ipa-replica-manage and ipa-csreplica-manage in older versions (3.0 and older) do not recognize CA agreements in IPA master of version 3.1+ with single CA instance database.
ipa-replica-manage
ipa-csreplica-manage
Examples:
[root@vm-044 ~]# ipa-replica-manage force-sync --from vm-104.idm.lab.bos.redhat.com ipa: ERROR: Found multiple agreements for vm-044.idm.lab.bos.redhat.com ipa: ERROR: Using the first one only (cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config) ipa: INFO: Setting agreement cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch ipa: INFO: Deleting schedule 2358-2359 0 from agreement cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config [root@vm-044 ~]# ipa-replica-manage re-initialize --from vm-104.idm.lab.bos.redhat.com ipa: ERROR: Found multiple agreements for vm-044.idm.lab.bos.redhat.com ipa: ERROR: Using the first one only (cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config) ipa: INFO: Setting agreement cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config schedule to 2358-2359 0 to force synch ipa: INFO: Deleting schedule 2358-2359 0 from agreement cn=meTovm-044.idm.lab.bos.redhat.com,cn=replica,cn=dc\3Didm\2Cdc\3Dlab\2Cdc\3Dbos\2Cdc\3Dredhat\2Cdc\3Dcom,cn=mapping tree,cn=config [root@vm-044 ~]# ipa-replica-manage list vm-104.idm.lab.bos.redhat.com vm-044.idm.lab.bos.redhat.com: replica vm-055.idm.lab.bos.redhat.com: replica vm-044.idm.lab.bos.redhat.com: replica
We should fix at least IPA 2.2 and IPA 3.0 to be compatible with the new CA agreements and do not mix CA and IPA agreements together.
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=878491
attachment freeipa-mkosek-337-filter-suffix-in-replication-management-tools.patch
Patch freeipa-mkosek-337-filter-suffix-in-replication-management-tools.patch sent for review
ipa-2-2: 18b873c[[BR]] ipa-3-0: 83d2822
Metadata Update from @mkosek: - Issue assigned to mkosek - Issue set to the milestone: FreeIPA 3.0.2
Login to comment on this ticket.