<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<p dir="ltr">Yes, kind of. I wanted a new environment with a proper certificate authority setup with only the old users and groups from the IPA 3.0 environment. The old environment use a self signed ca, I thought it would be easier to just migrate my users
and groups.</p>
<div class="x_gmail_quote">On 9 Sep 2015 4:49 pm, Rob Crittenden <rcritten@redhat.com> wrote:<br type="attribution">
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">Andreas Calminder wrote:<br>
> Hi,<br>
> thanks for your reply, I'm able to list the user with ldapsearch and I<br>
> can't find any conflict entries described in the article. The 4.1<br>
> environment is only 1 server connected to active directory. Forgot to<br>
> reply to the list before, doh!<br>
> <br>
> I've noticed a difference between users in 3.0 and 4.1 though, migrated<br>
> users in the 4.1 does not have an entry in "<br>
> cn=groups,cn=accounts,dc=sub,dc=domain,dc=tld" while users in 3.0 have this.<br>
> Example:<br>
> <br>
> FreeIPA 4.1 environment:<br>
> # ldapsearch -xLLL -D "cn=directory manager" -W<br>
> -b"cn=batman,cn=groups,cn=accounts,dc=sub,dc=domain,dc=tld"<br>
> Enter LDAP Password:<br>
> No such object (32) Matched DN:<br>
> cn=groups,cn=accounts,dc=sub,dc=domain,dc=tld<br>
> <br>
> FreeIPA 3.0 environment:<br>
> # ldapsearch -xLLL -D "cn=directory manager" -W -b<br>
> "cn=batman,cn=groups,cn=accounts,dc=sub,dc=domain,dc=tld"<br>
> Enter LDAP Password:<br>
> dn: cn=batman,cn=groups,cn=accounts,dc=dev,dc=sub,dc=domain,dc=tld<br>
> objectClass: posixgroup<br>
> objectClass: ipaobject<br>
> objectClass: mepManagedEntry<br>
> objectClass: top<br>
> cn: batman<br>
> gidNumber: 1486600065<br>
> description: User private group for batman<br>
> mepManagedBy: uid=batman,cn=users,cn=accounts,dc=sub,dc=domain,dc=tld<br>
> ipaUniqueID: 139f6140-5074-11e5-a09d-005056914c0c<br>
<br>
Migrated users don't get user-private groups created.<br>
<br>
Is there a reason you migrated from 3.0 to 4.1 rather than just adding a<br>
4.1 master to the existing pool?<br>
<br>
rob<br>
<br>
> <br>
> /andreas<br>
> <br>
> On 09/09/2015 04:29 PM, Rich Megginson wrote:<br>
>> On 09/09/2015 03:39 AM, Martin Basti wrote:<br>
>>><br>
>>><br>
>>> On 09/09/2015 10:50 AM, Andreas Calminder wrote:<br>
>>>> Forgot to write that deleting users in active directory not migrated<br>
>>>> with the migrate-ds command works fine, it's only migrated users<br>
>>>> present in the ad that breaks the winsync agreement on deletion.<br>
>>>><br>
>>>> On 09/09/2015 10:35 AM, Andreas Calminder wrote:<br>
>>>>> Hi,<br>
>>>>> I've asked in #freeipa on freenode but to no avail, figured I'll<br>
>>>>> ask here as well, since I think I've actually hit a bug or (quite)<br>
>>>>> possibly I've done something moronic configuration/migration -wise.<br>
>>>>><br>
>>>>> I've got an existing FreeIPA 3.0.0 environment running with a fully<br>
>>>>> functioning winsync agreement and passsync service with the windows<br>
>>>>> environments active directory, I'm trying to migrate the 3.0.0<br>
>>>>> environments users into a freshly installed 4.1 (rhel7)<br>
>>>>> environment, after migration I setup a winsync agreement and make<br>
>>>>> it bi-directional (one-way sync from windows) everything seems to<br>
>>>>> be working alright until I delete a migrated user from the Active<br>
>>>>> Directory, after the winsync picks up on the change it'll break and<br>
>>>>> suggests a re-initialize. After the re-initialization the agreement<br>
>>>>> seems to be fine, however the deleted user are still present in the<br>
>>>>> ipa 4.1 environment and cannot be deleted. The webgui and ipa cli<br>
>>>>> says: ipauser1: user not found. ipa user-find ipauser1 finds the<br>
>>>>> user and it's visible in the ui.<br>
>>>>><br>
>>>>> Anyone had the same problem or anything similar or any pointers on<br>
>>>>> where to start looking?<br>
>>>>><br>
>>>>> Regards,<br>
>>>>> Andreas<br>
>>>>><br>
>>>><br>
>>><br>
>>> Hello, this might be a replication conflict.<br>
>>><br>
>>> Can you list that user via ldapsearch to check if this is replication<br>
>>> conflict?<br>
>>><br>
>>> <a href="https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html">
https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/8.2/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html</a><br>
>>><br>
>>><br>
>> Use the latest docs, just in case they are more accurate:<br>
>> <a href="https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html">
https://access.redhat.com/documentation/en-US/Red_Hat_Directory_Server/10/html/Administration_Guide/Managing_Replication-Solving_Common_Replication_Conflicts.html</a><br>
>><br>
>><br>
> <br>
> <br>
> <br>
<br>
</div>
</span></font>
</body>
</html>