On 03/17/2015 04:27 PM, Benjamin Reed wrote:
> On 3/17/15 7:33 AM, Martin Kosek wrote:
>> # ipa config-mod --enable-migration=true
>> # echo Secret123 | ipa migrate-ds --bind-dn="cn=Directory Manager"
>> --user-container=cn=users,cn=accounts --group-container=cn=groups,cn=accounts
>> --group-objectclass=posixgroup
>> --user-ignore-attribute={krbPrincipalName,krbextradata,krblastfailedauth,krblastpwdchange,krblastsuccessfulauth,krbloginfailedcount,krbpasswordexpiration,krbticketflags,krbpwdpolicyreference}
>> --with-compat ldap://vm-086.rhel-6.test
> Confirmed, this works PERFECTLY.
> It'd be great to have it as a simple option in the migrate-ds script.
> Thanks so much for the help!  You saved me a lot of pain.  :)

Ah, good to hear!

I would still wished we fixed the original root cause why replication was
failing for you - as this is the obviously expected way of upgrading to
RHEL/CentOS 7.1 from RHEL-6 environment and I think/hope it would be less work
than starting over (depends on how populated is your existing IPA instance).


Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to