Re: [Freeipa-users] lowest-privilege method of checking for out of sync FreeIPA masters?

2016-12-06 Thread List dedicated to discussions about use, configuration and deployment of the IPA server.
List dedicated to discussions about use, configuration and deployment of the IPA server. wrote: > Hello, > > There's a method to check the replication status of FreeIPA masters by > looking at objectClass=nsDS5ReplicationAgreement in the "cn=mapping > tree,cn=config" part of LDAP. > >

[Freeipa-users] lowest-privilege method of checking for out of sync FreeIPA masters?

2016-12-06 Thread List dedicated to discussions about use, configuration and deployment of the IPA server.
Hello, There's a method to check the replication status of FreeIPA masters by looking at objectClass=nsDS5ReplicationAgreement in the "cn=mapping tree,cn=config" part of LDAP. Unfortunately that requires Directory Admin level privileges. Is there a method to check those replication agreement