[Freeipa-users] export users/groups from one ipa server to another

Rob Crittenden rcritten at redhat.com
Fri Jan 17 20:59:04 UTC 2014


Les Stott wrote:
>> The first time your migrated production users authenticate with their
>> password their Kerberos credentials will be generated.
>
> Is there a way to avoid this?
>
> I had to do that for importing shadow files originally in DR. now, i'm going from freeipa to freeipa. if i export kerberos attributes will that avoid users having to regenerate the kerberos credentials?

No. The kerberos master keys are different.

rob




More information about the Freeipa-users mailing list