#4545 [RFE] Create a tool to migrate machines from a direct integration setup to the indirect one
Opened by dpal. Modified

Use case: a deployment has been using a direct integration and decides to move to IPA with trusts. They deploy IPA, set trusts but now they have a bunch of clients that are currently connected directly to AD. How these clients can be switched?

IMO it consists of several steps:

a. Reading in a subset of the systems from AD and populating IPA with them generating OTPs at the same time.
b. Connecting to the clients via OpenLMI and issuing a command to leave one domain and join another.

Regardless of the solution it would require clients that support REALMD and OpenLMI. Older clients would have to be reconfigured using other tools like Puppet.


We also need to discuss how to handle POSIX vs. id-mapped Active Directory setups. These will be unique migration scenarios, since they will interact differently with the IPA trusts.

Updated the ticket description and summary to make clear it is different from https://fedorahosted.org/freeipa/ticket/4524 which talks about users' migration

To be considered within 4.2 cycle.

Processing 4.2 backlog. This ticket was found as something that is not a priority for the nearest releases.

But as usual, please feel free to discuss your use cases or contribute patches, to make that happen sooner!

Metadata Update from @dpal:
- Issue assigned to someone
- Issue set to the milestone: Future Releases

Metadata