<p dir="ltr">Thanks Martin. <br>
Would upgrading both servers to 7.1 and then attempting a backup and restore from the CA-less replica to the new master be a safe option? Would this work better? </p>
<br><div class="gmail_quote">On Tue, May 26, 2015, 8:14 AM Martin Kosek <<a href="mailto:mkosek@redhat.com">mkosek@redhat.com</a>> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 05/26/2015 09:04 AM, Sina Owolabi wrote:<br>
> Hi Martin<br>
><br>
> I actually mean restore. It's a complicated situation... There once was a<br>
> primary and it's CA replica. The primary got hosed and was cloned a few years<br>
> ago from the replica. Then the replica got hosed a few times too, saved by the<br>
> "primary", only now it wouldn't install a CA during replica setup. Now the<br>
> cloned primary got hosed (it sees itself as a clone and being a the only CA,<br>
> has nowhere to go to renew certs). We opted to reinstall a fresh primary and<br>
> now we are looking for how to copy existing data from the standing CA-less<br>
> replica (everything is the same, realms, DNS hosts, HBAC, sudo rules, etc )<br>
> to the freshly installed CA primary.<br>
<br>
What do you mean by "hosed" replica? Do you know why it happened? This is<br>
obviously something that should not happen with FreeIPA, it being the backbone<br>
of the infrastructure.<br>
<br>
This is another reason why I think you should better build your infrastructure<br>
on RHEL-7.1, it has more Backup&Restore options (ipa-backup, ipa-restore):<br>
<br>
<a href="https://www.freeipa.org/page/Backup_and_Restore" target="_blank">https://www.freeipa.org/page/Backup_and_Restore</a><br>
<br>
> This would be amazing if we could or<br>
> we'll have to setup the entire network and rules from scratch.<br>
> I would really appreciate some example commands we could run to import data<br>
> into the new primary. We've already run db2bak and db2ldif on the replica to<br>
> export from a helpful script we found in a thread.<br>
> I hope you can help us!<br>
<br>
If realms is the same, I think db2ldif and then importing the LDIF can be very<br>
effective in restoring the DNS, HBAC, SUDO entries. You may just need to<br>
extract those from the LDIF and then ldapadd it to your server so that you do<br>
not overwrite other critical settings.<br>
<br>
As I wrote below, certificates or Kerberos keys cannot be that easily migrated<br>
and you would need to rebuild the keytabs when the services are created<br>
(ipa-getkeytab).<br>
<br>
I do not have any other specific scripts or examples at hand, maybe other users<br>
here has something.<br>
<br>
Martin<br>
<br>
><br>
><br>
> On Tue, May 26, 2015, 7:42 AM Martin Kosek <<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a><br>
> <mailto:<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>>> wrote:<br>
><br>
> On 05/25/2015 05:46 PM, Sina Owolabi wrote:<br>
> > Hi!<br>
> ><br>
> > Please how do I restore data to a freshly reinstalled IPA server from<br>
> > an existing CA-less replica that has had replication agreements<br>
> > removed?<br>
><br>
> By restore, you mean actually migrate? We have a pending RFE for this:<br>
> <a href="https://fedorahosted.org/freeipa/ticket/3656" target="_blank">https://fedorahosted.org/freeipa/ticket/3656</a><br>
><br>
> Migration of users/groups can be done via migrate-ds command. Migration of<br>
> SUDO/HBAC/automount/... can be done by LDIF export and import (with some<br>
> changes realms, etc.). But we have no automated way how to migrate Kerberos<br>
> keys or certificates as the underlying keys are different.<br>
><br>
> > Both servers are running rhel 6.6 with ipa-server versions 3.0.0<br>
> > ( For some reason the IPA servers do not upgrade beyond this version).<br>
><br>
> If you want a higher version than FreeIPA 3.0.0, please use RHEL-7.x. RHEL-7.1<br>
> has FreeIPA 4.1, which is much more cooler than 3.0.0 :-) This is what we<br>
> recommend for new deployments anyway.<br>
><br>
> > I have been searching for information from RHEL knowledgebase and from<br>
> > the FreeIPA site but I do not find information that exactly matches my<br>
> > situation.<br>
> ><br>
> > I am grateful for any assistance in this.<br>
> ><br>
> ><br>
> > Thanks!<br>
> ><br>
><br>
> HTH,<br>
> Martin<br>
><br>
<br>
</blockquote></div>