This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 1463186 - IPA shouldn't allow objectclass if not all in lower case
IPA shouldn't allow objectclass if not all in lower case
Status: POST
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa (Show other bugs)
Unspecified Unspecified
unspecified Severity unspecified
: rc
: ---
Assigned To: Pavel Vomacka
Depends On:
  Show dependency treegraph
Reported: 2017-06-20 06:58 EDT by Ming Davies
Modified: 2017-10-10 23:35 EDT (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Ming Davies 2017-06-20 06:58:24 EDT
Description of problem:
Customer said that they migrated users from the older version of IPA that had "objectclass=posixAccount" rather than "objectclass=posixaccount, which is problematic when comes to using "ipa idoverrideuser-add"

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. Create two users in IPA using a ldif file, one with ""objectclass=posixAccount" and the other with "objectclass=posixAccount"
2. Load the users to the IPA
3. Then run:
ipa idview-add testview
ipa idoverrideuser-add testview <username> --homeDirectory=/var/tmp

Actual results:

user with "objectClass: posixAccount"
# ipa idoverrideuser-add testview cgoodwin --homedir=/home/cgoodwin
ipa: ERROR: invalid 'IPA object': system IPA objects (e.g system groups, user private groups) cannot be overridden

user with "objectClass: posixaccount
# ipa idoverrideuser-add testview bgoodwin --homedir=/home/mygoodwin
Added User ID override "bgoodwin"
  Anchor to override: bgoodwin
  Home directory: /home/mygoodwin

Expected results:

Additional info:
The workaround is to replace "objectclass=posixAccount" with "objectclass=posixaccount
Comment 2 Petr Vobornik 2017-07-28 11:34:56 EDT
Upstream ticket:
Comment 3 Stanislav Laznicka 2017-09-12 12:05:32 EDT
Fixed upstream
Comment 4 Stanislav Laznicka 2017-09-13 02:47:13 EDT
Fixed upstream
Comment 5 Stanislav Laznicka 2017-09-14 02:36:45 EDT
Fixed upstream

Note You need to log in before you can comment on or make changes to this bug.