On 11/26/2015 02:39 PM, Petr Vobornik wrote:
On 11/23/2015 06:51 PM, Oleg Fayans wrote:
Hi all,

Here is a draft of the Replica Promotion test plan

== Test case: Unprivileged users are not allowed to enroll and promote
clients ==
User credentials are passed there through -p $principal and -w $password
options. It is correct atm because it is required for connection check.
But end goal of replica promotion is the avoid it. See
https://fedorahosted.org/freeipa/ticket/5497 and
https://fedorahosted.org/freeipa/ticket/5498 for more information.

== Missing test cases ==
1. ipa-replica-install works on CA-less master with with both domain levels
2. ipa-server-install works with --setup-dns option with both domain levels
3. ipa-server-install works with externally signed CA cert with both
domain levels
4. ipa-replica-install with options(and their combination): --setup-ca
--setup-dns --setup-kra works with both domain levels

Note: Not sure if #2 and #3 belongs here, but should be tested. Maybe
tests for domain level 0 already exist.

One more thing: test plans covers only the domain topology suffix(currently 'realm', will be renamed'[1]) and its segments. Segments for 'ca' topology suffix needs to be tested as well, or in other words that CA replication agreements are also managed. Maybe it fits more into: http://www.freeipa.org/page/V4/Manage_replication_topology/Test_plan

[1] https://www.redhat.com/archives/freeipa-devel/2015-November/msg00485.html
Petr Vobornik

Manage your subscription for the Freeipa-devel mailing list:
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code

Reply via email to