Bug 1665051
| Summary: | ipa-adtrust-install does not list service records for manual addition to DNS zone | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | Sergey Orlov <sorlov> |
| Component: | ipa | Assignee: | IPA Maintainers <ipa-maint> |
| Status: | CLOSED ERRATA | QA Contact: | ipa-qe <ipa-qe> |
| Severity: | unspecified | Docs Contact: | Lucie Vařáková <lmanasko> |
| Priority: | unspecified | ||
| Version: | 8.0 | CC: | abokovoy, fhanzelk, ksiddiqu, pasik, pcech, pvoborni, rcritten, tscherf, twoerner, vferschm |
| Target Milestone: | rc | Keywords: | Regression |
| Target Release: | 8.0 | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: |
.Information about required DNS records is now displayed when enabling support for AD trust in IdM
Previously, when enabling support for Active Directory (AD) trust in Red Hat Enterprise Linux Identity Management (IdM) installation with external DNS management, no information about required DNS records was displayed. Entering the `ipa dns-update-system-records --dry-run` command manually was necesary to obtain a list of all DNS records required by IdM.
With this update, the `ipa-adtrust-install` command correctly lists the DNS service records for manual addition to the DNS zone.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | 2020-04-28 15:43:29 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1683261 | ||
| Bug Blocks: | |||
| Attachments: | |||
|
Description
Sergey Orlov
2019-01-10 12:02:11 UTC
The same behavior is observed also in Fedora28 and RHEL 7 I think it is a regression but we can fix it in a next minor release because we have a workaround: # ipa dns-update-system-records --dry-run --out records.txt will return you all records that need to exist for IPA to function in a format that nsupdate tool understands. If you remove '--out records.txt', then just list of the records will be provided, as expected. Created attachment 1524991 [details]
Output of ipa-server-install
Created attachment 1524994 [details]
Output of first run of ipa-adtrust-install
Created attachment 1524995 [details]
Output of second run of ipa-adtrust-install
Created attachment 1524996 [details]
Log file of ipa-server-install and both runs of ipa-adtrust-install
Upstream PR: https://github.com/freeipa/freeipa/pull/4221 Fixed upstream master: https://pagure.io/freeipa/c/b3dbb36867ebf52483834ceb247050a24cf74d7c Fixed upstream ipa-4-8: https://pagure.io/freeipa/c/936e27f75961c67e619ecfa641e256ce80662d68 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2020:1640 |