Re: [Freeipa-users] Partial replica

2015-09-21 Thread Tomas Babej


On 09/15/2015 05:14 PM, Nicola Canepa wrote:
> Hello list.
> I'm trying to make a test deploy of FreeIPA, and I was wondering if it
> is possible to authenticate remote sites via LDAP by havong a partial
> replica based on saome filter (maybe a group, an attribute or similar).
> 
> Sorry if this is a silly question, but I am trying to explore the
> possibilities that I could have to slowly replace local authentications
> spread in various sites by having a central store (backed by FreeIPA)
> and many partial replicas which would contain what now I have in RADIUS
> or other authentication sources.
> 
> Thank you for any advice or pointer you can give to me.
> 
> Nicola
> 

Hello!

Short answer is that FreeIPA does not support filter-based partial
replication.

AFAIK, 389 can do fractional replication, which can exclude certain
attributes from being replicated (and hence lower the replication
traffic), but I gather that will not help in your use case. See
nsds5replicatedattributelist and nsds5replicatedattributelisttotal
attributes of the replication agreement, if interested.

Tomas

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project


[Freeipa-users] Partial replica

2015-09-15 Thread Nicola Canepa

Hello list.
I'm trying to make a test deploy of FreeIPA, and I was wondering if it 
is possible to authenticate remote sites via LDAP by havong a partial 
replica based on saome filter (maybe a group, an attribute or similar).


Sorry if this is a silly question, but I am trying to explore the 
possibilities that I could have to slowly replace local authentications 
spread in various sites by having a central store (backed by FreeIPA) 
and many partial replicas which would contain what now I have in RADIUS 
or other authentication sources.


Thank you for any advice or pointer you can give to me.

Nicola

--

Nicola Canepa
canep...@mmfg.it
---
Il contenuto della presente comunicazione è riservato e destinato 
esclusivamente ai destinatari indicati. Nel caso in cui sia ricevuto da persona 
diversa dal destinatario sono proibite la diffusione, la distribuzione e la 
copia. Nel caso riceveste la presente per errore, Vi preghiamo di informarci e 
di distruggerlo e/o cancellarlo dal Vostro computer, senza utilizzare i dati 
contenuti. La presente comunicazione (comprensiva dei documenti allegati) non 
avrà valore di proposta contrattuale e/o accettazione di proposte provenienti 
dal destinatario, nè rinuncia o riconoscimento di diritti, debiti e/o crediti, 
nè sarà impegnativa, qualora non sia sottoscritto successivo accordo da chi può 
validamente obbligarci. Non deriverà alcuna responsabilità precontrattuale a 
ns. carico, se la presente non sia seguita da contratto sottoscritto dalle 
parti.

The content of the above communication is strictly confidential and reserved 
solely for the referred addressees. In the event of receipt by persons 
different from the addressee, copying, alteration and distribution are 
forbidden. If received by mistake we ask you to inform us and to destroy and/or 
delete from your computer without using the data herein contained. The present 
message (eventual annexes inclusive) shall not be considered a contractual 
proposal and/or acceptance of offer from the addressee, nor waiver recognizance 
of rights, debts  and/or credits, nor shall it be binding when not executed as 
a subsequent agreement by persons who could lawfully represent us. No 
pre-contractual liability shall apply to us when the present communication is 
not followed by any binding agreement between the parties.

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project