#8100 V4/Allow AD users to manage FreeIPA
Closed: fixed by abbra. Opened by oliver.

Request for enhancement

As admin user with an AD account, I want to be able to manage FreeIPA with my AD account, instead of some local IPA admin account only.
As also seen here:
https://www.freeipa.org/page/V4/Allow_AD_users_to_manage_FreeIPA#Use_Cases

Issue

I can already login with my AD account to FreeIPA WebUI to manage my eg. ssh keys, but I cannot actually manage FreeIPA (admin rights).

Steps to Reproduce

  1. Connect IPA to AD
  2. Test you can login with your AD user to WebUI
  3. Add your user to the admins group
  4. Try again 2) and see it didn't change anything.

Actual behaviour

AD user cannot manage FreeIPA.

Expected behavior

AD user with the right group assigned (admins) can also manage FreeIPA.

Version/Release/Distribution

Tested with 4.6.4

Additional info:

I stumbled across https://www.freeipa.org/page/V4/Allow_AD_users_to_manage_FreeIPA while searching for a way to do this (for my customer) and no ticket is assigned, so I guess that functionality is still not implemented and I took the opportunity to create this ticket.


This is implemented in RHEL 8 and CentOS 8.

Metadata Update from @abbra:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Hey @abbra.
Thanks for the information. Can this be reflected here:

https://www.freeipa.org/page/V4/Allow_AD_users_to_manage_FreeIPA

as well?

Metadata