[Freeipa-devel] [PATCH] Add DS to IPA migration plugin and password migration page.

Pavel Zuna pzuna at redhat.com
Thu Oct 29 17:20:03 UTC 2009


Example output of migration plugin:

I have a DS server setup on a VM at 192.168.122.4 and I made a few tweaks to 
show how errors are reported.

# ipa migrate-ds ldap://192.168.122.4:389
Password:
Enter password again to verify:
-----------
migrate-ds:
-----------
Migrated:
   users: pzuna, mnagy
   groups: skupina1, skupina2, skupina3
Errors:
   user: mnagy: Kerberos principal mnagy at PZUNA already exists. Use 'ipa 
user-mod' to set it manually.
   group: accounting managers: This entry already exists
   group: hr managers: This entry already exists
   group: qa managers: This entry already exists
   group: pd managers: This entry already exists
----------
Passwords have been migrated in pre-hashed format. IPA is unable to generate 
Kerberos keys unless provided with clean text passwords. All migrated users need 
to login at http://your.domain/ipa/migration/ before they can use their Kerberos 
accounts.

I didn't try it yet, but this might also work for IPAv1->IPAv2 migration.

Pavel
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Add-DS-migration-plugin-and-password-migration-page.patch
Type: application/mbox
Size: 17285 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/freeipa-devel/attachments/20091029/7c3cf2fe/attachment.mbox>


More information about the Freeipa-devel mailing list