[Freeipa-devel] [PATCH 0339] trusts: Check for AD root domain among our trusted domains

Petr Vobornik pvoborni at redhat.com
Fri Jul 17 15:06:08 UTC 2015


On 07/15/2015 02:41 PM, Tomas Babej wrote:
>
>
> On 07/15/2015 02:31 PM, Alexander Bokovoy wrote:
>> On Wed, 15 Jul 2015, Tomas Babej wrote:
>>> Hi,
>>>
>>> Check for the presence of the forest root DNS domain of the AD realm
>>> among the IPA realm domains prior to esablishing the trust.
>>>
>>> This prevents creation of a failing setup, as trusts would not work
>>> properly in this case.
>>>
>>> https://fedorahosted.org/freeipa/ticket/4799
>> LGTM.
>>
>> The only comment I have is for the error message text. Would it make
>> sense to point to 'ipa realmdomans-mod --del-domain' command?
>>
>>
>
> Sure, why not.
>
> I actually abstained from generating the whole command (including the AD
> domain argument), as I believe it's better the users are discouraged
> from blindly copying commands around.
>
> Updated patch attached.
>
> Toams
>
>
>

ACK

Pushed to:
master: 45958d62197296eabe5513ea392e204e1d49d5c6
ipa-4-2: ddec4500161cce0fd258cbc011efca27ef1f5392
-- 
Petr Vobornik




More information about the Freeipa-devel mailing list