> Finn Fysj via FreeIPA-users wrote:
> 
> UPGs cannot be migrated at all. There is no risk. Some find it annoying
> to see a bunch of single-user groups in the interface, that's all.
> 
> rob

Thank you, Rob.

I've seen that the UPGs that get migrated have received following attributes:

ipaNTSecurityIdentifier
ipantgroupattrs
groupofnames
nestedgroup
ipausergroup

If I really want to keep UPGs I can use ipa group-mod --delattr=...

I'll do some more checking, but you're correct: I don't think we'll have the 
need for Kerberos unless on the IPA servers themselves, but if it's considered 
good practice too ignore krb attributes I'll do.

I'll try to do some more testing. 
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to