If sync'ing account disabled status both ways, and the entry has been disabled in AD, and you attempt to do another modify operation in AD, when the modify is synced to ipa, the ipa entry will be enabled. I believe this is due to faulty logic in sync_acct_disable() for the direction == ACCT_DISABLE_TO_DS modify case.
master: d43e87e
ipa-2-0: 1d42820
Metadata Update from @rmeggins: - Issue assigned to rcritten - Issue set to the milestone: FreeIPA 2.1 - 2011/07
Login to comment on this ticket.