ipa-replica-install --add-agents doesn't install trust-agent on replica
Replica installed is not showing the server role as: AD trust agent since the option was used. [root@master ~]# ipa server-show Server name: replica3.pytest.test Server name: replica3.pytest.test Managed suffixes: domain Min domain level: 0 Max domain level: 1 Enabled server roles: DNS server, NTP server
Replica server should be added as trust-agent sicne the option is used. Also need to check various other options specified in ipa-replica-install help AD trust options: --add-sids Add SIDs for existing users and groups as the final step --add-agents Add IPA masters to a list of hosts allowed to serve information about users from trusted forests --enable-compat Enable support for trusted domains for old clients --netbios-name=NETBIOS_NAME NetBIOS name of the IPA domain --rid-base=RID_BASE Start value for mapping UIDs and GIDs to RIDs --secondary-rid-base=SECONDARY_RID_BASE Start value of the secondary range for mapping UIDs and GIDs to RIDs
[root@master ~]# rpm -q ipa-server 389-ds-base ipa-server-trust-ad ipa-server-4.5.4-10.el7.x86_64 389-ds-base-1.3.7.5-16.el7.x86_64 ipa-server-trust-ad-4.5.4-10.el7.x86_64
Attached log
<img alt="ipareplica-install.log" src="/freeipa/issue/raw/files/85af6b9f8ec7b6425add8e41d1047eac4e5fd5b9f289cfa88b4dc7870109735a-ipareplica-install.log" />
<img alt="replica-trust-agent.txt" src="/freeipa/issue/raw/files/372b664600ad358ad8c4081d547e8ef2a811bd1fdeb91a778d35908ed516eff7-replica-trust-agent.txt" />
I think any of the trust-related options should an cause error if no --setup-adtrust was provided to ipa-replica-install. You weren't specified --setup-adtrust, so no trust setup install happened, thus no action on --add-agents.
--setup-adtrust
ipa-replica-install
--add-agents
Metadata Update from @stlaz: - Issue priority set to: normal - Issue set to the milestone: FreeIPA 4.8
Metadata Update from @abbra: - Issue assigned to abbra
PR: https://github.com/freeipa/freeipa/pull/1825
Metadata Update from @cheimes: - Issue set to the milestone: FreeIPA 4.7 (was: FreeIPA 4.8)
master:
Metadata Update from @cheimes: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Login to comment on this ticket.