Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-26261

Fix replica connection check for use with AD administrator

    • Icon: Bug Bug
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.5
    • rhel-8.10, rhel-9.4
    • ipa
    • ipa-4.12.0-1.el9
    • None
    • None
    • 5
    • rhel-sst-idm-ipa
    • 15
    • 22
    • None
    • False
    • Hide

      None

      Show
      None
    • Yes
    • 2024-Q1-Alpha-S4, 2024-Q1-Alpha-S5, 2024-Q1-Alpha-S6, 2024-Q3-Alpha-S1, 2024-Q3-Alpha-S2
    • Bug Fix
    • Hide
      .AD administrators can now deploy IdM replicas

      Previously, during the installation of a RHEL Identity Management (IdM) replica, checking if the provided Kerberos principal had the required privilege did not extend to checking user ID overrides. Consequently, a replica connection check failed while trying to deploy a replica using the credentials of an AD administrator that had an ID override with the needed privilege.

      With this update, a check if there is an ID override for the principal that has the needed privileges has been added. As a result, you can now deploy a replica using the credentials of an AD administrator that is configured to act as an IdM administrator.

      Note that this fix also applies to `ansible-freeipa`.
      Show
      .AD administrators can now deploy IdM replicas Previously, during the installation of a RHEL Identity Management (IdM) replica, checking if the provided Kerberos principal had the required privilege did not extend to checking user ID overrides. Consequently, a replica connection check failed while trying to deploy a replica using the credentials of an AD administrator that had an ID override with the needed privilege. With this update, a check if there is an ID override for the principal that has the needed privileges has been added. As a result, you can now deploy a replica using the credentials of an AD administrator that is configured to act as an IdM administrator. Note that this fix also applies to `ansible-freeipa`.
    • Done
    • None

      The replica connection check is failing if for example the AD administrator Administrator@AD.EXAMPLE.COM is used for the deployment or promotion of a replica.

              twoerner Thomas Woerner
              twoerner Thomas Woerner
              Florence Renaud Florence Renaud
              Anuja More Anuja More
              Filip Hanzelka Filip Hanzelka
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated:
                Resolved: