Bug 1463186 - IPA shouldn't allow objectclass if not all in lower case
IPA shouldn't allow objectclass if not all in lower case
Status: ASSIGNED
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
7.3
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Pavel Vomacka
ipa-qe
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-06-20 06:58 EDT by Ming Davies
Modified: 2017-07-28 11:34 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Ming Davies 2017-06-20 06:58:24 EDT
Description of problem:
Customer said that they migrated users from the older version of IPA that had "objectclass=posixAccount" rather than "objectclass=posixaccount, which is problematic when comes to using "ipa idoverrideuser-add"

Version-Release number of selected component (if applicable):
ipa-server-4.4.0-14.el7_3.7.x86_64
389-ds-base-1.3.5.10-20.el7_3.x86_64


How reproducible:


Steps to Reproduce:
1. Create two users in IPA using a ldif file, one with ""objectclass=posixAccount" and the other with "objectclass=posixAccount"
2. Load the users to the IPA
3. Then run:
ipa idview-add testview
ipa idoverrideuser-add testview <username> --homeDirectory=/var/tmp

Actual results:

user with "objectClass: posixAccount"
# ipa idoverrideuser-add testview cgoodwin --homedir=/home/cgoodwin
ipa: ERROR: invalid 'IPA object': system IPA objects (e.g system groups, user private groups) cannot be overridden


user with "objectClass: posixaccount
# ipa idoverrideuser-add testview bgoodwin --homedir=/home/mygoodwin
---------------------------------
Added User ID override "bgoodwin"
---------------------------------
  Anchor to override: bgoodwin
  Home directory: /home/mygoodwin


Expected results:


Additional info:
The workaround is to replace "objectclass=posixAccount" with "objectclass=posixaccount
Comment 2 Petr Vobornik 2017-07-28 11:34:56 EDT
Upstream ticket:
https://pagure.io/freeipa/issue/7074

Note You need to log in before you can comment on or make changes to this bug.