Project

General

Profile

Actions

tickets #130297

closed

Plan for migrating the primary freeipa to freeipa2

Added by hellcp about 1 year ago. Updated 7 months ago.

Status:
Rejected
Priority:
Normal
Assignee:
Category:
Core services and virtual infrastructure
Target version:
-
Start date:
2023-06-02
Due date:
% Done:

0%

Estimated time:

Description

We don't really want to rely on the old freeipa machine forever, so let's plan the migration path.

https://www.freeipa.org/page/Howto/Migration

Since this can go horribly wrong, it would be nice to have somebody who has more access as a backup in order to restore the functionality of the vpn.

Actions #1

Updated by crameleon about 1 year ago

  • Private changed from Yes to No

I know this is a bigger idea, but do we want to keep FreeIPA or use the opportunity to migrate to a different solution? After all, we barely use any of the features FreeIPA offers.

Actions #2

Updated by crameleon about 1 year ago

That being said, happy to be on stand-by for console access - just ping in IRC when you plan to start.

Actions #3

Updated by luc14n0 about 1 year ago

crameleon wrote:

I know this is a bigger idea, but do we want to keep FreeIPA or use the opportunity to migrate to a different solution? After all, we barely use any of the features FreeIPA offers.

I kind of feel the same here.

Actions #4

Updated by crameleon 8 months ago

What's the status of this? I notice freeipa.i.o.o runs Fedora 25 which is an operating system that reached it's End Of Life almost 5 years ago.

Actions #5

Updated by hellcp 8 months ago

I mean, I think we could do this any day, just a matter or making a commitment

Actions #6

Updated by crameleon 7 months ago

  • Status changed from New to Rejected

There didn't seem to be any commitment and nobody seems to be willing to administrate CentOS/Fedora.
We will probably switch to a Kanidm based solution based on openSUSE.

Actions #7

Updated by hellcp 7 months ago

That's kind of what I was eyeing as well, but I wanted to at least decommission the old Fedora system that was still around for something we can at the very least update, especially since we will have an easier time migrating to kanidm from newer freeipa

Actions

Also available in: Atom PDF