I think the culprit for me here is failing _ipa-dnskeysyncd_
Would you know guys why newly re-installed replica fail with:
...
File
"/usr/lib/python3.12/site-packages/ipaserver/dnssec/keysyncer.py",
line 192, in hsm_replica_sync
ipautil.run([paths.IPA_DNSKEYSYNCD_REPLICA])
File
"/usr/lib/python3.12/site-packages/ipapython/ipautil.py",
line 607, in run
raise CalledProcessError(
ipapython.ipautil.CalledProcessError:
CalledProcessError(Command
['/usr/libexec/ipa/ipa-dnskeysync-replica'] returned
non-zero exit status 1: 'ipa-dnskeysync-replica: INFO To
increase debugging set debug=True in dns.conf See
default.conf(5) for details\nTraceback (most recent call
last):\n File "/usr/libexec/ipa/ipa-dnskeysync-replica",
line 194, in <module>\n
ldap2replica_master_keys_sync(ldapkeydb, localhsm)\n File
"/usr/libexec/ipa/ipa-dnskeysync-replica", line 91, in
ldap2replica_master_keys_sync\n raise
ValueError(\nValueError: Local HSM does not contain suitable
unwrapping key for master key
0xf7880beb181502bc4f5185c3fcad420e\n')
... and
thanks, L.
--
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct:
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives:
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it:
https://forge.fedoraproject.org/infra/tickets/issues/new