Thanks for healthcheck Rob,
In our setup (2 CentOS 7.7 servers, running
ipa-server-4.6.5-11.el7.centos.3.x86_64) I get the output below when
ipa-healthcheck runs at the replica. The output is identical at master
too, except the first warning ("No DNA range defined. If no masters
define a range then users and groups cannot be created."). How serious
is my case?
Any recommendation is highly appreciated.
Thanks again,
Petros
[
{
"source": "ipahealthcheck.ipa.dna",
"kw": {
"msg": "No DNA range defined. If no masters define a range then
users and groups cannot be created.",
"range_start": 0,
"next_start": 0,
"next_max": 0,
"range_max": 0
},
"uuid": "f414f514-38b2-4381-a161-f43ea81ffbae",
"duration": "0.578066",
"when": "20191107160820Z",
"check": "IPADNARangeCheck",
"result": "WARNING"
},
{
"source": "ipahealthcheck.ipa.files",
"kw": {
"msg": "Permissions of /etc/dirsrv/slapd-GEO-SS-LAN/cert8.db are
0600 and should be 0640",
"key": "_etc_dirsrv_slapd-GEO-SS-LAN_cert8.db_mode",
"got": "0600",
"expected": "0640",
"path": "/etc/dirsrv/slapd-GEO-SS-LAN/cert8.db",
"type": "mode"
},
"uuid": "5a4a4d41-0761-403e-82f2-485bcfff5dd9",
"duration": "0.000125",
"when": "20191107160820Z",
"check": "IPAFileNSSDBCheck",
"result": "WARNING"
},
{
"source": "ipahealthcheck.ipa.files",
"kw": {
"msg": "Permissions of /etc/dirsrv/slapd-GEO-SS-LAN/key3.db are
0600 and should be 0640",
"key": "_etc_dirsrv_slapd-GEO-SS-LAN_key3.db_mode",
"got": "0600",
"expected": "0640",
"path": "/etc/dirsrv/slapd-GEO-SS-LAN/key3.db",
"type": "mode"
},
"uuid": "8fd976a9-d011-4e2b-a77d-792f50b1f1e4",
"duration": "0.000593",
"when": "20191107160820Z",
"check": "IPAFileNSSDBCheck",
"result": "WARNING"
},
{
"source": "ipahealthcheck.ipa.files",
"kw": {
"msg": "Permissions of /etc/dirsrv/slapd-GEO-SS-LAN/secmod.db are
0600 and should be 0640",
"key": "_etc_dirsrv_slapd-GEO-SS-LAN_secmod.db_mode",
"got": "0600",
"expected": "0640",
"path": "/etc/dirsrv/slapd-GEO-SS-LAN/secmod.db",
"type": "mode"
},
"uuid": "a0f8da6d-79ec-419d-9288-144a3a33cd97",
"duration": "0.000902",
"when": "20191107160820Z",
"check": "IPAFileNSSDBCheck",
"result": "WARNING"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=certmap,dc=geo,dc=ss,dc=lan",
"key":
"cn=certmap+nsuniqueid=ebb8b88e-a2c811e7-8f22c768-d7e7aa51,dc=geo,dc=ss,dc=lan"
},
"uuid": "b9e9c71d-c97c-43be-806f-b37bdc3607c3",
"duration": "0.005029",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict
cn=certmaprules,cn=certmap,dc=geo,dc=ss,dc=lan",
"key":
"cn=certmaprules+nsuniqueid=ebb8b8b7-a2c811e7-8f22c768-d7e7aa51,cn=certmap+nsuniqueid=ebb8b88e-a2c811e7-8f22c768-d7e7aa51,dc=geo,dc=ss,dc=lan"
},
"uuid": "2973a679-166c-48e1-b291-ed025b9ec727",
"duration": "0.005333",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=certificate identity mapping
administrators,cn=privileges,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=Certificate Identity Mapping
Administrators+nsuniqueid=ebb8b8b9-a2c811e7-8f22c768-d7e7aa51,cn=privileges,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "989214c0-b8bb-43fc-918a-8c752f62258c",
"duration": "0.005616",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: modify certmap
configuration,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Modify Certmap
Configuration+nsuniqueid=ebb8b8bf-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "b124c247-30ff-4f22-9b73-57001aa8ae8f",
"duration": "0.005921",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: read certmap
configuration,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Read Certmap
Configuration+nsuniqueid=ebb8b8c3-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "4f55e952-a32a-477d-a512-49651c63d4be",
"duration": "0.006249",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: add certmap
rules,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Add Certmap
Rules+nsuniqueid=ebb8b8c6-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "86e874d3-3dcd-455d-920f-37a64551ee9f",
"duration": "0.006553",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: delete certmap
rules,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Delete Certmap
Rules+nsuniqueid=ebb8b8ca-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "6d9c8d6d-639b-4d95-904e-9b50d0a38f4f",
"duration": "0.006855",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: modify certmap
rules,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Modify Certmap
Rules+nsuniqueid=ebb8b8ce-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "dfc6f379-e490-4745-a472-b090ce840498",
"duration": "0.007169",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: read certmap
rules,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Read Certmap
Rules+nsuniqueid=ebb8b8d2-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "a2c329f0-a3f1-4139-8f4b-2b3dcf9e65c0",
"duration": "0.007470",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: modify external group
membership,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Modify External Group
Membership+nsuniqueid=ebb8b8db-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "e2cc295f-7e21-424d-bdd6-b3150b1fab27",
"duration": "0.007771",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: read external group
membership,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Read External Group
Membership+nsuniqueid=ebb8b8e2-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "fd9600f0-aba2-41bf-8cca-f84ca75cc90e",
"duration": "0.008072",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
},
{
"source": "ipahealthcheck.ds.replication",
"kw": {
"msg": "Replication conflict",
"glue": false,
"conflict": "namingConflict cn=system: manage user certificate
mappings,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan",
"key": "cn=System: Manage User Certificate
Mappings+nsuniqueid=ebb8b8e9-a2c811e7-8f22c768-d7e7aa51,cn=permissions,cn=pbac,dc=geo,dc=ss,dc=lan"
},
"uuid": "8727dad3-da17-4cd6-94e0-eef33a9236da",
"duration": "0.008386",
"when": "20191107160829Z",
"check": "ReplicationConflictCheck",
"result": "ERROR"
}
]
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org