[Freeipa-users] Gave Up on RHEL6->7 migration, starting over. (ipa migrate-ds)

Benjamin Reed ranger at opennms.org
Tue Mar 17 16:56:24 UTC 2015


On 3/17/15 12:29 PM, Martin Kosek wrote:
> 1) Migrate users via SSSD and simply SSH or log in to any machine enrolled to
> the new IPA, as I showed in the example

I'll have my users who need working kerberos ssh in.  The union of the
set of users who need kerberos and users who ssh is a circle.  ;)

> 2) Implement your own migration tool, doing an LDAP BIND for the migrated user
> (this is what SSSD does too anyway).
>
> 3) (hackish) Until the potential ticket is fixed, you can try to fix
> /usr/share/ipa/migration/migration.py on the IPA server yourself. This is the
> migration script that is used. If you actually fix it, you may even think about
> contributing the fix to FreeIPA project as a patch, it would be very welcome :-)

I looked at the script and I don't know python or how the binding stuff
is set up enough to understand making a patch, but I have at least
created an issue: https://fedorahosted.org/freeipa/ticket/4953

Thanks again for your help.  I've been banging my head on getting away
from our broken old FreeIPA server for quite some time.

-- 
Benjamin Reed
The OpenNMS Group
http://www.opennms.org/


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://listman.redhat.com/archives/freeipa-users/attachments/20150317/93c2422f/attachment.sig>


More information about the Freeipa-users mailing list