[Freeipa-users] FreeIPA 4.4 - Can't find topology segment, nsunique attribute

Georgijs Radovs georgijsr at scandiweb.com
Thu Dec 22 08:31:46 UTC 2016


Hello everyone!

Today, I've updated 2 FreeIPA servers from version 4.2 to version 4.4.

Both of these servers are Masters and CAs, both are replicating between 
each other.

But, when I run

*ipa topologysegment-find* to view replication agreements for *domain* 
and *ca* suffixes

it returns zero results.

Web UI also does not show any agreements, but when I try to create a 
replication agreement between both servers, I get error that agreement 
already exists.

Also, when viewing directory using ldap browser, I found these containers:

DN: 
cn=ca+nsuniqueid=7252d047-c76611e6-a1fcaefe-5d4473a3,cn=topology,cn=ipa,cn=etc,dc=example,dc=com

DN: 
cn=domain+nsuniqueid=7252d000-c76611e6-a1fcaefe-5d4473a3,cn=topology,cn=ipa,cn=etc,dc=example,dc=com

Both of them contain topology segments, which I'm trying to create, but 
they do not show up anywhere.

How do I remove nsuniqueid attribute or delete those containers?

-- 
 <https://www.youtube.com/watch?v=bs0V2F06liw>




More information about the Freeipa-users mailing list