Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 1133966

Summary: ipa trust-add cmd should be interactive
Product: Red Hat Enterprise Linux 7 Reporter: Martin Kosek <mkosek>
Component: ipaAssignee: Martin Kosek <mkosek>
Status: CLOSED ERRATA QA Contact: Namita Soman <nsoman>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 7.0CC: rcritten, sgoveas
Target Milestone: rc   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ipa-4.0.3-1.el7 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-03-05 10:13:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Martin Kosek 2014-08-26 14:42:33 UTC
This bug is created as a clone of upstream ticket:
https://fedorahosted.org/freeipa/ticket/3034

{{{
[root@wazwan ~]# ipa trust-add
Realm name: ADLAB.QE
ipa: ERROR: invalid Gettext('AD Trust setup', domain='ipa',
localedir=None): Not enough arguments specified to perform trust
setup

[root@wazwan ~]# ipa trust-add --type=ad
Realm name: ADLAB.QE
ipa: ERROR: invalid Gettext('AD Trust setup', domain='ipa',
localedir=None): Not enough arguments specified to perform trust
setup

[root@wazwan ~]# ipa trust-add --type=ad --admin administrator
Realm name: ADLAB.QE
ipa: ERROR: invalid Gettext('AD Trust setup', domain='ipa',
localedir=None): Realm administrator password should be specified

[root@wazwan ~]# ipa trust-add --type=ad adlab.qe --admin administrator
ipa: ERROR: invalid Gettext('AD Trust setup', domain='ipa',
localedir=None): Realm administrator password should be specified

[root@wazwan ~]# ipa trust-add --password
Realm name: adrelm.com
Active directory domain adminstrator's password: 
ipa: ERROR: invalid Gettext('AD Trust setup', domain='ipa', localedir=None): Not enough arguments specified to perform trust setup
}}}

Comment 1 Martin Kosek 2014-09-02 08:19:06 UTC
Fixed upstream:

master:
9415aba87789512e34cb4ed62534cde7822ff70b ipa trust-add command should be interactive

ipa-4-1:
8bb2af0e0ca375e10a406883ada5769963813763 ipa trust-add command should be interactive

ipa-4-0:
b708001074e1fc1e412bc18b1e5e0b408151847b ipa trust-add command should be interactive

Comment 3 Steeve Goveas 2014-11-26 19:00:36 UTC
Verified in ipa-server-trust-ad-4.1.0-8.el7.x86_64

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0006: trust-add interactively
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'kdestroy -A'
:: [   PASS   ] :: Command 'kdestroy -A' (Expected 0, got 0)
:: [ 21:38:30 ] :: https://fedorahosted.org/freeipa/ticket/3034
:: [  BEGIN   ] :: Running 'echo -e "adtest.qe
Administrator
Secret123" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "adtest.qe\nAdministrator\nSecret123" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out'
Realm name: Active Directory domain administrator: --------------------------------------------------
Added Active Directory trust for realm "adtest.qe"
--------------------------------------------------
  Realm name: adtest.qe
  Domain NetBIOS name: ADTEST
  Domain Security Identifier: S-1-5-21-1910160501-511572375-3625658879
  SID blacklist incoming: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  SID blacklist outgoing: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Added Active Directory trust for realm "adtest.qe"' 
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Trust type: Active Directory domain' 
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Trust status: Established and verified' 
:: [  BEGIN   ] :: Running 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: ADTEST.QE_id_range
  First Posix ID of the range: 1148400000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-1910160501-511572375-3625658879
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: PUNE.ADTEST.QE_id_range
  First Posix ID of the range: 839000000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-91314187-2404433721-1858927112
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa trust-del adtest.qe'
-------------------------
Deleted trust "adtest.qe"
-------------------------
:: [   PASS   ] :: Command 'ipa trust-del adtest.qe' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del ADTEST.QE_id_range'
-------------------------------------
Deleted ID range "ADTEST.QE_id_range"
-------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del ADTEST.QE_id_range' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del PUNE.ADTEST.QE_id_range'
------------------------------------------
Deleted ID range "PUNE.ADTEST.QE_id_range"
------------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del PUNE.ADTEST.QE_id_range' (Expected 0, got 0)
'9e1e3287-2294-4dbd-93d2-7bbe01736db7'
trust-cli-0006 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931710.23 (Tue Nov 25 21:38:30 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0006_2: trust-add interactively with --admin
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "adtest.qe
Secret123" | ipa trust-add --admin Administrator > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "adtest.qe\nSecret123" | ipa trust-add --admin Administrator > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out'
Realm name: --------------------------------------------------
Added Active Directory trust for realm "adtest.qe"
--------------------------------------------------
  Realm name: adtest.qe
  Domain NetBIOS name: ADTEST
  Domain Security Identifier: S-1-5-21-1910160501-511572375-3625658879
  SID blacklist incoming: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  SID blacklist outgoing: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Added Active Directory trust for realm "adtest.qe"' 
:: [  BEGIN   ] :: Running 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: ADTEST.QE_id_range
  First Posix ID of the range: 1148400000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-1910160501-511572375-3625658879
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: PUNE.ADTEST.QE_id_range
  First Posix ID of the range: 839000000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-91314187-2404433721-1858927112
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa trust-del adtest.qe'
-------------------------
Deleted trust "adtest.qe"
-------------------------
:: [   PASS   ] :: Command 'ipa trust-del adtest.qe' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del ADTEST.QE_id_range'
-------------------------------------
Deleted ID range "ADTEST.QE_id_range"
-------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del ADTEST.QE_id_range' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del PUNE.ADTEST.QE_id_range'
------------------------------------------
Deleted ID range "PUNE.ADTEST.QE_id_range"
------------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del PUNE.ADTEST.QE_id_range' (Expected 0, got 0)
'6b3b3ed4-cac5-4933-ad3e-298ee22f5ecc'
trust-cli-0006-2 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931755.82 (Tue Nov 25 21:39:15 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0006_3: trust-add interactively with AD domain
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "Administrator
Secret123" | ipa trust-add adtest.qe > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "Administrator\nSecret123" | ipa trust-add adtest.qe > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out'
Active Directory domain administrator: --------------------------------------------------
Added Active Directory trust for realm "adtest.qe"
--------------------------------------------------
  Realm name: adtest.qe
  Domain NetBIOS name: ADTEST
  Domain Security Identifier: S-1-5-21-1910160501-511572375-3625658879
  SID blacklist incoming: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  SID blacklist outgoing: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Added Active Directory trust for realm "adtest.qe"' 
:: [  BEGIN   ] :: Running 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: ADTEST.QE_id_range
  First Posix ID of the range: 1148400000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-1910160501-511572375-3625658879
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: PUNE.ADTEST.QE_id_range
  First Posix ID of the range: 839000000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-91314187-2404433721-1858927112
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa trust-del adtest.qe'
-------------------------
Deleted trust "adtest.qe"
-------------------------
:: [   PASS   ] :: Command 'ipa trust-del adtest.qe' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del ADTEST.QE_id_range'
-------------------------------------
Deleted ID range "ADTEST.QE_id_range"
-------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del ADTEST.QE_id_range' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del PUNE.ADTEST.QE_id_range'
------------------------------------------
Deleted ID range "PUNE.ADTEST.QE_id_range"
------------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del PUNE.ADTEST.QE_id_range' (Expected 0, got 0)
'94bcae2a-a73b-4de4-8c3d-fcdacb195924'
trust-cli-0006-3 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931803.43 (Tue Nov 25 21:40:03 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0006_4: trust-add interactively with --password
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "adtest.qe
Secret123
Administrator" | ipa trust-add --password > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "adtest.qe\nSecret123\nAdministrator" | ipa trust-add --password > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out'
Realm name: Active Directory domain administrator: --------------------------------------------------
Added Active Directory trust for realm "adtest.qe"
--------------------------------------------------
  Realm name: adtest.qe
  Domain NetBIOS name: ADTEST
  Domain Security Identifier: S-1-5-21-1910160501-511572375-3625658879
  SID blacklist incoming: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  SID blacklist outgoing: S-1-5-20, S-1-5-3, S-1-5-2, S-1-5-1, S-1-5-7, S-1-5-6, S-1-5-5, S-1-5-4, S-1-5-9, S-1-5-8, S-1-5-17, S-1-5-16, S-1-5-15, S-1-5-14, S-1-5-13, S-1-5-12, S-1-5-11, S-1-5-10, S-1-3, S-1-2, S-1-1, S-1-0, S-1-5-19, S-1-5-18
  Trust direction: Two-way trust
  Trust type: Active Directory domain
  Trust status: Established and verified
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Added Active Directory trust for realm "adtest.qe"' 
:: [  BEGIN   ] :: Running 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: ADTEST.QE_id_range
  First Posix ID of the range: 1148400000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-1910160501-511572375-3625658879
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1'
  Range name: PUNE.ADTEST.QE_id_range
  First Posix ID of the range: 839000000
  Number of IDs in the range: 200000
  First RID of the corresponding RID range: 0
  Domain SID of the trusted domain: S-1-5-21-91314187-2404433721-1858927112
  Range type: Active Directory domain range
:: [   PASS   ] :: Command 'ipa idrange-show PUNE.ADTEST.QE_id_range | tee /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out 2>&1' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0006.out' should contain 'Range type: Active Directory domain range' 
:: [  BEGIN   ] :: Running 'ipa trust-del adtest.qe'
-------------------------
Deleted trust "adtest.qe"
-------------------------
:: [   PASS   ] :: Command 'ipa trust-del adtest.qe' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del ADTEST.QE_id_range'
-------------------------------------
Deleted ID range "ADTEST.QE_id_range"
-------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del ADTEST.QE_id_range' (Expected 0, got 0)
:: [  BEGIN   ] :: Running 'ipa idrange-del PUNE.ADTEST.QE_id_range'
------------------------------------------
Deleted ID range "PUNE.ADTEST.QE_id_range"
------------------------------------------
:: [   PASS   ] :: Command 'ipa idrange-del PUNE.ADTEST.QE_id_range' (Expected 0, got 0)
'013ad0d0-abaa-449d-8e22-50696777a8a7'
trust-cli-0006-4 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931855.83 (Tue Nov 25 21:40:55 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0007_1: trust-add interactively without realm
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "
" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "\n" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1' (Expected 1, got 1)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out'
ipa: ERROR: 'realm' is required
Realm name: :: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' should contain 'ipa: ERROR: 'realm' is required' 
'd9a4f9bb-d1cd-494a-beca-03dea527536b'
trust-cli-0007-1 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931902.04 (Tue Nov 25 21:41:42 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0007_2: trust-add interactively without admin and password
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "adtest.qe

" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "adtest.qe\n\n" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1' (Expected 1, got 1)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out'
ipa: ERROR: invalid 'AD Trust setup': Not enough arguments specified to perform trust setup
Realm name: Active Directory domain administrator: :: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' should contain 'ipa: ERROR: invalid 'AD Trust setup': Not enough arguments specified to perform trust setup' 
'e101f401-6c11-4336-855e-6e37d7f3ec82'
trust-cli-0007-2 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931904.77 (Tue Nov 25 21:41:44 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0007_3: trust-add interactively without password
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "adtest.qe
Administrator
" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "adtest.qe\nAdministrator\n" | ipa trust-add > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1' (Expected 1, got 1)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out'
ipa: ERROR: invalid 'AD Trust setup': Realm administrator password should be specified
Realm name: Active Directory domain administrator: :: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' should contain 'ipa: ERROR: invalid 'AD Trust setup': Realm administrator password should be specified' 
'd27cb0c2-75c8-4e36-9b26-4544ba061efa'
trust-cli-0007-3 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931908.78 (Tue Nov 25 21:41:48 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0007_4: trust-add interactively without argument for --admin
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'ipa trust-add --admin > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1'
:: [   PASS   ] :: Command 'ipa trust-add --admin > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1' (Expected 2, got 2)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out'
Usage: ipa [global-options] trust-add REALM [options]

ipa: error: --admin option requires an argument
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' should contain 'ipa: error: --admin option requires an argument' 
'6d8b6464-b5c0-4aa4-9a6b-8b02fb91aa0d'
trust-cli-0007-4 result: PASS
   metric: 0
   Log: /var/tmp/beakerlib-26186692/journal.txt
    Info: Searching AVC errors produced since 1416931912.05 (Tue Nov 25 21:41:52 2014)
     Searching logs...
     Info: No AVC messages found.
 Writing to /mnt/testarea/tmp.RTAlkS
:
   AvcLog: /mnt/testarea/tmp.RTAlkS

::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
:: [   LOG    ] :: trust_cli_0007_5: trust-add interactively without giving administrator interactively
::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::

:: [  BEGIN   ] :: Running 'echo -e "Secret123" | ipa trust-add adtest.qe --password > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1'
:: [   PASS   ] :: Command 'echo -e "Secret123" | ipa trust-add adtest.qe --password > /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out 2>&1' (Expected 1, got 1)
:: [  BEGIN   ] :: Running 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out'
ipa: ERROR: Could not get Active Directory domain administrator interactively
Active Directory domain administrator: 
:: [   PASS   ] :: Command 'cat /tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' (Expected 0, got 0)
:: [   PASS   ] :: File '/tmp/tmp.oTnprLAKKW/tmpout.trust_cli_0007.out' should contain 'ipa: ERROR: Could not get Active Directory domain administrator interactively'

Comment 5 errata-xmlrpc 2015-03-05 10:13:29 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2015-0442.html