David Hanina via FreeIPA-users wrote:
> Hi Aram,
> 
> I think I did try to fix this some while ago: 
> https://github.com/freeipa/freeipa/pull/7803 to at least warn, when the user 
> is outside of idranges. There still seems to be the same bug with groups and 
> in some other cases related to users as well.
> 
> https://pagure.io/freeipa/issue/9795
> https://pagure.io/freeipa/issue/9796
> 
> I don't really recall the exact details, but I think when you use automatic 
> idranges it warns you if you run out of ids or straight up declines the 
> creation.
> 
> Not having the ipaNTSecurityIdentifier is very common bug, it's a bit 
> difficult to know exactly what went wrong without the exact commands 
> executed, but yes, if all is good it should be generated automatically, in 
> general a good rule of thumb is, to never touch idranges that are already in 
> use.
> 

David, they modified the DNA range which is both why your change didn't
catch this and the new users ended up without SIDs.

Changing the DNA range, as opposed to recovering lost ranges due to
server removal, plus directly modifying the ID range, is a risky move
and is not supported. The IPA API purposely prevents changing the main
IPA ID range.

rob

-- 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to