<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">On 04/07/2015 03:04 PM, Natxo Asenjo
wrote:<br>
</div>
<blockquote
cite="mid:CAHBEJzUqutu8OSvxU98apOne6Oug4o+6MqCa8hOppu_oNHuyog@mail.gmail.com"
type="cite">
<div dir="ltr">
<div class="gmail_extra">
<div class="gmail_quote">hi,<br>
<br>
On Fri, Apr 3, 2015 at 4:41 PM, Dmitri Pal <span dir="ltr"><<a
moz-do-not-send="true" href="mailto:dpal@redhat.com"
target="_blank">dpal@redhat.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="#FFFFFF" text="#000000"><span class="">
<div>On 04/03/2015 09:46 AM, Brian Topping wrote:<br>
</div>
<blockquote type="cite">
<blockquote type="cite">
<pre>On Apr 3, 2015, at 6:48 AM, Tamas Papp <a moz-do-not-send="true" href="mailto:tompos@martos.bme.hu" target="_blank"><tompos@martos.bme.hu></a> wrote:
hi All,
I have CentOS 6.6 server and want to upgrade to 7.1.
What is the upgrade path, can I do it directly or first I need to make it to 3.3?
Also is there any known issue I should expect with workarounds?
</pre>
</blockquote>
<pre>I just did this yesterday, so here's my experience. If you have a simple single-server installation with no custom LDAP DIT modifications, you should find "yum upgrade" does the right thing.
If you do have DIT mods, you should ask yourself why they are there and whether the data will still be accessible after the ACLs are changed. In my case, I had Postfix using a LDAP hash and mail delivery stopped working (although the domain data was still there just fine).
Note that the ACLs will propagate from the 4.1 server to your 3.0 if they are replicated. To be safe, back up all replicas (snapshot or whatnot) before the first upgrade and if you decide to restore any of them, be sure everything is shut down and restore all of them to avoid 4.x schema contaminating 3.0 as they come up.</pre>
</blockquote>
<br>
<br>
</span> The general recommendation for 3.3 -> 4.1
migration is to start introducing 4.1 replicas into your
3.3 environment and then turn your 3.3 replicas off. Do
not forget to install the CA component with one of your
4.1 replicas before removing all the 3.3 instanced with
CAs. With this procedure you would also need to move the
CRL generation and cert tracking.<br>
<br>
See details in migration section
<a moz-do-not-send="true"
href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html-single/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html#migrating-ipa-proc"
target="_blank">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html-single/Linux_Domain_Identity_Authentication_and_Policy_Guide/index.html#migrating-ipa-proc</a><span
class=""><br>
</span></div>
</blockquote>
<div><br>
</div>
<div> Will this excellent documentation work too on the
migration from 3.0x (rhel 6) to 4.1.x (rhel 7.1)? <br>
<br>
</div>
<div>I will be migrating the coming months to 7.1 or 7.2
(whichever is the current stable then), so just wondering.<br>
</div>
</div>
</div>
</div>
</blockquote>
<br>
Yes, though it is recommended to get to the latest 6.x first before
you start introducing 7.x replicas.<br>
<br>
<blockquote
cite="mid:CAHBEJzUqutu8OSvxU98apOne6Oug4o+6MqCa8hOppu_oNHuyog@mail.gmail.com"
type="cite">
<div dir="ltr">
<div class="gmail_extra">
<div class="gmail_quote">
<div><br>
</div>
<div>Thanks!<br>
<br>
</div>
</div>
<div class="gmail_signature">--<br>
Groeten,<br>
natxo</div>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<br>
<br>
<pre class="moz-signature" cols="72">--
Thank you,
Dmitri Pal
Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
</body>
</html>