On 11/26/2015 02:39 PM, Petr Vobornik wrote:
On 11/23/2015 06:51 PM, Oleg Fayans wrote:
Hi all,
Here is a draft of the Replica Promotion test plan
http://www.freeipa.org/page/V4/Replica_Promotion/Test_plan
== Test case: Unprivileged users are not allowed to enroll and promote
clients ==
User credentials are passed there through -p $principal and -w $password
options. It is correct atm because it is required for connection check.
But end goal of replica promotion is the avoid it. See
https://fedorahosted.org/freeipa/ticket/5497 and
https://fedorahosted.org/freeipa/ticket/5498 for more information.
== Missing test cases ==
1. ipa-replica-install works on CA-less master with with both domain levels
2. ipa-server-install works with --setup-dns option with both domain levels
3. ipa-server-install works with externally signed CA cert with both
domain levels
4. ipa-replica-install with options(and their combination): --setup-ca
--setup-dns --setup-kra works with both domain levels
Note: Not sure if #2 and #3 belongs here, but should be tested. Maybe
tests for domain level 0 already exist.
One more thing: test plans covers only the domain topology
suffix(currently 'realm', will be renamed'[1]) and its segments.
Segments for 'ca' topology suffix needs to be tested as well, or in
other words that CA replication agreements are also managed. Maybe it
fits more into:
http://www.freeipa.org/page/V4/Manage_replication_topology/Test_plan
[1]
https://www.redhat.com/archives/freeipa-devel/2015-November/msg00485.html
--
Petr Vobornik
--
Manage your subscription for the Freeipa-devel mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-devel
Contribute to FreeIPA: http://www.freeipa.org/page/Contribute/Code