- local install of IPA so you have a kerberos and LDAP infrastructure on your development machine
- install additional packages listed in freeipa.spec.in file in source repository
You also need to configure IPA for your local installation.
- When running the server in-tree the server will use ~/.ipa/ instead of /etc/ipa to look for configuration files. You need to create ~/.ipa/default.conf. You can probably copy this from /etc/ipa/default.conf and tune as needed. Mine looks like:
[global] domain=example.com realm=EXAMPLE.COM basedn=dc=example,dc=com server=puma.example.com enable_ra=True #xmlrpc_uri=https://lion.example.com/ipa/xml #in_tree=True
This BASH+SED snippet should prepare the configuration file for you:
mkdir -p ~/.ipa cat /etc/ipa/default.conf | sed 's/^xmlrpc_uri/#xmlrpc_uri/' > ~/.ipa/default.conf
- If you need to test DNS plugin, you should add the wait_for_dns=<timeout> option to the default.conf (IPA version >=4.0)
echo 'wait_for_dns=5' >> ~/.ipa/default.conf
- In order for the certificate tests to pass you'll also need to create ~/.ipa/alias. The easiest way to populate this is to grab the 3 NSS db files from /etc/httpd/alias and copy them ~/.ipa/alias. Copy /etc/httpd/alias/pwdfile.txt to ~/.ipa/alias/.pwd. Be sure to change ownership of these files too. That should do it.
mkdir -p ~/.ipa/alias cp /etc/httpd/alias/*.db ~/.ipa/alias cp /etc/httpd/alias/pwdfile.txt ~/.ipa/alias/.pwd chown -R $USER ~/.ipa/alias
- As the last step, you need to store password for Directory Managed to ~/.ipa/.dmpw file.
Build the testing utility:
You need to start with an admin ticket:
In one window start the lite server. I like to start it in debug mode.
In another window run the test script:
This command executes all the tests in ipatests folder.
You can also use this to run specific tests. Here is how you would test the user plugin:
Note that some of the tests make certain assumptions about the data on the server. Some tests, for example, pull all entries and expect a certain number to be returned and may raise an error.
This is super-useful for general development too. You can use the lite-server to quickly test plugins within the source tree. The only trick is to run the in-tree ipa command and not the system one, so:
./ipa user-show admin
It will detect that it is in the source tree and use local files and not the ones installed in /usr/lib.
You can also test against an IPA installation on another machine, it just requires a bit more configuration.
You first need to update ~/.ipa/default.conf to point to the remote machine. My test machine is lion.example.com, here is my configuration:
[global] domain=example.com realm=EXAMPLE.COM basedn=dc=example,dc=com server=lion.example.com enable_ra=True xmlrpc_uri=https://lion.lion.com/ipa/xml in_tree=True wait_for_attr=True
If you need to test DNS plugin, you should add the wait_for_dns=<timeout> option to the default.conf (IPA version >=4.0)
echo 'wait_for_dns=5' >> ~/.ipa/default.conf
Next, you need to configure yourself to be in the realm on your test machine. The easiest way to do this is to grab the remote krb5.conf and use that:
% scp lion.example.com:/etc/krb5.conf lion-krb5.conf % export KRB5_CONFIG=`pwd`/lion-krb5.conf % kinit admin
Finally you need to trust the CA on the remote machine. You need to be root to do this.
# wget -O /tmp/lion.crt http://lion.example.com/ipa/config/ca.crt # certutil -A -d /etc/pki/nssdb -n "lion IPA CA" -t CT,CT, -a -i /tmp/lion.crt
Now you should be good-to-go to run the XML-RPC tests against a remote server.
Web UI testing
To run the integration tests you need to have the freeipa-tests package installed:
# yum install freeipa-tests
All the files containing actual test implementations are located in the $PYTHON_SITELIB/ipatests/test_integration/ directory and start with a test_ prefix. As of FreeIPA 3.3, this is the current file listing:
$ ls ipatests/test_integration/test_*.py ipatests/test_integration/test_caless.py ipatests/test_integration/test_legacy_clients.py ipatests/test_integration/test_external_ca.py ipatests/test_integration/test_simple_replication.py ipatests/test_integration/test_forced_client_reenrollment.py ipatests/test_integration/test_topologies.py ipatests/test_integration/test_kerberos_flags.py ipatests/test_integration/test_trust.py
To properly configure the environment, see integration testing configuration page.
Particularly, the configuration of your environment used for the testing can be done in two ways:
To run the whole integration test suite, run the following:
To run only tests from a specific file, run the following:
$ ipa-run-tests test_integration/test_simple_replication.py
Please note that you need to specify a whole path relative to the python's site-packages/ipatests/ directory.