Red Hat Bugzilla – Bug 815515
RFE: Update the DUA profile included in IPA
Last modified: 2017-06-14 14:34:47 EDT
Please see attached an updated DUA profile for updating the default DUA profile in IPA.
This DUA profile configures the following that should be in the default profile:
* Printer objectclass mapping so that printers for the Solaris printer service can be added to the directory using existing objectclasses
The DUA profile also includes the following that can be specified in a seperate DUA config profile as an extended example:
* Sets the LDAP connection to be authenticated and secured, using a proxy account.
* Sets a default server list and list of preferred server list for servers local to the client.
Provided in the attached example, but might not be included in the default dua profile as these entries cannot be managed using the IPA CLI or WEBUI:
* Aliases mapping for handling sendmail and postfix aliases. All required objectclasses already exists in IPA.
* Printers mapping for handling central management of the Solaris print service.
Created attachment 579657 [details]
Example DUA Config Profile
Make a knowledge base article and reference it in the documentation.
Kicking the FreeIPA doc bugs to Martin.
This message is a reminder that Fedora 17 is nearing its end of life.
Approximately 4 (four) weeks from now Fedora will stop maintaining
and issuing updates for Fedora 17. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '17'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version'
to a later Fedora version prior to Fedora 17's end of life.
Bug Reporter: Thank you for reporting this issue and we are sorry that
we may not be able to fix it before Fedora 17 is end of life. If you
would still like to see this bug fixed and are able to reproduce it
against a later version of Fedora, you are encouraged change the
'version' to a later Fedora version prior to Fedora 17's end of life.
Although we aim to fix as many bugs as possible during every release's
lifetime, sometimes those efforts are overtaken by events. Often a
more recent Fedora release includes newer upstream software that fixes
bugs or makes them obsolete.
Fedora 17 changed to end-of-life (EOL) status on 2013-07-30. Fedora 17 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.
If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version.
Thank you for reporting this bug and we are sorry it could not be fixed.
Any plans for updating the DUA profile soon? Should be quick and easy to implement and will help Solaris users implement IPA.
While we value your interest in IPA Solaris support, the implementation of the DUA profile is not on our nearest schedule at the moment. We lack both knowledge and resources to focus on integration with Solaris. This is where we need a help (ideally patches) and contribution from the community to help us push these features in.
I checked your example DUAConfigProfile and I think it cannot be just added to FreeIPA right away. E.g. for defaultServerList or preferredServerList, you would need to expand installers and ipa-replica-manage to handle these lists and update them when replica is added or updated to prevent it being outdated. printers or aliases serviceSearchDescriptor refers to objects not being available and so on. It is not as straightforward as it seems.
What I think that we can work on is to work together on
... and add all the steps needed to make IPA work on Solaris 10. I could for example prepare an updated page and you could review it. Would that work for you?
The default DUAprofile that's already included in IPA by default already contains defaultServerList which include the IPA servers hostnames, so I believe this is already taken care of.
The serviceSearchDescriptor for aliases and printers can be moved to a knowledge base article. I see that these will not be relevant for everyone and do not have sources by default in IPA.
I don't mind reviewing the article. Let me know when it's ready.
We had a discussion about this Bug. While IPA on Solaris and other platform should simply work when the standard protocols are used, in RHEL product we officially do not test, document or support IPA on Solaris platform.
I am therefore moving this Bugzilla to Fedora product as upstream-only Bug to properly set the expectations and also to allow fixing the Bugzilla without forcing developers to be bound by RHEL product processes.
Given the discussion in this bug and that FreeIPA upstream project no longer maintains it's own user guide besides the FreeIPA.org community wiki (details in http://www.freeipa.org/page/Upstream_User_Guide), I am closing this Bugzilla.
Please follow or contribute in the upstream ticket: