Univention Bugzilla – Bug 35090
UCS in Active Directory domain - Wizard
Last modified: 2014-08-07 18:07:46 CEST
We need a wizard for the connector setup. See ucs-3.2/component/ucs-in-ad-domain/univention-ad-connector I think we should merge the current AD connector wizard / module with the new module. +++ This bug was initially created as a clone of Bug #34091 +++ It should be possible to run UCS as part of an Active Directory domain. In this case UCS must not provide Kerberos, DNS or Samba domain controller functionality. The synchronization of users, groups and computers will be done through the UCS AD connector. A password synchronization is not necessary, we will add an overlay module for OpenLDAP which uses the AD Kerberos as password verification backend for simple LDAP bind. The UCS system should able to provide Samba shares. Synchronized objects should be marked as synced (objectsuniventionObjectFlag: synced). In the default read mode of the connector it should not be possible to modify the synchronized attributes. The UDM modules property extension should be extended, for example "readonly_when_synced: True", default is False. Furthermore the object creation via UMC should display a warning that this object will not synchronized to AD.
We need a command line tool to start the wizard in a test setup like: test/ucs-ec2-tools$ ls examples/jenkins/utils/schoolinstaller.py
(In reply to Stefan Gohmann from comment #1) > We need a command line tool to start the wizard in a test setup like: > test/ucs-ec2-tools$ ls examples/jenkins/utils/schoolinstaller.py There is already such a tool: univention-ad-member See Bug #35091#c1, the configuration tool must allow the upload of the AD root certificate.
The wizard should uninstall univention-samba4 if it is installed.
Note: Wizard's "back" (why is this visible anyway?) and "abort" buttons do not work on the very first page.
Hmmmm... I accidently entered UCS' own IP. At first it worked... but then the join failed. "Verify that username/password are correct"
See changelog below. Open points are: * translations * incomplete JavaScript logic with wizard button handling * images on wizard pages * the radio button for the member mode should be pre-selected * the button for enabling/disabling the password service should be removed for the member mode case univention-ad-connector (8.0.17-59): Bug #35090: * Automatically add a host static entry in the connector configuration * Added translations [WIP] * Fixed jslint errors, removed unneeded parts
Another open point: * Piwik infos
All remaining open points should have been addressed now: univention-ad-connector (8.0.17-62): Bug #35090: * added piwik topic publishing * adjusted texts and added translations * pre-select AD member mode on start page * hide start/stop buttons for password service + fixed backend function * added missing images * enable 'cancel' button * fixed some internal page navigation logic * added hint to allow port for password sync on windows * added target="_blank" for UMCP based download links on IE * automatically advance in (connector config) wizard after uploading AD root certificate
Please add the server name to this sentence: Die MSI Dateien sind die Installationsdateien für den Passwort-Dienst und können per Doppelklick gestartet werden. For example: Die MSI Dateien sind die Installationsdateien für den Passwort-Dienst und können auf dem Server admaster per Doppelklick gestartet werden. Please also add a short note to the YAML file.
(In reply to Stefan Gohmann from comment #9) > Please add the server name to this sentence: > > Die MSI Dateien sind die Installationsdateien für den Passwort-Dienst und > können per Doppelklick gestartet werden. > > For example: > > Die MSI Dateien sind die Installationsdateien für den Passwort-Dienst und > können auf dem Server admaster per Doppelklick gestartet werden. > > Please also add a short note to the YAML file. FIXED. I submitted the following adaptation: "The MSI files are the installation files for the password service. The installation can be started on the Active Directory domain controller by double clicking on it." Package is building. univention-ad-connector (8.0.17-63): * Bug #35090: text adaptations
YAML file has been updated.
OK
http://errata.univention.de/ucs/3.2/162.html