<div dir="ltr">I wanted to follow up on this as i finally gotten around to doing the upgrade. I an running into this error. I also found a bugzilla ticket. Do you have to do some type of schema upgrade like you do with active directory?<div><br></div><div><a href="https://bugzilla.redhat.com/show_bug.cgi?id=1235766">https://bugzilla.redhat.com/show_bug.cgi?id=1235766</a><br><div><br></div><div>
<p class=""><span class=""> STDERR: ipa : CRITICAL The master CA directory server does not have necessary schema. Please copy the following script to all CA masters and run it on them: /usr/share/ipa/copy-schema-to-ca.py</span></p>
<p class=""><span class=""> If you are certain that this is a false positive, use --skip-schema-check.</span></p>
<p class=""><span class=""> ipa.ipapython.install.cli.install_tool(Replica): ERROR IPA schema missing on master CA directory server</span></p><p class=""><span class=""><br></span></p><p class=""><span class=""><br></span></p><p class=""><span class="">Thank You</span></p><p class=""><span class=""><br></span></p><p class=""><span class=""><br></span></p></div></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Nov 20, 2015 at 11:13 AM, Martin Kosek <span dir="ltr"><<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 11/20/2015 04:08 PM, Ash Alam wrote:<br>
</span><span class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
Most of the clients in my env are centos 6.6 with ipa 3.0.0 client installed. I<br>
if bring up a replica on centos 7.2 with ipa 4.2.3 server and then start<br>
phasing out the older 3.0.0 servers. Will the client that are still running the<br>
older client software still work?<br>
</blockquote>
<br></span>
It should, yes. It is expected that there are RHEL/CentOS-6 clients with RHEL-7 FreeIPA servers. The older clients just won't be able to use the newest features.<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">
<br>
On Fri, Nov 20, 2015 at 4:31 AM, Martin Kosek <<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a><br></span><span class="">
<mailto:<a href="mailto:mkosek@redhat.com" target="_blank">mkosek@redhat.com</a>>> wrote:<br>
<br>
On 11/19/2015 11:03 PM, Ash Alam wrote:<br>
<br>
Hello All<br>
<br>
I am looking for some advice on upgrading. Currently our FreeIPA<br>
servers are<br>
3.0.0 on centos 6.6. We are looking to go to 4.2.3 Centos7. This<br>
upgrade path<br>
is not possible per IPA documentation. Minimum version required is 3.3.x. I<br>
have also found that cenos6 does not provide anything past 3.0.0.<br>
<br>
<br>
And it won't. There are no plans in updating FreeIPA version in<br>
RHEL/CentOS-6.x, we encourage people who want the new features to migrate<br>
to RHEL-7.x:<br>
<br>
<a href="http://www.freeipa.org/page/Howto/Migration#Migrating_Identity_Management_in_RHEL.2FCentOS" rel="noreferrer" target="_blank">http://www.freeipa.org/page/Howto/Migration#Migrating_Identity_Management_in_RHEL.2FCentOS</a><br>
<br>
<a href="https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc" rel="noreferrer" target="_blank">https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Linux_Domain_Identity_Authentication_and_Policy_Guide/upgrading.html#migrating-ipa-proc</a><br>
<br>
If you want to wait on CentOS-7.2, it should be in works now:<br>
<a href="http://seven.centos.org/2015/11/rhel-7-2-released-today/" rel="noreferrer" target="_blank">http://seven.centos.org/2015/11/rhel-7-2-released-today/</a><br>
<br>
One idea is to upgrade to 3.3.x first and then upgrade to 4.2.3 on centos7.<br>
This is harder since centos does not provide this. The other issue is if<br>
3.0/3.3 client will be supported with 4.2.3 server.<br>
<br>
<br>
The right way is to migrate via creating replicas in RHEL/CentOS-7.x and<br>
slowly deprecating RHEL/CentOS-6 ones. Detailed procedure in the links above.<br>
<br>
<br>
</span></blockquote>
<br>
</blockquote></div><br></div>