#7600 Enable compat tree to provide information about AD users and groups on trust agents
Closed: fixed by frenaud. Opened by frenaud.

Ticket was cloned from Red Hat Bugzilla (product Red Hat Enterprise Linux 7): Bug 1585020

RHEL IdM has an option to enable serving information about AD users and groups
in the compatibility tree (RFC2307) when converting IdM master to AD trust
controller. At the same time, AD trust controller can designate other IdM
masters to be able to resolve information about AD users and groups by
promoting them to AD trust agents.
However, there is no way to configure the compatibility tree on AD trust agents
to serve information about AD users and groups. As result, if legacy clients
are configured to use the compatibility tree on AD trust agents as opposed to
AD trust controllers, information about AD users' group membership will be
missing.
We should provide means to enable this functionality in the compatibility tree
on AD trust agents independently from converting AD trust agent to AD trust
controller.

Metadata Update from @frenaud:
- Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=1585020

Metadata Update from @frenaud:
- Custom field on_review adjusted to https://github.com/freeipa/freeipa/pull/4277
- Issue set to the milestone: None (was: FreeIPA 4.6.5)

Metadata Update from @frenaud:
- Issue assigned to frenaud

master:

  • 68c72e344a29e27416af428f6dbf5300c85e66e1 Privilege: add a helper checking if a principal has a given privilege
  • 911992b8bf33b40f650ec406444ca8b9b847b54e ipa-adtrust-install: run remote configuration for new agents
  • fc4c3ac795e3af48fcfd8dd51085f5ff98047f1e ipatests: add test for ipa-adtrust-install --add-agents

ipa-4-8:

  • 66154f8bf79584b8fa6792e3d2ca534900dfa481 Privilege: add a helper checking if a principal has a given privilege
  • 5edc674e7262ce4506c40b8c066207f9e5f55c33 ipa-adtrust-install: run remote configuration for new agents
  • 4afd6e5e07061dde6e30b5352668bdf23cd6dedd ipatests: add test for ipa-adtrust-install --add-agents

ipa-4-7:

  • 2b5c409c3031696a358d57def4dc2e98142ef643 Privilege: add a helper checking if a principal has a given privilege
  • 3a880ff64d44156fa274ef13ea726fe78cd37f2e ipa-adtrust-install: run remote configuration for new agents
  • 59b09f154b9d85d937da64d6fe271d09c5b61bc1 ipatests: add test for ipa-adtrust-install --add-agents

ipa-4-6:

  • d051d2d47a36c79fd2c20733437fda95f443f053 Privilege: add a helper checking if a principal has a given privilege
  • f9fcd2c7fb7823becb3a6b68da4b0bf2c1db229f ipa-adtrust-install: run remote configuration for new agents
  • 796c86ac701d23d1dd281d0d5c5331b9a66c2888 ipatests: add test for ipa-adtrust-install --add-agents

master:

  • 233a18b2a24d814518a119bd3f1688a0eb361917 ipa-adtrust-install: remote command fails if ipa-server-trust-ad pkg missing
  • 1fbc4e01ea5be004f7c57cb71df2d37659271d68 selinux policy: add the right context for org.freeipa.server.trust-enable-agent

ipa-4-8:

  • 21c923c4cf21f30f20ec4b21c488db6f6fa92b67 ipa-adtrust-install: remote command fails if ipa-server-trust-ad pkg missing
  • df0df14bf31dba5800747aa08824b24b8be41eab selinux policy: add the right context for org.freeipa.server.trust-enable-agent

ipa-4-7:

  • 1fccdd00d53bc71e87ab5a4b1c68ab6e3efcce8c ipa-adtrust-install: remote command fails if ipa-server-trust-ad pkg missing

ipa-4-6:

  • 79f9ba5557d14e74ab29b85407c5de5622d7ea35 ipa-adtrust-install: remote command fails if ipa-server-trust-ad pkg missing

Metadata Update from @frenaud:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata