On 3/17/15 7:33 AM, Martin Kosek wrote:
> # ipa config-mod --enable-migration=true
>
> # echo Secret123 | ipa migrate-ds --bind-dn="cn=Directory Manager"
> --user-container=cn=users,cn=accounts --group-container=cn=groups,cn=accounts
> --group-objectclass=posixgroup
> --user-ignore-attribute={krbPrincipalName,krbextradata,krblastfailedauth,krblastpwdchange,krblastsuccessfulauth,krbloginfailedcount,krbpasswordexpiration,krbticketflags,krbpwdpolicyreference}
> --with-compat ldap://vm-086.rhel-6.test

Confirmed, this works PERFECTLY.

It'd be great to have it as a simple option in the migrate-ds script.

Thanks so much for the help!  You saved me a lot of pain.  :)

-- 
Benjamin Reed
The OpenNMS Group
http://www.opennms.org/


Attachment: signature.asc
Description: OpenPGP digital signature

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to