This was found during investigation of a user's case. trust-add did not work because Samba service was not allowed to write to LDAP. The reason was the samba service was not added as a member attribute value of cn=adtrust agents.
member
cn=adtrust agents
ipa-adtrust-install should always try to add this attribute.
I can send a patch since I still have the fresh context.
attachment freeipa-mkosek-481-ipa-adtrust-install-does-not-re-add-member-in-adtrus.patch
Patch freeipa-mkosek-481-ipa-adtrust-install-does-not-re-add-member-in-adtrus.patch sent for review
master:
ipa-4-1:
ipa-4-0:
Metadata Update from @mkosek: - Issue assigned to mkosek - Issue set to the milestone: FreeIPA 4.0.2
Login to comment on this ticket.