Hi Rob,

We have our system in migration mode. Due to the number and diversity of systems we have, we've found we really need to test everything extensively before we can cut over and make our IPA cluster our source of truth. Keeping a subset of systems on IPA during this time allows us to be comfortable switching at some future date, given that we know we've had no issues with each subset x of all systems y with t duration of production utilization.

Andy

On Wed, Feb 3, 2021 at 2:08 PM Rob Crittenden <rcritten@redhat.com> wrote:
Alfred Victor via FreeIPA-users wrote:
> Hi all,
>
> We have a need to set the password hash value directly, is this
> possible? It does not appear that ipa user-mod will support this, and
> using the API or other methods looks like it will be fraught with access
> control complications.

Why do you need to set the hash directly?

It is possible to do when adding a new user for migration purposes, but
after that it is generally not allowed.

rob