Bug 1301664

Summary: [RFE] FreeIPA-to-FreeIPA migration
Product: Red Hat Enterprise Linux 9 Reporter: Martin Kosek <mkosek>
Component: ipaAssignee: Florence Blanc-Renaud <frenaud>
Status: NEW --- QA Contact: ipa-qe <ipa-qe>
Severity: unspecified Docs Contact:
Priority: low    
Version: unspecifiedCC: abroy, cobrown, deco, ipa-maint, ldelouw, pasik, pvoborni, rcritten, tmihinto, tscherf
Target Milestone: betaKeywords: FutureFeature, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: Feature Request
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Martin Kosek 2016-01-25 15:57:38 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3656

Provide a tool to migrate from FreeIPA to FreeIPA.

Currently FreeIPA can migrate users and groups from a generic LDAP server, but if you already have an IPA deployment there is currently no mechanism to migrate FreeIPA-specific data such as SUDO rules, HBAC, automount, hosts, services, etc (these last two may not be possible as re-enrollment of the client is required).

Comment 1 deco 2016-02-15 18:42:41 UTC
In Fedora 18: "Fedora does not provide a simple rename command to facilitate the renaming of a FreeIPA host. Renaming a host in a FreeIPA domain involves deleting the entry in FreeIPA, uninstalling the client software, changing the hostname, and re-enrolling using the new name. Additionally, part of renaming hosts requires regenerating service principals."

So it would be nice if RedHat IDM team could create a feature for changing domain or rename IPA domain. With such feature, users would avoid the hassle of doing this: https://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/renaming-machines.html

Comment 2 Petr Vobornik 2016-02-15 21:22:00 UTC
Wander, 

This bugzilla is about IPA to IPA migration, i.e., migrating data from one IPA server to different one. It is unrelated to ipa client renames. 

It is preferred to file a new upstream ticket for client renames https://fedorahosted.org/freeipa/newticket