| Summary: | ipa-server-install when realm != domain puts ldap information in realm. | ||
|---|---|---|---|
| Product: | [Retired] freeIPA | Reporter: | Erinn Looney-Triggs <erinn.looneytriggs> |
| Component: | ipa-server | Assignee: | Rob Crittenden <rcritten> |
| Status: | CLOSED ERRATA | QA Contact: | Chandrasekar Kannan <ckannan> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 2.0 | CC: | benl, dpal, jgalipea, jhrozek, sgallagh, ssorce |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | freeipa-2.1.0-1.fc15 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-03-28 09:27:34 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Erinn Looney-Triggs
2011-02-23 00:05:36 UTC
https://fedorahosted.org/freeipa/ticket/1001 Need to check with the SSSD team but yes, looks like ipa_domain should be set to the realm name, not the domain name, in sssd.conf. Indeed setting the ipa_domain to linux.foo.com does resolve the issue and lookups work again. Interestingly the only other reference I could find to the ldap base was in /etc/ipa/default.conf: [global] basedn = dc=linux,dc=foo,dc=com So that at least looks like it is correct, but I can't find much documentation on what it means or is used for. (In reply to comment #1) > https://fedorahosted.org/freeipa/ticket/1001 > > Need to check with the SSSD team but yes, looks like ipa_domain should be set > to the realm name, not the domain name, in sssd.conf. The IPA provider in SSSD derives the base DN from the ipa_domain option. The values /etc/ipa/default.conf are used by the ipa tool and the server. basedn is the LDAP basedn. The default.conf file will get a man page in the next IPA release candidate. As discussed on IRC, this is a bug in SSSD. Since FreeIPA uses realm to construct the base DN, so should SSSD. The upstream SSSD bug is: https://fedorahosted.org/sssd/ticket/807 FreeIPA should only require the fixed version of SSSD. Require sssd 1.5.1-12 or higher in RHEL. |