.redhat.com/documentation/en-us/red_hat_satellite/6.5/html/administering_red_hat_satellite/chap-red_hat_satellite-administering_red_hat_satellite-configuring_external_authentication#sect-Red_Hat_Satellite-Administering_Red_Hat_Satellite-External_Authentication_for_Provisioned_Hosts-Configuring_a_Red_Hat_Satellite_Server_or_Capsule_Server_for_IdM_Realm_Support

Please confirm if this feature can be integrated with the Satellite Server.

Regards
Surjeet

Comment 9 Surjeet Salvi 2019-10-23 18:11:38 UTC
Hello Team,

Could you please provide an update on the issue.

Regards
Surjeet

Comment 10 Bryan Kearney 2019-11-04 14:03:06 UTC
Thank you for your interest in Satellite 6. We have evaluated this request, and while we recognize that it is a valid request, we do not expect this to be implemented in the product in the foreseeable future. This is due to other priorities for the product, and not a reflection on the request itself. We are therefore closing this out as WONTFIX. If you have any concerns about this, please do not reopen. Instead, feel free to contact Red Hat Technical Support. Thank you.