RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1999017 - subid-range is displayed in 'idrange-find' after uninstall-install of ipa-server.
Summary: subid-range is displayed in 'idrange-find' after uninstall-install of ipa-ser...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: ipa
Version: 9.0
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: François Cami
QA Contact: ipa-qe
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-08-30 09:15 UTC by Sudhir Menon
Modified: 2021-08-31 14:01 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-08-31 14:01:19 UTC
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-95560 0 None None None 2021-08-30 09:46:30 UTC

Description Sudhir Menon 2021-08-30 09:15:31 UTC
Description of problem: ipa subid-range is present even after reinstall of ipa-server
 
Version-Release number of selected component (if applicable):
ipa-server-4.9.6-6.el9.x86_64
389-ds-base-2.0.8-1.el9.x86_64
pki-server-11.0.0-0.4.alpha1.el9.noarch

How reproducible: Always

Steps to Reproduce:
1. Install IPA server | kinit admin
2. Run ipa subid-generate
3. Uninstall IPA server and reinstall again and check the output of 'ipa idrange-find' command

Actual results:
2. The idrange is generated
[root@server ~]# ipa subid-generate
-----------------------------------------------------------
Added subordinate id "b4775188-261d-485e-a7b4-097a005141c9"
-----------------------------------------------------------
  Unique ID: b4775188-261d-485e-a7b4-097a005141c9
  Description: auto-assigned subid
  Owner: admin
  SubUID range start: 2147483648
  SubUID range size: 65536
  SubGID range start: 2147483648
  SubGID range size: 65536

3. Post reinstall the subid range is listed

[root@server ~]# kinit admin
Password for admin:
[root@server ~]# ipa idrange-find
----------------
2 ranges matched
----------------
  Range name: RHEL90.TEST_id_range
  First Posix ID of the range: 312200000
  Number of IDs in the range: 200000
  Range type: local domain range
 
  Range name: RHEL90.TEST_subid_range
  First Posix ID of the range: 2147483648
  Number of IDs in the range: 2147352576
  First RID of the corresponding RID range: 2147283648
  Domain SID of the trusted domain: S-1-5-21-738065-838566-3237957612
  Range type: Active Directory domain range
----------------------------
Number of entries returned 2
----------------------------

Not sure if reinstall should list the subid range, but when i check the specific subid which was generated it displays error.

[root@server ~]# ipa subid-show
Unique ID: b4775188-261d-485e-a7b4-097a005141c9
ipa: ERROR: b4775188-261d-485e-a7b4-097a005141c9: Subordinate id not found

Expected results: Logging the above scenario as bug to check if this is expected behaviour.

Additional info:

Comment 1 François Cami 2021-08-30 13:35:58 UTC
Taking for investigating. I bet it's some kind of cache (sssd?).

Comment 2 François Cami 2021-08-31 14:01:19 UTC
In fact, this is not a bug. On a freshly installed system, the two ranges are already present by design. Adding the subid range does not alter that.

[root@ipa0 ~]# ipa subid-find
-------------------------
0 subordinate ids matched
-------------------------
----------------------------
Number of entries returned 0
----------------------------
[root@ipa0 ~]# ipa idrange-find
----------------
2 ranges matched
----------------
  Range name: LAPTOP.EXAMPLE.ORG_id_range
  First Posix ID of the range: 860600000
  Number of IDs in the range: 200000
  Range type: local domain range
 
  Range name: LAPTOP.EXAMPLE.ORG_subid_range
  First Posix ID of the range: 2147483648
  Number of IDs in the range: 2147352576
  First RID of the corresponding RID range: 2147283648
  Domain SID of the trusted domain: S-1-5-21-738065-838566-3831296979
  Range type: Active Directory domain range
----------------------------
Number of entries returned 2
----------------------------
[root@ipa0 ~]# ipa subid-generate
-----------------------------------------------------------
Added subordinate id "582f9ded-1bf9-40f2-9474-558bae50855f"
-----------------------------------------------------------
  Unique ID: 582f9ded-1bf9-40f2-9474-558bae50855f
  Description: auto-assigned subid
  Owner: admin
  SubUID range start: 2147483648
  SubUID range size: 65536
  SubGID range start: 2147483648
  SubGID range size: 65536
[root@ipa0 ~]# ipa subid-find
------------------------
1 subordinate id matched
------------------------
  Unique ID: 582f9ded-1bf9-40f2-9474-558bae50855f
  Owner: admin
  SubUID range start: 2147483648
  SubUID range size: 65536
  SubGID range start: 2147483648
  SubGID range size: 65536
----------------------------
Number of entries returned 1
----------------------------
[root@ipa0 ~]# ipa idrange-find
----------------
2 ranges matched
----------------
  Range name: LAPTOP.EXAMPLE.ORG_id_range
  First Posix ID of the range: 860600000
  Number of IDs in the range: 200000
  Range type: local domain range
 
  Range name: LAPTOP.EXAMPLE.ORG_subid_range
  First Posix ID of the range: 2147483648
  Number of IDs in the range: 2147352576
  First RID of the corresponding RID range: 2147283648
  Domain SID of the trusted domain: S-1-5-21-738065-838566-3831296979
  Range type: Active Directory domain range
----------------------------
Number of entries returned 2
----------------------------


Note You need to log in before you can comment on or make changes to this bug.