Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1437502 - ipa-replica-install fails with requirement to use --force-join that is a client install option.
ipa-replica-install fails with requirement to use --force-join that is a clie...
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.4
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: IPA Maintainers
Abhijeet Kasurde
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-30 08:24 EDT by German Parente
Modified: 2017-08-01 05:47 EDT (History)
7 users (show)

See Also:
Fixed In Version: ipa-4.5.0-7.el7
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2017-08-01 05:47:49 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
console.log (6.50 KB, text/plain)
2017-06-02 04:23 EDT, Abhijeet Kasurde
no flags Details


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:2304 normal SHIPPED_LIVE ipa bug fix and enhancement update 2017-08-01 08:41:35 EDT

  None (edit)
Description German Parente 2017-03-30 08:24:38 EDT
Description of problem:


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:
Comment 2 German Parente 2017-03-30 08:28:16 EDT
Bug was saved without description:

Customer is installing replica:

ipa-replica-install --server <server> --domain <domain> --realm <realm> --setup-ca --setup-dns --no-forwarders --principal admin --admin-password some-passwd
Configuring client side components
Client hostname: XXXX
Realm: XXXXX
DNS Domain: XXXX
IPA Server: xXXXXXX
BaseDN: XXXXXXXX

Skipping synchronizing time with NTP server.
Successfully retrieved CA cert
    Subject:     CN=Certificate Authority,O=XXXX
    Issuer:      CN=Certificate Authority,O=XXXX
    Valid From:  Wed Mar 01 11:51:48 2017 UTC
    Valid Until: Sun Mar 01 11:51:48 2037 UTC

Joining realm failed: Host is already joined.

Use --force-join option to override the host entry on the server and force client enrollment.
Installation failed. Rolling back changes.
IPA client is not configured on this system.
Removing client side components
IPA client is not configured on this system.


But when he wants to install replica with --force-join, it does not work because it's an ipa-client-install option.

The workaround is to do a first ipa-client-install --force-join and then a ipa-replica-install
Comment 3 Petr Vobornik 2017-04-04 06:12:57 EDT
If there is high demand we might try to fix this in 7.4(add --force-join option to replica installer) (there was already a preliminary patch), if not, I'd rather post-pone to future release.
Comment 5 Petr Vobornik 2017-04-05 04:47:26 EDT
Upstream ticket:
https://pagure.io/freeipa/issue/6183
Comment 8 Abhijeet Kasurde 2017-06-02 04:23:15 EDT
Version verified using IPA version ::

ipa-server-4.5.0-14.el7.x86_64

Marking BZ as verified. See attachment as console.log.
Comment 9 Abhijeet Kasurde 2017-06-02 04:23 EDT
Created attachment 1284349 [details]
console.log
Comment 10 errata-xmlrpc 2017-08-01 05:47:49 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:2304

Note You need to log in before you can comment on or make changes to this bug.