Bug 837369
| Summary: | [RFE] Switch to client promotion to replica model | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Dmitri Pal <dpal> | ||||||||||||
| Component: | ipa | Assignee: | Martin Kosek <mkosek> | ||||||||||||
| Status: | CLOSED ERRATA | QA Contact: | Namita Soman <nsoman> | ||||||||||||
| Severity: | medium | Docs Contact: | Aneta Šteflová Petrová <apetrova> | ||||||||||||
| Priority: | high | ||||||||||||||
| Version: | 7.0 | CC: | akasurde, jcholast, jgalipea, mbabinsk, mbasti, mkosek, nsoman, pvoborni | ||||||||||||
| Target Milestone: | rc | Keywords: | FutureFeature | ||||||||||||
| Target Release: | --- | ||||||||||||||
| Hardware: | Unspecified | ||||||||||||||
| OS: | Unspecified | ||||||||||||||
| Whiteboard: | |||||||||||||||
| Fixed In Version: | ipa-4.4.0-1.el7 | Doc Type: | Release Note | ||||||||||||
| Doc Text: |
Simplified replica installation
Installing a replica no longer requires you to log in to the initial server, use the Directory Manager (DM) credentials, and copy the replica information file from the initial server to the replica. For example, this allows for easier provisioning using an external infrastructure management system, while retaining a reasonable level of security.
In addition, the "ipa-replica-install" utility can now also promote an existing client to a replica.
For details, see https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html-single/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html#install-replica
Note that the new functionality requires raising the domain level to `1`. See https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html-single/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html#domain-level
|
Story Points: | --- | ||||||||||||
| Clone Of: | |||||||||||||||
| : | 1351220 (view as bug list) | Environment: | |||||||||||||
| Last Closed: | 2016-11-04 05:43:22 UTC | Type: | --- | ||||||||||||
| Regression: | --- | Mount Type: | --- | ||||||||||||
| Documentation: | --- | CRM: | |||||||||||||
| Verified Versions: | Category: | --- | |||||||||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||||||||
| Embargoed: | |||||||||||||||
| Bug Depends On: | |||||||||||||||
| Bug Blocks: | 1199516, 1292074, 1296125, 1313485, 1351220 | ||||||||||||||
| Attachments: |
|
||||||||||||||
|
Description
Dmitri Pal
2012-07-03 16:00:55 UTC
Replica Promotion and Topology features were postponed in the upstream project, to FreeIPA 4.3 which should closely follow FreeIPA 4.2 release. See the reasoning and details in: http://www.redhat.com/archives/freeipa-devel/2015-July/msg00092.html Fixed upstream master: 9e007edbd902a5395797ca0ca9a698033540d755 Remove unused kra option 6a0087aea176d1e1154b359fa262066896d663e3 Add low level helper to get domain level 42e859daa78396321d25e95107eabf35d46cdd91 Make checks for existing credentials reusable 2606f5aecd6ac0db31abb515b691529bb7eaf14e Allow to setup the CA when promoting a replica 102651b10afa144384db53b45fb558747a092d6d prevent operation on tombstones fcb9854dcb047018a1904c7e6db655af0596e3ae handle multiple managed suffixes 80e11d24696c30ee311bd019ed39df8fc0f908a2 topology plugin configuration workaround 834b5fd513d799bb9fe2cbc29417ff8ec7357033 enable topology plugin on upgrade fff31ca220311421f1ac8cef0888aaa892e97584 topology: manage ca replication agreements 86240938b58cd9bf85a96d34c39b55f6d59a36b8 Add function to extract CA certs for install 5761f73e2598dc404a3b51c6810e3dd250d2ba11 Allow ipa-replica-conncheck to use default creds f7d1e4f9a21b0f3e63bd3bcd4a17acf749e0b208 Change DNS installer code to use passed in api d03619fff3a1eb7d21c2ba21f8867ae8018779b8 Implement replica promotion functionality 2cd0d20a2a454369488b77e841a9cce643b26d34 Require a DS version that has working DNA plugin 463dda30679da9ac5eea5683984002989965e2a5 Add ipa-custodia service 98bf90e4cecb38fc72a0b598a6e6a50fee284f31 fix dsinstance.py:get_domain_level function 958996b9cc55b6e9ecdc23981e79599ec6826b4c Allow ipa-ca-install to use the new promotion code Fixed upstream master: https://fedorahosted.org/freeipa/changeset/bc39cc9f813c35ba603b45c7dc5e9c5ba2be5743 Referencing https://fedorahosted.org/freeipa/ticket/5424 as a possible test case which is not strictly related to the promotion process itself. Upstream ticket: https://fedorahosted.org/freeipa/ticket/5455 Fixed upstream master: https://fedorahosted.org/freeipa/changeset/fa2fbc680aea8f9cb43238ae0103e5030324f3f6 https://fedorahosted.org/freeipa/changeset/dcaf57271c91f75733e42048683a04bde4ea9b2a https://fedorahosted.org/freeipa/changeset/ab8cba61c08571e4cbce1246bcbf820d3e337506 Has been implemented upstream, see comments above. *** Bug 1298845 has been marked as a duplicate of this bug. *** Upstream ticket: https://fedorahosted.org/freeipa/ticket/5721 This bug was accidentally moved from POST to MODIFIED via an error in automation, please see mmccune with any questions Ticket 5721 was closed as duplicate, adding ticket 5604. Core is implemented, but some regressions/issues we found, moving to assigned. Upstream ticket: https://fedorahosted.org/freeipa/ticket/5966 Upstream ticket: https://fedorahosted.org/freeipa/ticket/5976 master: https://fedorahosted.org/freeipa/changeset/8b12ef50e1c016a5a025cf2a69271f769b585a03 ipa-4-3: https://fedorahosted.org/freeipa/changeset/3d71c43504ea7837ea14bb9dd4a469c07337293f Upstream ticket: https://fedorahosted.org/freeipa/ticket/837369 Upstream ticket: https://fedorahosted.org/freeipa/ticket/5983 Ticket 5983 fixed upstream master: https://fedorahosted.org/freeipa/changeset/99339bf7892fcc1201e06e6a8105b0bb4681c4f4 This is not related to upstream ticket 5604 Created attachment 1190297 [details]
tkt_5455.log
Created attachment 1190299 [details]
tkt_5966.log
Created attachment 1190304 [details]
tkt_2888.log
Created attachment 1190322 [details]
tkt_5976.log
Created attachment 1191150 [details]
tkt_5983.log
Verified using IPA version :: ipa-server-4.4.0-7.el7.x86_64 Marking RFE bz as verified. See attachments for respective tkts. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2016-2404.html |