Hi

A bit late I realise but I noticed ...

https://www.freeipa.org/page/Domain_Levels
(# ipa domainlevel-get)
IPA 4.5 is likely domain level 1. According to the ipa-replica-del man page:

<-- snip
To manage IPA replication agreements in a domain at domain level 1, use IPA CLI or Web UI, see `ipa help topology` for additional information.
<-- snip

When I decommissioned a site recently with 2 IPA servers, I followed this advice and ended up using this command from a remote  IPA server:

# ipa server-del <IPA_name_to_decom>

Which initially threw errors, giving very specific messages about how replication would fail due to missing topology agreements should the server removal carry on, allowing me to sort those agreements out separately. Once all the agreements were in place to support the removal of the server, the command removed all topology agreements related to this server and then deleted the server altogether.

In our environment, one of the the servers to be decomm'ed was the CA renewal server so I had to move that first - these are tasks I perform very rarely (once so far!) and have little knowledge of - all the tools worked really well, I went home on time and slept well!

Regards
Angus


From: Satish Patel via FreeIPA-users <freeipa-users@lists.fedorahosted.org>
Sent: 20 September 2019 02:51
To: FreeIPA users list <freeipa-users@lists.fedorahosted.org>
Cc: Dmitry Perets <dmitry.perets@gmail.com>; Satish Patel <satish.txt@gmail.com>
Subject: [Freeipa-users] Re: remove bad replica from list not working
 
You are awesome!!!

ipa topologysegment-del works!! and i am successfully able to remove bad replica

On Thu, Sep 19, 2019 at 6:08 PM Dmitry Perets via FreeIPA-users
<freeipa-users@lists.fedorahosted.org> wrote:
>
> Hi,
>
> Try using these, to delete replication agreements:
>
> ipa topologysegment-find
> ipa topologysegment-del
>
> Then you can repeat "ipa-replica-manage del".
>
> ---
> Regards,
> Dmitry Perets
> _______________________________________________
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
> Fedora Code of Conduct: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.fedoraproject.org%2Fen-US%2Fproject%2Fcode-of-conduct%2F&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572764530&amp;sdata=2YUtKQmQRWbWV1VqmeXI%2BJOWeH0CE47TvAVIUKA6iA8%3D&amp;reserved=0
> List Guidelines: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ffedoraproject.org%2Fwiki%2FMailing_list_guidelines&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572764530&amp;sdata=LdSnouDrzXBuQoxHZGmb%2BF8lpqekBbyz%2B%2F96f1RbJp0%3D&amp;reserved=0
> List Archives: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.fedorahosted.org%2Farchives%2Flist%2Ffreeipa-users%40lists.fedorahosted.org&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572764530&amp;sdata=NsD4oDjziW4J4WVA2Aj0FM8ewa7ewuiSj6RZqkJa3Io%3D&amp;reserved=0
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdocs.fedoraproject.org%2Fen-US%2Fproject%2Fcode-of-conduct%2F&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572774543&amp;sdata=8jgo%2BPzx9oGIlbj5R%2Bw9qnTn3knwg%2FIDFqoYzhqzyGw%3D&amp;reserved=0
List Guidelines: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ffedoraproject.org%2Fwiki%2FMailing_list_guidelines&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572774543&amp;sdata=bYspsbSYEYMunM3wKmN%2FanSkoST1p8xkCIQ4WGcunIo%3D&amp;reserved=0
List Archives: https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Flists.fedorahosted.org%2Farchives%2Flist%2Ffreeipa-users%40lists.fedorahosted.org&amp;data=02%7C01%7C%7C75dcabdc56244c481c0d08d73d64d455%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C637045375572774543&amp;sdata=h%2FMKtEnCUN4vTvdjRraYK7HLanOgczGlmpV1eb%2BbMR4%3D&amp;reserved=0