Bug 1253480

Summary: ipa vault-add-owner does not fail when adding an existing owner
Product: Red Hat Enterprise Linux 7 Reporter: Scott Poore <spoore>
Component: ipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED ERRATA QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 7.2CC: mkosek, pvoborni, rcritten
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-4.2.0-5.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-11-19 12:05:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Scott Poore 2015-08-13 19:22:03 UTC
Description of problem:

[root@master ~]# ipa vault-add vname
-------------------
Added vault "vname"
-------------------
  Vault name: vname
  Type: standard
  Owner users: admin
[root@master ~]# ipa vault-add-owner vname --users=vaultuser1
  Vault name: vname
  Type: standard
  Owner users: admin, vaultuser1
------------------------
Number of owners added 1
------------------------
[root@master ~]# ipa vault-add-owner vname --users=vaultuser1
  Vault name: vname
  Type: standard
  Owner users: admin, vaultuser1
------------------------
Number of owners added 0
------------------------


Version-Release number of selected component (if applicable):
ipa-server-4.2.0-4.el7.x86_64

How reproducible:
always


Steps to Reproduce:
1.  ipa-server-install
2.  ipa-kra-install
3.  kinit admin
4.  ipa vault-add vname
5.  ipa vault-add-owner vname --users=user1
6.  ipa vault-add-owner vname --users=user1

Actual results:
no error

Expected results:
I expected an error/warning like vault-add-member shows:

[root@master ~]# ipa vault-add-member vname --groups=vaultvaultgroup1
  Vault name: vname
  Type: standard
  Owner users: admin
  Member groups: vaultvaultgroup1
  Failed members:
    member user:
    member group: vaultvaultgroup1: This entry is already a member


Additional info:

Comment 1 Scott Poore 2015-08-13 19:23:42 UTC
same for group

[root@master ~]# ipa vault-add-owner vname --groups=vaultgroup1
  Vault name: vname
  Type: standard
  Owner users: admin
  Owner groups: vaultgroup1
------------------------
Number of owners added 1
------------------------
[root@master ~]# ipa vault-add-owner vname --groups=vaultgroup1
  Vault name: vname
  Type: standard
  Owner users: admin
  Owner groups: vaultgroup1
------------------------
Number of owners added 0
------------------------

Comment 3 Scott Poore 2015-08-14 01:13:41 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/5214

Comment 6 Scott Poore 2015-08-21 18:07:24 UTC
Verified.

Version ::

ipa-server-4.2.0-5.el7.x86_64

Results ::

[root@master ~]# ipa user-add user1 --first=f --last=l
------------------
Added user "user1"
------------------
  User login: user1
  First name: f
  Last name: l
  Full name: f l
  Display name: f l
  Initials: fl
  Home directory: /home/user1
  GECOS: f l
  Login shell: /bin/sh
  Kerberos principal: user1
  Email address: user1
  UID: 744800004
  GID: 744800004
  Password: False
  Member of groups: ipausers
  Kerberos keys available: False
[root@master ~]# ipa vault-add vname
-------------------
Added vault "vname"
-------------------
  Vault name: vname
  Type: standard
  Owner users: admin
  Vault user: admin
[root@master ~]# ipa vault-add-owner vname --users=user1

  Vault name: vname
  Type: standard
  Owner users: admin, user1
  Vault user: admin
------------------------
Number of owners added 1
------------------------
[root@master ~]# 
[root@master ~]# ipa vault-add-owner vname --users=user1
  Vault name: vname
  Type: standard
  Owner users: admin, user1
  Vault user: admin
  Failed owners: 
    owner user: user1: This entry is already a member
    owner group: 
    owner service: 
------------------------
Number of owners added 0
------------------------

Comment 7 errata-xmlrpc 2015-11-19 12:05:28 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2015-2362.html