Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1485700

Summary: [Docs][RFE][Admin] Document how to remove LDAP provider configuration
Product: Red Hat Enterprise Virtualization Manager Reporter: Avital Pinnick <apinnick>
Component: DocumentationAssignee: Avital Pinnick <apinnick>
Status: CLOSED CURRENTRELEASE QA Contact: Tahlia Richardson <trichard>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 4.1.1CC: apinnick, bazulay, lbopf, lsurette, mperina, oourfali, rbalakri, Rhev-m-bugs, srevivo, ykaul
Target Milestone: ovirt-4.1.6Keywords: FutureFeature
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-11-12 07:54:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: Docs RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1409827    
Bug Blocks:    

Description Avital Pinnick 2017-08-27 10:14:51 UTC
If you want to remove a configured LDAP provider, you need to do following (assuming here the default name 'profile1', please rename according to your setup):

  1. Remove provider configuration files

      rm /etc/ovirt-engine/extensions.d/profile1-authn.properties
      rm /etc/ovirt-engine/extensions.d/profile1-authz.properties
      rm /etc/ovirt-engine/aaa/profile1.properties

  2. Restart ovirt-engine

      systemctl restart ovirt-engine


The above will remove provider configuration, so users from this provider will no longer be able to login into engine.

But those users still have permissions defined in engine, so if you want to remove those permissions you need to do following:

  1. Login into webadmin and switch to Users tab
  2. Remove all users from the provider you have removed above (they should have their Authorization provider set to 'profile1-authz'