[Freeipa-users] IPA server certificate update and "Directory Manager" password

Simo Sorce ssorce at redhat.com
Tue Feb 1 20:01:25 UTC 2011


On Tue, 1 Feb 2011 12:38:50 -0500
Peter Doherty <doherty at hkl.hms.harvard.edu> wrote:

> If I want to start from scratch with the new Beta release, how would
> I dump the entire LDAP/KRB database so that I could import it into a
> new server?
> The Docs mention doing regular backups, but they don't even tell how  
> to backup the data, whether to backups files (which ones?!) or to
> dump the data into a file, and backup that.

database dumps + filesystem backups

> Can I convert from the 1.9 alpha to a 2.0beta freeipa instance?

Not easy, and it depends on what you mean by convert.

A simple rpm update will give you issues because we still made minor
changes to the DIT and schema between the 1.9 alpha and the beta.

If you have many keys in your kerberos database I can describe a
procedure that *should* work to dump the keys and reload them in a new
server where you manually/script migrate the users/host/services data
by using the ipa user-add/host-add/srvice-add commands.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-users mailing list