Bug 1464498 - [Docs][Admin] Note that AD configuration examples are available in README files in the ovirt-engine-extension-aaa-ldap package
Summary: [Docs][Admin] Note that AD configuration examples are available in README fil...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Enterprise Virtualization Manager
Classification: Red Hat
Component: Documentation
Version: 4.1.0
Hardware: Unspecified
OS: Unspecified
medium
unspecified
Target Milestone: ovirt-4.1.6
: ---
Assignee: Avital Pinnick
QA Contact: Emma Heftman
URL:
Whiteboard:
Depends On: 1462294 1472254 1489402
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-06-23 14:56 UTC by Marian Jankular
Modified: 2022-03-13 14:19 UTC (History)
13 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-01-17 12:40:44 UTC
oVirt Team: Docs
Target Upstream Version:
Embargoed:
lsvaty: testing_plan_complete-


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 1450555 0 unspecified CLOSED [KBase][Docs] - the ovirt-engine-extension-aaa-ldap setup dialog and section 15.3.2 of the RHV Administration Guide abou... 2021-02-22 00:41:40 UTC

Internal Links: 1450555

Description Marian Jankular 2017-06-23 14:56:20 UTC
Description of problem:
ovirt-engine-extension-aaa-ldap is working most of the time, however lot of customers have special setups (multiple A records for each domain controller, domain/forest trusts, domain controllers behind firewall so they can not use srvrecord serverset for example)
Would it be possible to document all the possible directives because all i have found is:

https://github.com/oVirt/ovirt-engine-extension-aaa-ldap/blob/master/README.profile 
https://github.com/oVirt/ovirt-engine-extension-aaa-ldap

And that is not all off it. It would be nice if customers could find it on redhat customer portal with all directives described.

Thank you very much in advance.

Comment 1 Martin Perina 2017-06-23 19:19:02 UTC
(In reply to Marian Jankular from comment #0)
> Description of problem:
> ovirt-engine-extension-aaa-ldap is working most of the time, however lot of
> customers have special setups (multiple A records for each domain
> controller, domain/forest trusts, domain controllers behind firewall so they
> can not use srvrecord serverset for example)
> Would it be possible to document all the possible directives because all i
> have found is:
> 
> https://github.com/oVirt/ovirt-engine-extension-aaa-ldap/blob/master/README.
> profile 
> https://github.com/oVirt/ovirt-engine-extension-aaa-ldap
> 
> And that is not all off it. It would be nice if customers could find it on
> redhat customer portal with all directives described.
> 
> Thank you very much in advance.

Other details can be found at [1] and we also have oVirt AAA FAQ [2], which we are extending when someone report problem which can be interesting also for others.

We can add some additional documentation, but aaa-ldap is so extensible, that pretty much anything can be achieved by changing property files. Anyway providing more detailed description of all properties and all possible customizations is a huge task ...


[1] https://github.com/oVirt/ovirt-engine-extension-aaa-ldap/blob/master/README
[2] http://www.ovirt.org/develop/release-management/features/infra/aaa_faq/

Comment 6 Martin Perina 2017-08-03 13:02:57 UTC
As a part of BZ1462294 (RHV 4.2) and BZ1472254 (RHV 4.1.5) we will provide examples for most common AD configurations which cannot be configured using ovirt-engine-extension-aaa-ldap-setup tool. Examples with corresponding README.md files will be part of ovirt-engine-extension-aaa-ldap package, so you can link or even fully document those examples in Administration Guide

Comment 7 Lucy Bopf 2017-08-08 00:34:48 UTC
Thanks, Martin! That's great. We've decided that we'll mention these examples in the Admin Guide, and tell users where to find them. That way, you can update the examples in the package at any time, and we won't need to update the Admin Guide to match.

Comment 8 Martin Perina 2017-10-27 08:55:40 UTC
Additional examples around using GSSAPI has been added to ovirt-engine-extension-aaa-ldap-1.3.5, which will be part of 4.1.8 (BZ1489402)

Comment 19 Emma Heftman 2018-01-17 11:32:37 UTC
Verified and merged.


Note You need to log in before you can comment on or make changes to this bug.