Bug 869656

Summary: Improve information on passsync user in man page, command help
Product: Red Hat Enterprise Linux 6 Reporter: Dmitri Pal <dpal>
Component: ipaAssignee: Rob Crittenden <rcritten>
Status: CLOSED ERRATA QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 6.4CC: dlackey, mkosek, sgoveas
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-3.0.0-8.el6 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-02-21 09:29:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dmitri Pal 2012-10-24 13:47:32 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3208

There is some confusion about the passsync user because our language is very misleading in the command-line help:

  --passsync=PASSSYNC   Password for the Windows PassSync user

and not much better in the man page:

   --passsync=PASSSYNC_PWD
          Password for the Windows  PassSync  user.  Required  when  using
          --winsync.  This does not mean you have to use the PassSync service

The passsync user is a special bind user we create for the Windows PassSync service to use to change passwords in IPA. It skips over policy checking because it is assumed that AD has already done this, and by the time we get the password it is too late to reject it. The password is also created as non-expired.

Comment 2 Rob Crittenden 2012-11-02 14:15:26 UTC
Improved help in tool and man page.

Fixed upstream.

master: 85a0cdeb696c9c1d1c50fa43b87ffe8d6d8e3ae6

ipa-3-0: 343e90eff6c93de536539f0abc3fe9e516beeb2b

Comment 5 Steeve Goveas 2013-01-17 09:43:41 UTC
[root@ratchet ~]# man ipa-replica-manage
--passsync=PASSSYNC_PWD
              Password  for  the  IPA system user used by the Windows PassSync plugin to synchronize
              passwords. Required when using --winsync. This does not  mean  you  have  to  use  the
              PassSync service.


[root@ratchet ~]# ipa-replica-manage --help | grep -i passsync
  --passsync=PASSSYNC   Password for the IPA system user used by the Windows
                        PassSync plugin to synchronize passwords

Verified in version

[root@ratchet ~]# rpm -qa | grep ipa-server
ipa-server-3.0.0-22.el6.x86_64
ipa-server-selinux-3.0.0-22.el6.x86_64

Comment 7 errata-xmlrpc 2013-02-21 09:29:02 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHSA-2013-0528.html