We¹re currently trying to set up an AD domain (great fun for a bunch of
linux adminsŠ not) so that we can get authentication working with various
bits of hardware that only support AD. We want this domain to trust our
existing FreeIPA setup.

When trying to ipa-adtrust-install I¹m getting:

  [10/22]: adding RID bases
ipa         : CRITICAL Found more than one local domain ID range with no RID
base set.

>From reading up, I need to have the id ranges configured with primary and
secondary RIDs. Is there any way to do this, or do I have to delete and
recreate the ranges? And if I do that, what are the implications?

IPA 4.2.0 (CentOS 7)
AD 2012R2



