Yesterday I've upgraded F38-F49, all went fine, no issues. Today I tried F39-f40 and system freezes on autofs. Got some sssd errors, and i assume it might be all related (?). There are no errors from autofs side itself, only warning: "autofs.service: Referenced but unset environment variable evaluates to an empty string: OPTIONS" . As soon as I enable autofs, all system is frozen (although my nfs mounts are set to 'soft').
I am getting those errors, which I have reported here (https://github.com/SSSD/sssd/issues/7314) as I saw something similar being reported year ago: /var/log/sssd/krb5_child.log (2024-04-24 14:15:14): [krb5_child[13003]] [sss_krb5_expire_callback_func] (0x0020): [RID#97] Time to expire out of range. ********************** PREVIOUS MESSAGE WAS TRIGGERED BY THE FOLLOWING BACKTRACE: * (2024-04-24 14:15:14): [krb5_child[13003]] [main] (0x0400): [RID#97] krb5_child started. * (2024-04-24 14:15:14): [krb5_child[13003]] [unpack_buffer] (0x1000): [RID#97] total buffer size: [113] * (2024-04-24 14:15:14): [krb5_child[13003]] [unpack_buffer] (0x0100): [RID#97] cmd [241 (auth)] uid [1907400001] gid [1907400001] validate [true] enterprise principal [false] offline [false] UPN [[email protected]] * (2024-04-24 14:15:14): [krb5_child[13003]] [unpack_buffer] (0x0100): [RID#97] ccname: [KCM:] old_ccname: [KCM:] keytab: [/etc/krb5.keytab] * (2024-04-24 14:15:14): [krb5_child[13003]] [switch_creds] (0x0200): [RID#97] Switch [email protected] to [1907400001][1907400001]. * (2024-04-24 14:15:14): [krb5_child[13003]] [switch_creds] (0x0200): [RID#97] Switch [email protected] to [0][0]. * (2024-04-24 14:15:14): [krb5_child[13003]] [k5c_check_old_ccache] (0x4000): [RID#97] Ccache_file is [KCM:] and is active and TGT is valid. * (2024-04-24 14:15:14): [krb5_child[13003]] [k5c_setup_fast] (0x0100): [RID#97] Fast principal is set to [host/[email protected]] * (2024-04-24 14:15:14): [krb5_child[13003]] [find_principal_in_keytab] (0x4000): [RID#97] Trying to find principal host/[email protected] in keytab. * (2024-04-24 14:15:14): [krb5_child[13003]] [match_principal] (0x1000): [RID#97] Principal matched to the sample (host/[email protected]). * (2024-04-24 14:15:14): [krb5_child[13003]] [check_fast_ccache] (0x0200): [RID#97] FAST TGT is still valid. * (2024-04-24 14:15:14): [krb5_child[13003]] [[email protected]] (0x0200): [RID#97] Trying to become [email protected] [1907400001][1907400001]. * (2024-04-24 14:15:14): [krb5_child[13003]] [main] (0x2000): [RID#97] Running as [1907400001][1907400001]. * (2024-04-24 14:15:14): [krb5_child[13003]] [set_lifetime_options] (0x0100): [RID#97] No specific renewable lifetime requested. * (2024-04-24 14:15:14): [krb5_child[13003]] [set_lifetime_options] (0x0100): [RID#97] No specific lifetime requested. * (2024-04-24 14:15:14): [krb5_child[13003]] [set_canonicalize_option] (0x0100): [RID#97] Canonicalization is set to [true] * (2024-04-24 14:15:14): [krb5_child[13003]] [main] (0x0400): [RID#97] Will perform auth * (2024-04-24 14:15:14): [krb5_child[13003]] [main] (0x0400): [RID#97] Will perform online auth * (2024-04-24 14:15:14): [krb5_child[13003]] [tgt_req_child] (0x1000): [RID#97] Attempting to get a TGT * (2024-04-24 14:15:14): [krb5_child[13003]] [get_and_save_tgt] (0x0400): [RID#97] Attempting kinit for realm [DOMAIN.COM] * (2024-04-24 14:15:14): [krb5_child[13003]] [sss_krb5_responder] (0x4000): [RID#97] Got question [password]. * (2024-04-24 14:15:14): [krb5_child[13003]] [sss_krb5_expire_callback_func] (0x0020): [RID#97] Time to expire out of range. ********************** BACKTRACE DUMP ENDS HERE ********************************* (2024-04-24 14:15:14): [krb5_child[13003]] [sss_extract_pac] (0x0040): [RID#97] No PAC authdata available. ********************** PREVIOUS MESSAGE WAS TRIGGERED BY THE FOLLOWING BACKTRACE: * (2024-04-24 14:15:14): [krb5_child[13003]] [validate_tgt] (0x2000): [RID#97] Found keytab entry with the realm of the credential. * (2024-04-24 14:15:14): [krb5_child[13003]] [validate_tgt] (0x0400): [RID#97] TGT verified using key for [host/[email protected]]. * (2024-04-24 14:15:14): [krb5_child[13003]] [sss_extract_pac] (0x0040): [RID#97] No PAC authdata available. ********************** BACKTRACE DUMP ENDS HERE ********************************* (2024-04-24 14:15:14): [krb5_child[13003]] [validate_tgt] (0x0040): [RID#97] sss_extract_and_send_pac failed, group membership for [email protected] with principal [[email protected]] might not be correct. -- _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected] Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
