Bug 1390673

Summary: Traceback seen in error_log when trustdomain-del is run
Product: Red Hat Enterprise Linux 7 Reporter: Marcel Kolaja <mkolaja>
Component: ipaAssignee: IPA Maintainers <ipa-maint>
Status: CLOSED ERRATA QA Contact: Kaleem <ksiddiqu>
Severity: unspecified Docs Contact: Marc Muehlfeld <mmuehlfe>
Priority: high    
Version: 7.3CC: abokovoy, ipa-maint, jcholast, mbabinsk, mkolaja, mmuehlfe, nsoman, pvoborni, rcritten, sumenon
Target Milestone: rcKeywords: Regression, ZStream
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-4.4.0-14.el7_3 Doc Type: Bug Fix
Doc Text:
Previously, the ipa trustdomain-del command incorrectly searched for domains in trusted forest information. Consequently, when removing a trusted domain, an incorrect error message was displayed stating that the domain was not found instead of a success notification. The code for searching for trusted domains has been fixed. As a result, when removing a trusted domain, the domain is now correctly searched and removed from the database.
Story Points: ---
Clone Of: 1389709 Environment:
Last Closed: 2016-12-06 17:03:26 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 1389709    
Bug Blocks:    

Description Marcel Kolaja 2016-11-01 16:17:30 UTC
This bug has been copied from bug #1389709 and has been proposed
to be backported to 7.3 z-stream (EUS).

Comment 7 Martin Babinsky 2016-11-09 09:00:59 UTC
Done.

Comment 8 Sudhir Menon 2016-11-10 09:43:38 UTC
Verified on RHEL7.3u1 using 

ipa-server-4.4.0-14.el7_3.x86_64
sssd-1.14.0-43.el7_3.2.x86_64

[root@master yum.repos.d]# ipa trust-add --two-way=true
Realm name: ipaad2008r2.test
Active Directory domain administrator: administrator
Active Directory domain administrator's password:
---------------------------------------------------------
Added Active Directory trust for realm "ipaad2008r2.test"
---------------------------------------------------------
  Realm name: ipaad2008r2.test
  Domain NetBIOS name: IPAAD2008R2
  Domain Security Identifier: S-1-5-21-1765444267-4284514389-3232425237
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified
[root@master yum.repos.d]# ipa trustdomain-find
Realm name: ipaad2008r2.test
  Domain name: ipaad2008r2.test
  Domain NetBIOS name: IPAAD2008R2
  Domain Security Identifier: S-1-5-21-1765444267-4284514389-3232425237
  Domain enabled: True
 
  Domain name: ipasub2008r2-1.ipaad2008r2.test
  Domain NetBIOS name: IPASUB2008R2-1
  Domain Security Identifier: S-1-5-21-469193889-4273894478-2486872656
  Domain enabled: True
----------------------------
Number of entries returned 2
----------------------------
 
[root@master yum.repos.d]# ipa trustdomain-del ipaad2008r2.test ipasub2008r2-1.ipaad2008r2.test
------------------------------------------------------------------------------
Removed information about the trusted domain "ipasub2008r2-1.ipaad2008r2.test"
------------------------------------------------------------------------------
 
[root@master yum.repos.d]# ipa trustdomain-find
Realm name: ipaad2008r2.test
  Domain name: ipaad2008r2.test
  Domain NetBIOS name: IPAAD2008R2
  Domain Security Identifier: S-1-5-21-1765444267-4284514389-3232425237
  Domain enabled: True
----------------------------
Number of entries returned 1

Comment 12 errata-xmlrpc 2016-12-06 17:03:26 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2863.html