Hi,

you can follow the debugging guidelines from
https://www.freeipa.org/page/Active_Directory_trust_setup#Debugging_trust.
The *ipa trust-add* logs will be visible in /var/log/httpd/error_log and in
the /var/log/samba directory.

flo

On Wed, Mar 30, 2022 at 7:17 PM Jeremy Tourville via FreeIPA-users <
[email protected]> wrote:

> I think I got a little further in troubleshooting this after looking at
> /var/log/httpd/error_log
>
> I reviewed the Operations performed from an IdM trust controller towards
> AD domain controllers in table 6.7 from
> https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/planning_identity_management/planning-a-cross-forest-trust-between-idm-and-ad_planning-identity-management
>
>
> I can see the CLDAP  transaction and it seems like it is returning data.
> finddcs: performing CLDAP query on 192.168.105.15
> then a few lines down in the log I see a bunch of data such as forest
> name, domain name, server_site, client_site, pdc_name etc.
>
>  I *think* it might be stuck at the next step
>
> Operation
> Protocol              Purpose
> Requests to TCP/TCP6 ports 389 and 3268     LDAP                 To query
> AD user and group information
> on an AD DC
>
> Assuming this is correct.... how do you troubleshoot?
> _______________________________________________
> FreeIPA-users mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedorahosted.org/archives/list/[email protected]
> Do not reply to spam on the list, report it:
> https://pagure.io/fedora-infrastructure
>
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to