This bug is created as a clone of upstream ticket:
We want users in the admins group to always be able to log into the IPA masters.
We should create a new hostgroup that contains all of the IPA masters in it. This hostgroup would be created on new installs and updated at the same time that cn=masters is updated (so via replication changes and when new masters are added).
A new HBAC rule for the ssh service will be added that allows users in the admins group to machines in the IPA masters hostgroup.
We will not prevent additional hosts to be added to the hostgroup.
A task will be needed to handle upgrades so that any missing IPA masters can be added.
The required functionality for replica promotion was implemented upstream in
* a8d7ce5cf1ccd6c8a81fa5b4569afa3aa3c2882d aci: add IPA servers host group 'ipaservers'
* 7b9a97383ce4090d30e624fc8b7263d6c5f1b823 aci: replace per-server ACIs with
* 8f36a5bd68140fdd338d9c738977a6c67fdfdf08 replica install: add ipaservers if it does not exist
HBAC rule was not implemented and is not needed for replica promotion.
This bug was accidentally moved from POST to MODIFIED via an error in automation, please see email@example.com with any questions
copying comment: https://fedorahosted.org/freeipa/ticket/3416#comment:14
admins user group and ipaservers host group exist now(4.3). Therefore moving this ticket to 4.3 as fixed.
For the hbac rule part, if anybody wants it, please open a new RFE ticket.
this bz was part of rebase
Please provide steps to verify this.
IPA-server version: ipa-server-4.4.0-12.el7.x86_64
Tested the bug on the basis of following steps:
1. Noticed that new user group 'admin' is now available for latest version of IPA server.
2. Noticed that new hostgroup "ipaservers" is now available for latest version of IPA server.
3. Noticed that Master/ replica automatically become part of it after upgrade or on fresh install of ipa-server/replica.
4. Noticed that new users can be manually added to 'admins' group.
5. Noticed that new host can be manually added to 'ipaservers' group.
6. As for the hbacrule observation (HBAC rule is not implemented) in above comment#2 and #4, it will be handled separately.
Thus on the basis of above observations, marking the status of bug to "VERIFIED".
Bug is verified needinfo is not needed, I was contacted personally.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.