OnWorks favicon

ipa-restore - Online in the Cloud

Run ipa-restore in OnWorks free hosting provider over Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator

This is the command ipa-restore that can be run in the OnWorks free hosting provider using one of our multiple free online workstations such as Ubuntu Online, Fedora Online, Windows online emulator or MAC OS online emulator



ipa-restore - Restore an IPA master


ipa-restore [OPTION]... BACKUP


Only the name of the backup needs to be passed in, not the full path. Backups are stored
in a subdirectory in /var/lib/ipa/backup. If a backup is in another location then the full
path must be provided.

The naming convention for full backups is ipa-full-YEAR-MM-DD-HH-MM-SS in the GMT time

The naming convention for data backups is ipa-data-YEAR-MM-DD-HH-MM-SS In the GMT time

The type of backup is automatically detected. A data restore can be done from either type.

WARNING: A full restore will restore files like /etc/passwd, /etc/group, /etc/resolv.conf
as well. Any file that IPA may have touched is backed up and restored.

An encrypted backup is also automatically detected and the root keyring is used by
default. The --keyring option can be used to define the full path to the private and
public keys.

Within the subdirectory is file, header, that describes the back up including the type,
system, date of backup, the version of IPA, the version of the backup and the services on
the master.

A backup can not be restored on another host.

A backup can not be restored in a different version of IPA.

Restoring from backup sets the server as the new data master. All other masters will need
to be re-initialized. The first step in restoring a backup is to disable replication on
all the other masters. This is to prevent the changelog from overwriting the data in the

Use the ipa-replica-manage and ipa-csreplica-manage commands to re-initialize other
masters. ipa-csreplica-manage only needs to be executed on masters that have a CA


The restoration on other masters needs to be done carefully, to match the replication
topology, working outward from the restored master. For example, if your topology is A <->
B <-> C and you restored master A you would restore B first, then C.

Replication is disabled on all masters that are available when a restoration is done. If a
master is down at the time of the restoration you will need to proceed with extreme
caution. If this master is brought back up after the restoration is complete it may send
out replication updates that apply the very changes you were trying to back out. The only
safe answer is to reinstall the master. This would involve deleting all replication
agreements to the master. This could have a cascading effect if the master is a hub to
other masters. They would need to be connected to other masters before removing the downed

If the restore point is from a period prior to a replication agreement then the master
will need to be re-installed. For example, you have masters A and B and you create a
backup. You then add master C from B. Then you restore from the backup. The restored data
is going to lose the replication agreement to C. The master on C will have a replication
agreement pointing to B, but B won't have the reverse agreement. Master C won't be
registered as an IPA master. It may be possible to manually correct these and re-connect C
to B but it would be very prone to error.

If re-initializing on an IPA master version prior to 3.2 then the replication agreements
will need to be manually re-enabled otherwise the re-initialization will never complete.
To manually enable an agreement use ldapsearch to find the agreement name in cn=mapping
tree,cn=config. The value of nsds5ReplicaEnabled needs to be on, and enabled on both
sides. Remember that CA replication is done through a separate agreement and will need to
be updated separately.

If you have older masters you should consider re-creating them rather than trying to
re-initialize them.


-p, --password=PASSWORD
The Directory Manager password.

--data Restore the data only. The default is to restore everything in the backup.

The full path to a GPG keyring. The keyring consists of two files, a public and a
private key (.sec and .pub respectively). Specify the path without an extension.

Exclude the IPA service log files in the backup (if they were backed up).

Perform the restore on-line. Requires data-only backup or the --data option.

Restore only the databases in this 389-ds instance. The default is to restore all
found (at most this is the IPA REALM instance and the PKI-IPA instance). Requires
data-only backup or the --data option.

The backend to restore within an instance or instances. Requires data-only backup
or the --data option.

--v, --verbose
Print debugging information

-d, --debug
Alias for --verbose

-q, --quiet
Output only errors

Log to the given file


0 if the command was successful

1 if an error occurred

Use ipa-restore online using onworks.net services

Free Servers & Workstations

Download Windows & Linux apps

  • 1
    SuiteCRM is the award-winning Customer
    Relationship Management (CRM)
    application brought to you by authors
    and maintainers, SalesAgility. It is the
    world�s mos...
    Download SuiteCRM
  • 2
    Poweradmin is a web-based DNS
    administration tool for PowerDNS server.
    The interface has full support for most
    of the features of PowerDNS. It has full
    Download Poweradmin
  • 3
    Gin Web Framework
    Gin Web Framework
    Gin is an incredibly fast web framework
    written in Golang that can perform up to
    40 times faster, thanks to its
    martini-like API and custom version of
    Download Gin Web Framework
  • 4
    CEREUS LINUX basado en MX LINUX con
    varios entornos de escritorios. This is
    an application that can also be fetched
    Download CEREUS LINUX
  • 5
    Task Coach
    Task Coach
    Task Coach - Your friendly task
    manager. Task Coach is a free open
    source todo manager. It grew out of
    frustration about other programs not
    handling composite ...
    Download Task Coach
  • 6
    HyperSQL Database Engine (HSQLDB)
    HyperSQL Database Engine (HSQLDB)
    HSQLDB is a relational database engine
    written in Java, with a JDBC driver,
    conforming to ANSI SQL:2016. A small,
    fast, multithreaded engine and server
    with mem...
    Download HyperSQL Database Engine (HSQLDB)
  • 7
    Project Recovery developed by Batik
    Recovery Teamwork from Indonesia, this
    Batik Recovery is a derivative of the
    Official TWRP that was modified by the
  • More »

Linux commands