I think the culprit for me here is failing _ipa-dnskeysyncd_
Would you know guys why newly re-installed replica fail with:
...
File "/usr/lib/python3.12/site-packages/ipaserver/dnssec/keysyncer.py", line 192, in hsm_replica_sync
    ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA])
File "/usr/lib/python3.12/site-packages/ipapython/ipautil.py", line 607, in run
    raise CalledProcessError(
ipapython.ipautil.CalledProcessError: CalledProcessError(Command ['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned non-zero exit status 1: 'ipa-dnskeysync-replica: INFO To increase debugging set debug=True in dns.conf See default.conf(5) for details\nTraceback (most recent call last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 194, in <module>\n ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File "/usr/libexec/ipa/ipa-dnskeysync-replica", line 91, in ldap2replica_master_keys_sync\n raise ValueError(\nValueError: Local HSM does not contain suitable unwrapping key for master key 0xf7880beb181502bc4f5185c3fcad420e\n')

... and
thanks, L.
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to