Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[ipa-4-4] Prevent denial of replication updates during CA replica install #283

Closed
wants to merge 2 commits into from

Conversation

martbab
Copy link
Contributor

@martbab martbab commented Nov 29, 2016

This is #269 rebased on top of ipa-4-4
branch.

https://fedorahosted.org/freeipa/ticket/6508

Martin Babinsky added 2 commits November 29, 2016 15:46
Without this attribute explicitly set the replication plugin won't recognize
updates from members of 'replication managers' sysaccount group, leading to
stuck replica CA installation.

https://fedorahosted.org/freeipa/ticket/6508
…nfig

This is a safeguard ensuring valid replica configuration against incorrectly
upgraded masters lacking 'nsds5replicabinddngroupcheckinterval' attribute on
their domain/ca topology config.

https://fedorahosted.org/freeipa/ticket/6508
@flo-renaud flo-renaud self-assigned this Nov 30, 2016
@flo-renaud flo-renaud added the ack Pull Request approved, can be merged label Nov 30, 2016
@flo-renaud
Copy link
Contributor

Hi,
the patch works as expected. Thanks!

@martbab martbab added the pushed Pull Request has already been pushed label Nov 30, 2016
@martbab martbab closed this Nov 30, 2016
@martbab martbab deleted the 4-4-ca-replica-upgrade-fix branch December 16, 2016 14:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ack Pull Request approved, can be merged pushed Pull Request has already been pushed
Projects
None yet
2 participants