Bug 499299 - ipa group-add-member doesn't seem to be finding groups and users
ipa group-add-member doesn't seem to be finding groups and users
Product: freeIPA
Classification: Community
Component: ipa-admintools (Show other bugs)
All Linux
low Severity medium
: ---
: ---
Assigned To: Rob Crittenden
Chandrasekar Kannan
Depends On:
  Show dependency treegraph
Reported: 2009-05-05 21:11 EDT by Michael Gregg
Modified: 2015-01-04 18:38 EST (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2009-05-06 15:55:13 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Michael Gregg 2009-05-05 21:11:42 EDT
Description of problem:
I may be using this utility wrong, and I know that the documentation isn't ready for this tool yet, but whenever I try to add one group to the member of another group, group-add-member reports "entry not found"

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. create group1
2. create group2
3. add group1 as a member of group2
Actual results:
ipa group-add-member --groups=group1 group2
ipa: ERROR: entry not found

Expected results:

Additional info:
I've also tried:
ipa group-add-member --groups=group2 cn=group1,cn=groups,cn=accounts,dc=dsdev,dc=sjc,dc=redhat,dc=com

ipa group-add-member --groups=cn=group1,cn=groups,cn=accounts,dc=dsdev,dc=sjc,dc=redhat,dc=com group2
Comment 1 Rob Crittenden 2009-05-05 21:53:23 EDT
I can't duplicate this. Can you re-run the group-add-member with the first (simpler) format then attach the last 100 lines of so of /var/log/httpd/error_log to the bug?
Comment 2 Michael Gregg 2009-05-06 13:33:13 EDT
[root@iparhel5-vma ~]# ipa group-add-member --groups=group1 group2
ipa: ERROR: entry not found

I know it's not 100 lines, but this what gets generated in the error_log.
ipa: INFO: Created connection context.ldap
ipa: DEBUG: raw: group_add_member(u'group2', groups=(u'group1',))
ipa: INFO: group_add_member(u'group2', groups=(u'group1',))
ipa: INFO: Destroyed connection context.ldap
ipa: INFO: response: NotFound: entry not found
Comment 3 Rob Crittenden 2009-05-06 13:57:09 EDT
The plot thickens...

Ok, need some LDAP logs then. Can you do this:

ipa group-show group1
ipa group-show group2
ipa group-add-member --groups=group1 group2

And attach the LDAP access log for that period?
Comment 4 Michael Gregg 2009-05-06 15:55:13 EDT
The problem ended up being that I had a QA daemon that was running and removing group2. 

That's why the command was reporting "entry not found" when I would try to add group1 to group2.

Note You need to log in before you can comment on or make changes to this bug.