#4826 ID range should be immutable
Closed: Fixed Opened by pvoborni.

Ticket was cloned from Red Hat Bugzilla (product Fedora): Bug 1177706

Description of problem: On a fresh install of FreeIPA, if we do not set a ID
range during installation it will choose a randomly generated range. But after
the installation, if we want to change this under IPA Server --> ID Ranges -->
EXAMPLE.COM_id_range, the change is accepted but it appears that its not
getting honored.
Version-Release number of selected component (if applicable): 4.1.20
How reproducible: On a fresh FC21 install.
Steps to Reproduce:
1. Install the freeipa-server using yum on a FC21.
2. Setup IPA using ipa-server-install command. Do not specify an ID range.
3. Login to the webUI and note the ID range
5. Change the ID Range.
5. Create a user or a group.
Actual results:
1. User or group gets an ID from range noted in step #3 above.
Expected results:
1. User or group should have an ID from range defined in step #4 above.
Additional info:
For adding 1 or 2 users by hand this is just a inconvenience as the ID can be
changed after adding the user to whatever we want. But if I'm automating and
adding 100s of users/groups it becomes a hassle.

I've also tried:

  • create new ID range
  • migrate all users and groups into the new ID range
  • delete old ID range
  • create new user

New user got UID from the old ID range.

this behavior is expected since there is no connection between ID ranges and DNA plugin yet, see #3609.

We may warn user after modification of local range about this behavior: http://www.redhat.com/archives/freeipa-devel/2015-January/msg00013.html

As agreed, for short term we should make local ranges immutable (and document why).

During processing of remaining tickets in 4.2 Backlog, this ticket was found as suitable to be fixed in the nearest bugfixing branch - which is 4.2.x.

Fixed by the following commits:

  • master: 55feea500be1f4ae7bf02ef3c48377a6751ca71d
  • ipa-4-2: 5738cdb1145f6bce7f31a6d29bd39ceadbe62c8

Metadata Update from @pvoborni:
- Issue assigned to mbabinsk
- Issue set to the milestone: FreeIPA 4.2.1

master:

  • 83ed8d279210766d3d068a2a6daa0f8368c937e4 WebUI Tests: fixing test_hbac
  • dae5bac39bb2cbea1219b320d05d2171f5f86e63 WebUI Tests: fixing test_group
  • 3fa4378bc4f8b1d01c3f9844d605c174d0aa815f WebUI Tests: fixing test_navigation
  • 7c3f9b79eb42252b4540e26267e5aa229343f392 WebUI Tests: refactoring login method to be more readable
  • 49a17e98b0eb62636f4c4f0f43218a36fcea383d WebUI Tests: changing how the login screen is detected
  • 12da43c54fb927b48677fcca50f5110c5e659b1e WebUI Tests: fixing test_range test case
  • a072fe9718a4273aea0363667c728e6861c3f3b7 WebUI Tests: Changing how the initial load process is done
  • 81fb7e5a321e2f4fa0e4112bea073c30dbe9d54e WebUI Tests: fixing test_user.py::test_test_noprivate_posix
  • a5bd7bf7668092d9b329e640b656f23b8bf7bfe6 WebUI Tests: changing the ActionsChains.move_to_element to a new approach

ipa-4-6:

  • a4e7a20f3fa7ae94885faa878f32f3c9adbfda20 WebUI Tests: fixing test_hbac
  • c5e2deec4612cd0da872fbb80477b5d0cbaec2ad WebUI Tests: fixing test_group
  • 19fb8b9f0c2e4520c57c734ebfd49694fae2d278 WebUI Tests: fixing test_navigation
  • 9490884c4ca4f857bc252a3ef4ad563caf2a6eae WebUI Tests: refactoring login method to be more readable
  • 6865e6e67b560602b9972b1ad9e2710e211380f0 WebUI Tests: changing how the login screen is detected
  • 5fb9c4fa8bdcab9080e162905eb1d81d40d27209 WebUI Tests: fixing test_range test case
  • 8ce814d5c4298290a259b6ec52b5b8a69f87f84d WebUI Tests: Changing how the initial load process is done
  • d8ffd80c2c29d8dff0f7fb25c96d31bfbbcb3658 WebUI Tests: fixing test_user.py::test_test_noprivate_posix
  • d1eb7bcf6bdc6681dc67fae353a3d3bd2b6c62bf WebUI Tests: changing the ActionsChains.move_to_element to a new approach
Metadata