Bug 813880 - Improvement: promoting and recycling replicas/servers
Summary: Improvement: promoting and recycling replicas/servers
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: doc-Identity_Management_Guide
Version: 6.3
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: Deon Ballard
QA Contact: ecs-bugs
Depends On:
TreeView+ depends on / blocked
Reported: 2012-04-18 16:22 UTC by Deon Ballard
Modified: 2012-07-03 02:54 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2012-07-03 02:54:41 UTC
Target Upstream Version:

Attachments (Terms of Use)

Description Deon Ballard 2012-04-18 16:22:27 UTC
There is a section on promoting a replica to a server. It's really not well explained what is happening or why because replicas and servers are functionally identical, with one exception.

There are two problems that need to be addressed:

1. The replica promotion process itself needs to be clarified.

2. There needs to be a larger explanation on how to decommission and re-install replicas and servers.

Comment 1 Deon Ballard 2012-04-18 16:35:57 UTC
So, for part 1:

Only the first CA generates the CRL. All this promotion change does is defines which of the remaining servers will generate the CRL. We want to change the language of "promotion" but it is still true that all the CAs are peers. 

For selfsign, the CA cert needs to be imported into the Apache databsae (/etc/httpd/alias), not 389-ds. The cacert.p12 is the file generated during installation that was saved by the user.

Comment 2 Deon Ballard 2012-04-18 16:38:53 UTC
Part 2:

This probably needs to come from dev, but there needs to be a blessed procedure for wiping out a server or replica cleanly (part 2a) and then re-installing it later (part 2b).

Comment 5 Deon Ballard 2012-06-22 21:48:44 UTC
Okay, changes...

For comment #1. Working backwards, self-signed CAs (for other reasons) have been dropped from the documentation entirely. While still possible to configure, this is very much not a recommended or supported option. Less said, the better.

All that "promoting" a replica means is having one server take over CRL generation for the domain. That is, hopefully, more clear here:

For comment #2, there is a procedure to remove a replica:

There is no specific procedure for re-installing a replica.

Note You need to log in before you can comment on or make changes to this bug.