Message info From:Dmitri Pal Subject:Re: [Freeipa-users] Problem in "ipa migrate-ds" procedure Date:Sun, 18 Mar 2012 12:49:35 -0400

On 03/17/2012 07:36 AM, Marco Pizzoli wrote:
Hi guys,
I'm trying to migrate my ldap user base to freeipa. I'm using the last Release Candidate.

I already changed "ipa config-mod --enable-migration=TRUE"
This is what I have:

ipa -v migrate-ds --bind-dn="cn=manager,dc=mydc1," --user-container="ou=people,dc=mydc1," --user-objectclass=inetOrgPerson --group-container="ou=groups,dc=mydc1," --group-objectclass=posixGroup --base-dn="dc=mydc1," --with-compat ldap://ldap01
ipa: INFO: trying
ipa: INFO: Forwarding 'migrate_ds' to server u''
ipa: ERROR: Container for group not found at ou=groups,dc=mydc1,

I looked at my ldap server logs and I found out that the search executed has scope=1. Actually both for users and groups. This is a problem for me, in having a lot of subtrees (ou) in which my users and groups are. Is there a way to manage this?

Thanks in advance

P.s. As a side note, I suppose there's a typo in the verbose message I obtain in my output:
ipa: INFO: Forwarding 'migrate_ds' to server u''

Please open tickets for both issues.

_______________________________________________ Freeipa-users mailing list

Thank you,
Dmitri Pal

Sr. Engineering Manager IPA project,
Red Hat Inc.

Looking to carve out IT costs?