Discussion:
[Freeipa-users] CentOS patch management on FreeIPA server
Lakshan Jayasekara
2017-05-17 05:23:19 UTC
Permalink
Hi All,

I'm using FreeIPA server VERSION: 4.4.0, API_VERSION: 2.213 and running on CentOS 7 and have one replica server as well. I need to patch up centos system as per PCI DSS compliance. Let me know whether I can proceed as usual or to follow any sequential steps to achieve the task.



Lakshanth Chandika Jayasekara
Lachlan Musicman
2017-05-17 06:04:00 UTC
Permalink
On 17 May 2017 at 15:23, Lakshan Jayasekara <
Post by Lakshan Jayasekara
Hi All,
I’m using FreeIPA server VERSION: 4.4.0, API_VERSION: 2.213 and running
on CentOS 7 and have one replica server as well. I need to patch up centos
system as per PCI DSS compliance. Let me know whether I can proceed as
usual or to follow any sequential steps to achieve the task.


Lakshanth,

You should always have appropriate backup and restore procedures that are
good for you.

Having said that, I regularly update our IPA server with patches (via
Katello/Foreman) without a problem.

I think I even "yum update"d from IPA 4.2 to 4.4 and it just worked.


cheers
L.


------
"Mission Statement: To provide hope and inspiration for collective action,
to build collective power, to achieve collective transformation, rooted in
grief and rage but pointed towards vision and dreams."

- Patrice Cullors, Black Lives Matter founder
Christophe TREFOIS
2017-05-17 17:55:08 UTC
Permalink
Hi,

I think yum update is fine, just don’t do it at the same time. It’s written somewhere in the docs that this could lead to crappy outcome.

Also, Lachlan, how do you do backups of FreeIPA?
--
Dr Christophe Trefois, Dipl.-Ing.
Technical Specialist / Post-Doc

UNIVERSITÉ DU LUXEMBOURG

LUXEMBOURG CENTRE FOR SYSTEMS BIOMEDICINE
Campus Belval | House of Biomedicine
6, avenue du Swing
L-4367 Belvaux
T: +352 46 66 44 6124
F: +352 46 66 44 6949
http://www.uni.lu/lcsb

[Facebook]<https://www.facebook.com/trefex> [Twitter] <https://twitter.com/Trefex> [Google Plus] <https://plus.google.com/+ChristopheTrefois/> [Linkedin] <https://www.linkedin.com/in/trefoischristophe> [skype] <http://skype:Trefex?call>

----
This message is confidential and may contain privileged information.
It is intended for the named recipient only.
If you receive it in error please notify me and permanently delete the original message and any copies.
----
Post by Lakshan Jayasekara
Hi All,
I’m using FreeIPA server VERSION: 4.4.0, API_VERSION: 2.213 and running on CentOS 7 and have one replica server as well. I need to patch up centos system as per PCI DSS compliance. Let me know whether I can proceed as usual or to follow any sequential steps to achieve the task.
Lakshanth,

You should always have appropriate backup and restore procedures that are good for you.

Having said that, I regularly update our IPA server with patches (via Katello/Foreman) without a problem.

I think I even "yum update"d from IPA 4.2 to 4.4 and it just worked.


cheers
L.


------
"Mission Statement: To provide hope and inspiration for collective action, to build collective power, to achieve collective transformation, rooted in grief and rage but pointed towards vision and dreams."

- Patrice Cullors, Black Lives Matter founder
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project
Lakshan Jayasekara
2017-05-18 03:58:09 UTC
Permalink
Hi Chris,

Thanks for the update. Pl let me know any sort of configuration backup can be taken for IPA server. Also let me know the sequence of updating the systems, as I have IPA servers and a replica server in my infrastructure.

These are virtual servers and backing up before updating.


Best Regards,

Reply / Forwarded by
Lakshanth Chandika Jayasekara
Senior Systems Engineer

Confidentiality Notice: The information contained in this message is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, or the employee or agent responsible to deliver it to the intended recipient, you are hereby notified that any release, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the author immediately by replying to this message and delete the original message. Internet communications cannot be guaranteed to be timely, secure, error or virus-free. The sender does not accept liability for any errors or omissions. This email has been scanned for all viruses by the Symantec End Point Protection Email Security System.
P Save a tree. Don't print this e-mail unless it's really necessary.

From: Christophe TREFOIS [mailto:***@uni.lu]
Sent: Wednesday, May 17, 2017 11:25 PM
To: Lachlan Musicman <***@gmail.com>
Cc: Lakshan Jayasekara <***@lankaclear.com>; freeipa-***@redhat.com
Subject: Re: [Freeipa-users] CentOS patch management on FreeIPA server

Hi,

I think yum update is fine, just don’t do it at the same time. It’s written somewhere in the docs that this could lead to crappy outcome.

Also, Lachlan, how do you do backups of FreeIPA?
--
Dr Christophe Trefois, Dipl.-Ing.
Technical Specialist / Post-Doc
UNIVERSITÉ DU LUXEMBOURG

LUXEMBOURG CENTRE FOR SYSTEMS BIOMEDICINE
Campus Belval | House of Biomedicine
6, avenue du Swing
L-4367 Belvaux
T: +352 46 66 44 6124
F: +352 46 66 44 6949
http://www.uni.lu/lcsb
[Facebook]<https://www.facebook.com/trefex> [Twitter] <https://twitter.com/Trefex> [Google Plus] <https://plus.google.com/+ChristopheTrefois/> [Linkedin] <https://www.linkedin.com/in/trefoischristophe> [skype] <http://skype:Trefex?call>
----
This message is confidential and may contain privileged information.
It is intended for the named recipient only.
If you receive it in error please notify me and permanently delete the original message and any copies.
----
Post by Lakshan Jayasekara
Hi All,
I’m using FreeIPA server VERSION: 4.4.0, API_VERSION: 2.213 and running on CentOS 7 and have one replica server as well. I need to patch up centos system as per PCI DSS compliance. Let me know whether I can proceed as usual or to follow any sequential steps to achieve the task.
Lakshanth,

You should always have appropriate backup and restore procedures that are good for you.
Having said that, I regularly update our IPA server with patches (via Katello/Foreman) without a problem.

I think I even "yum update"d from IPA 4.2 to 4.4 and it just worked.

cheers
L.


------
"Mission Statement: To provide hope and inspiration for collective action, to build collective power, to achieve collective transformation, rooted in grief and rage but pointed towards vision and dreams."

- Patrice Cullors, Black Lives Matter founder
--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project
Loading...