I was able to resolve but some services are down. ntpd Service: STOPPED and smb 
Service: STOPPED

Please help

# ipactl status
Directory Service: RUNNING
krb5kdc Service: RUNNING
kadmin Service: RUNNING
named Service: RUNNING
httpd Service: RUNNING
ipa-custodia Service: RUNNING
ntpd Service: STOPPED
pki-tomcatd Service: RUNNING
smb Service: STOPPED
winbind Service: RUNNING
ipa-otpd Service: RUNNING
ipa-dnskeysyncd Service: RUNNING
ipa: INFO: The ipactl command was successful

But NTP is installed

# systemctl restart ntpd
Failed to restart ntpd.service: Unit is masked.

# yum install ntp
Loaded plugins: versionlock
Package ntp-4.2.6p5-25.el7.centos.2.x86_64 already installed and latest version
Nothing to do


-----Original Message-----
From: Jochen Hein [mailto:joc...@jochen.org] 
Sent: September 15, 2017 1:26 PM
To: Gady Notrica via FreeIPA-users <freeipa-users@lists.fedorahosted.org>
Cc: Alexander Bokovoy <aboko...@redhat.com>; Rob Crittenden 
<rcrit...@redhat.com>; Gady Notrica <gnotr...@candeal.com>
Subject: Re: [Freeipa-users] Re: IPA Server down after system update

Gady Notrica via FreeIPA-users <freeipa-users@lists.fedorahosted.org>

> But still having the same issue:

No, you don't.  Earlier it timed out waiting for dirsrv, but now it's dogtag 
(Port 8080, 8443):
> 2017-09-15T15:58:46Z DEBUG stderr= 2017-09-15T15:58:46Z DEBUG
> wait_for_open_ports: localhost [8080, 8443] timeout 300 
> 2017-09-15T16:03:46Z ERROR IPA server upgrade failed: Inspect 
> /var/log/ipaupgrade.log and run command ipa-server-upgrade manually.

Have a look at the dogtag logs and possibly 

For me another replica refreshed the certificate while ipaupgrade was running.  
Another possibility was failure to refresh the cert due to selinux. (Can't find 
the ticket now).


This space is intentionally left blank.
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org

Reply via email to