From de8c6d81fd5d0f759ac0201e2c517bcb8b43d960 Mon Sep 17 00:00:00 2001 From: Martin Basti Date: Mar 16 2016 12:50:56 +0000 Subject: Fix broken trust warnings Warning should be shown only for parent entries of trust domain. Subdomains do not contain ipaNTSecurityIdentifier attribute at all. https://fedorahosted.org/freeipa/ticket/5737 Reviewed-By: Alexander Bokovoy --- diff --git a/ipalib/plugins/trust.py b/ipalib/plugins/trust.py index ba0c98e..7d815fd 100644 --- a/ipalib/plugins/trust.py +++ b/ipalib/plugins/trust.py @@ -597,7 +597,9 @@ class trust(LDAPObject): try: entries, truncated = ldap.find_entries( - base_dn=DN(self.container_dn, self.api.env.basedn), + base_dn=DN(self.api.env.container_adtrusts, + self.api.env.basedn), + scope=ldap.SCOPE_ONELEVEL, attrs_list=['cn'], filter='(&(ipaNTTrustPartner=*)' '(!(ipaNTSecurityIdentifier=*)))',