<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 12px; font-family: Calibri, sans-serif;"><div>Hi,</div><div><br></div><div>We’re currently trying to set up an AD domain (great fun for a bunch of linux admins… not) so that we can get authentication working with various bits of hardware that only support AD. We want this domain to trust our existing FreeIPA setup.</div><div><br></div><div>When trying to ipa-adtrust-install I’m getting:</div><div><br></div><div><div> [10/22]: adding RID bases</div><div>ipa : CRITICAL Found more than one local domain ID range with no RID base set.</div></div><div><br></div><div>From reading up, I need to have the id ranges configured with primary and secondary RIDs. Is there any way to do this, or do I have to delete and recreate the ranges? And if I do that, what are the implications?</div><div><br></div><div>IPA 4.2.0 (CentOS 7)</div><div>AD 2012R2</div><div><br></div><div>Cheers,</div><div><br></div><div>Darren.</div><div><br></div></body></html>