Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2002712

Summary: When installing RHOSP 17.0 with freeipa, overcloud installation fails.
Product: Red Hat OpenStack Reporter: tkorol <tkorol>
Component: ansible-tripleo-ipaAssignee: Ade Lee <alee>
Status: CLOSED NOTABUG QA Contact: Jeremy Agee <jagee>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 17.0 (Wallaby)CC: ggrasza
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-10-04 14:29:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description tkorol@redhat.com 2021-09-09 14:54:04 UTC
Description of problem:
When installing RHOSP 17.0 with freeipa, Overcloud installation fails with the following error message:

FATAL | add dns zone | undercloud | error={"changed": false, "msg": "response dnszone_add: Insufficient access: Insufficient 'write' privilege to the 'associatedDomain' attribute of entry 'cn=realm domains,cn=ipa,cn=etc,dc=redhat,dc=local'."}

Version-Release number of selected component (if applicable):
RHOS-17.0

Overcloud log can be accessed by this link: http://rhos-ci-logs.lab.eng.tlv2.redhat.com/logs/rhos-ci-staging-jenkins/phase2-17.0_compact-director-rhel-8.4-virthost-1cont_1comp_1ceph_1freeipa-ipv4-geneve-ceph-tls/3/undercloud-0/home/stack/overcloud_install.log.gz

The job is https://rhos-ci-staging-jenkins.lab.eng.tlv2.redhat.com/view/QE/view/OSP17.0/job/phase2-17.0_compact-director-rhel-8.4-virthost-1cont_1comp_1ceph_1freeipa-ipv4-geneve-ceph-tls/

Thanks

Comment 2 Grzegorz Grasza 2021-09-20 14:22:50 UTC
Please confirm if this is a configuration issue, and close the bug.

Comment 3 Ade Lee 2021-10-04 14:29:42 UTC
Closing as a configuration issue.  Please reopen if needed.