Bug 815515

Summary: RFE: Update the DUA profile included in IPA
Product: [Fedora] Fedora Reporter: Sigbjorn Lie <sigbjorn>
Component: freeipaAssignee: Rob Crittenden <rcritten>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: rawhideCC: abokovoy, clasohm, dpal, extras-orphan, jgalipea, mkosek, pviktori, rcritten, sigbjorn, ssorce
Target Milestone: ---Keywords: Documentation, FutureFeature, Reopened
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
: 858006 (view as bug list) Environment:
Last Closed: 2014-10-15 10:40:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 858006    
Attachments:
Description Flags
Example DUA Config Profile none

Description Sigbjorn Lie 2012-04-23 18:39:32 UTC
Please see attached an updated DUA profile for updating the default DUA profile in IPA.

This DUA profile configures the following that should be in the default profile:

* Automounter
* Ethers 
* Printer objectclass mapping so that printers for the Solaris printer service can be added to the directory using existing objectclasses


The DUA profile also includes the following that can be specified in a seperate DUA config profile as an extended example:

* Sets the LDAP connection to be authenticated and secured, using a proxy account.
* Sets a default server list and list of preferred server list for servers local to the client.


Provided in the attached example, but might not be included in the default dua profile as these entries cannot be managed using the IPA CLI or WEBUI:

* Aliases mapping for handling sendmail and postfix aliases. All required objectclasses already exists in IPA.
* Printers mapping for handling central management of the Solaris print service.

Comment 1 Sigbjorn Lie 2012-04-23 18:41:50 UTC
Created attachment 579657 [details]
Example DUA Config Profile

Comment 3 Dmitri Pal 2012-04-23 19:12:18 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/2669

Comment 4 Dmitri Pal 2012-04-24 16:07:10 UTC
Make a knowledge base article and reference it in the documentation.

Comment 5 Deon Ballard 2013-06-25 19:29:08 UTC
Kicking the FreeIPA doc bugs to Martin.

Comment 6 Fedora End Of Life 2013-07-04 06:19:49 UTC
This message is a reminder that Fedora 17 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 17. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '17'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 17's end of life.

Bug Reporter:  Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 17 is end of life. If you 
would still like  to see this bug fixed and are able to reproduce it 
against a later version  of Fedora, you are encouraged  change the 
'version' to a later Fedora version prior to Fedora 17's end of life.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events. Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

Comment 7 Fedora End Of Life 2013-08-01 17:50:39 UTC
Fedora 17 changed to end-of-life (EOL) status on 2013-07-30. Fedora 17 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.

Comment 9 Sigbjorn Lie 2013-08-01 19:17:08 UTC
Any plans for updating the DUA profile soon? Should be quick and easy to implement and will help Solaris users implement IPA.

Comment 11 Martin Kosek 2013-08-02 06:46:05 UTC
Hello Sigbjorn,

While we value your interest in IPA Solaris support, the implementation of the DUA profile is not on our nearest schedule at the moment. We lack both knowledge and resources to focus on integration with Solaris. This is where we need a help (ideally patches) and contribution from the community to help us push these features in.

I checked your example DUAConfigProfile and I think it cannot be just added to FreeIPA right away. E.g. for defaultServerList or preferredServerList, you would need to expand installers and ipa-replica-manage to handle these lists and update them when replica is added or updated to prevent it being outdated. printers or aliases serviceSearchDescriptor refers to objects not being available and so on. It is not as straightforward as it seems.

What I think that we can work on is to work together on
http://docs.fedoraproject.org/en-US/Fedora/18/html/FreeIPA_Guide/Configuring_an_IPA_Client_on_Solaris.html#Configuring_an_IPA_Client_on_Solaris_10
... and add all the steps needed to make IPA work on Solaris 10. I could for example prepare an updated page and you could review it. Would that work for you?

Comment 12 Sigbjorn Lie 2013-08-02 15:50:23 UTC
Hi Martin,

The default DUAprofile that's already included in IPA by default already contains defaultServerList which include the IPA servers hostnames, so I believe this is already taken care of.

The serviceSearchDescriptor for aliases and printers can be moved to a knowledge base article. I see that these will not be relevant for everyone and do not have sources by default in IPA.

I don't mind reviewing the article. Let me know when it's ready.



Regards,
Siggi

Comment 13 Martin Kosek 2014-01-23 12:20:46 UTC
We had a discussion about this Bug. While IPA on Solaris and other platform should simply work when the standard protocols are used, in RHEL product we  officially do not test, document or support IPA on Solaris platform.

I am therefore moving this Bugzilla to Fedora product as upstream-only Bug to properly set the expectations and also to allow fixing the Bugzilla without forcing developers to be bound by RHEL product processes.

Comment 14 Martin Kosek 2014-10-15 10:40:28 UTC
Given the discussion in this bug and that FreeIPA upstream project no longer maintains it's own user guide besides the FreeIPA.org community wiki (details in http://www.freeipa.org/page/Upstream_User_Guide), I am closing this Bugzilla.

Please follow or contribute in the upstream ticket:
https://fedorahosted.org/freeipa/ticket/4633