[Freeipa-users] Re: Migrated users have not attribute ipaNThash

2020-12-20 Thread Alexander Bokovoy via FreeIPA-users
On ma, 21 joulu 2020, Mikhail Kiselev via FreeIPA-users wrote: I'm not add range: Yes, you cannot because you are not following explanation in 'ipa help idrange' and what I suggested. You need to design it carefully. [root@ipa ~]# ipa idrange-add --base-id=1000 --range-size=1000

[Freeipa-users] Re: Migrated users have not attribute ipaNThash

2020-12-20 Thread Mikhail Kiselev via FreeIPA-users
I'm not add range: [root@ipa ~]# ipa idrange-add --base-id=1000 --range-size=1000 --rid-base=1000 --secondary-rid-base=100 magrated_range ipa: ERROR: Constraint violation: New base range overlaps with

[Freeipa-users] Re: Migrated users have not attribute ipaNThash

2020-12-18 Thread Alexander Bokovoy via FreeIPA-users
On pe, 18 joulu 2020, Kiselev Mikhail via FreeIPA-users wrote: Thanks, this is my case: "Running 'ipa-adtrust-install --add-sids' might still not produce SIDs for some users and groups because their UIDs/GIDs might be out of the ID range associated with IPA deployment. This is a common issue

[Freeipa-users] Re: Migrated users have not attribute ipaNThash

2020-12-18 Thread Kiselev Mikhail via FreeIPA-users
Thanks, this is my case: "Running 'ipa-adtrust-install --add-sids' might still not produce SIDs for some users and groups because their UIDs/GIDs might be out of the ID range associated with IPA deployment. This is a common issue for users migrated from a different LDAP server with 'ipa

[Freeipa-users] Re: Migrated users have not attribute ipaNThash

2020-12-18 Thread Alexander Bokovoy via FreeIPA-users
On pe, 18 joulu 2020, Kiselev Mikhail via FreeIPA-users wrote: Hello. My specs: cat /etc/system-release CentOS Linux release 7.8.2003 (Core) rpm -qa ipa-server ipa-server-4.6.6-11.el7.centos.x86_64 We migrated users from openLDAP. These users do not have a attribute ipaNThash: ldapsearch -h