-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi Dave,
There is no actual AD at this time. Thanks :) On 7/22/15 12:22 PM, Dave Sirrine wrote: > Bill, > > Can you let us know what version of FreeIPA you're using? The most > likely due to the occurrence of "NT_STATUS_INVALID_PARAMETER" which > is most likely a time skew issue between AD and IPA. Can you verify > this? Thanks! > > -- Dave > > ----- Original Message ----- >> From: "William Graboyes" <wgrabo...@cenic.org> To: >> "freeipa-users" <freeipa-users@redhat.com> Sent: Wednesday, July >> 22, 2015 2:14:51 PM Subject: [Freeipa-users] Samba Failing to >> start (Causing FreeIPA to not start!) >> > Hi All, > > I have been messing around with AD trust installs mainly around > doing ntlm_auth for a radius server. > > However, as I was unable to see some of the needed resources, I > thought maybe IPA may need a kick. > > So I ran the following command > > `ipactl restart` > > # ipactl restart Restarting Directory Service Restarting krb5kdc > Service Restarting kadmin Service Restarting ipa_memcached Service > Restarting httpd Service Restarting ipa-otpd Service Starting smb > Service Job for smb.service failed. See 'systemctl status > smb.service' and 'journalctl -xn' for details. Failed to start smb > Service Shutting down Aborting ipactl > > # systemctl status smb.service smb.service - Samba SMB Daemon > Loaded: loaded (/usr/lib/systemd/system/smb.service; disabled) > Active: failed (Result: exit-code) since Wed 2015-07-22 11:01:44 > PDT; 20s ago Process: 16752 ExecStart=/usr/sbin/smbd $SMBDOPTIONS > (code=exited, status=1/FAILURE) Main PID: 16752 (code=exited, > status=1/FAILURE) Status: "Starting process..." CGroup: > /system.slice/smb.service > > Jul 22 11:01:43 ipa-server-1.foo.bar systemd[1]: Starting Samba > SMB Daemon... Jul 22 11:01:43 ipa-server-1.foo.bar smbd[16751]: > [2015/07/22 11:01:43.956721, 0] > ../source3/smbd/server.c:1269(main) Jul 22 11:01:44 > ipa-server-1.foo.bar smbd[16752]: GSSAPI client step 1 Jul 22 > 11:01:44 ipa-server-1.foo.bar smbd[16752]: GSSAPI client step 1 Jul > 22 11:01:44 ipa-server-1.foo.bar smbd[16752]: GSSAPI client step 1 > Jul 22 11:01:44 ipa-server-1.foo.bar smbd[16752]: GSSAPI client > step 2 Jul 22 11:01:44 ipa-server-1.foo.bar systemd[1]: > smb.service: main process exited, code=exited, status=1/FAILURE Jul > 22 11:01:44 ipa-server-1.foo.bar systemd[1]: Failed to start Samba > SMB Daemon. Jul 22 11:01:44 ipa-server-1.foo.bar systemd[1]: Unit > smb.service entered failed state. > > journalctl -xn provides no useful information, however journalctl > does... sorta: > > Jul 22 11:03:19 ipa-server-1.foo.bar smbd[16903]: [2015/07/22 > 11:03:19.824614, 0] ipa_sam.c:3574(get_fallback_group_sid) Jul 22 > 11:03:19 ipa-server-1.foo.bar smbd[16903]: Missing mandatory > attribute ipaNTSecurityIdentifier. Jul 22 11:03:19 > ipa-server-1.foo.bar smbd[16903]: [2015/07/22 11:03:19.824829, 0] > ipa_sam.c:4526(pdb_init_ipasam) Jul 22 11:03:19 > ipa-server-1.foo.bar smbd[16903]: Cannot find SID of fallback > group. Jul 22 11:03:19 ipa-server-1.foo.bar smbd[16903]: > [2015/07/22 11:03:19.824878, 0] > ../source3/passdb/pdb_interface.c:178(make_pdb_method_name) Jul 22 > 11:03:19 ipa-server-1.foo.bar smbd[16903]: pdb backend > ipasam:ldapi://%2fvar%2frun%2fslapd-CENIC-ORG.socket did not > correctly init (error was NT_STATUS_INVALID_PARAMETER) Jul 22 > 11:03:19 ipa-server-1.foo.bar systemd[1]: smb.service: main process > exited, code=exited, status=1/FAILURE Jul 22 11:03:19 > ipa-server-1.foo.bar systemd[1]: Failed to start Samba SMB Daemon. > Jul 22 11:03:19 ipa-server-1.foo.bar systemd[1]: Unit smb.service > entered failed state. > > > Thanks, Bill > >> >> -- Manage your subscription for the Freeipa-users mailing list: >> https://www.redhat.com/mailman/listinfo/freeipa-users Go to >> http://freeipa.org for more info on the project >> -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2 Comment: GPGTools - https://gpgtools.org iQIcBAEBCgAGBQJVr/slAAoJEJFMz73A1+zr9i0P/ikhGkBsqX0zT6bqHjah7Gyy dvP2jd+WJeJxhH8jsLhUEGs26OcPdLVRc8MkvIeINcZd8dTz4l7gRVZZVk4dVho4 Tqg29EMbXh+5EOiOYd0LcFuZA1q0rFUaa9b56a3xnm9njwvKUwjnlRfUOMim3kKZ 6XfN1fAT7VVKqKJXyWn534ym/msivOuklbV5n0if0TAuIHe9X4Uwl8VvMiBsCtSv cpcpFEAZLygzW9qMxl9RgxYqPCN9gor8pW2ijO6BjJqfXTxQ0AxTCz+0C3mMizf7 lc4tdprS4hR1eWnrooBGahznm3usb4eRJvEAslHY7UUfsla9B4fgmJN4Nis8J7Mk CIRMZrFNI1YlVw8bfgxr3viq+lcVxFWAPghffmXfv1yu3Gx0OBa6bGD8fuNKVLU1 AoHZL6z0cHgGH6RsWjgC7APutssE6JqhWDTxa9cDcUozpN9R4fOH3H7uFAhJkSOU ZbslxHnmLOaLRXIDAyx9oAfp4ndYxMQH1mZ5scRHGkIZEv49mJtUOfgka67X/3xB bh78q/nxMibomteFZiWIXeCtxTOKaZ2wZLqPuhd/HS+689C9ONADsGcP8Tae/f35 nSBJEbZXzsrcWy3CN4iYtZ4dQK55FSBfW5GCyvnrBMO4MGsw48UzPOS1WiQ63NPd s0tJA1c/IO2kPzQzCaFM =KNGl -----END PGP SIGNATURE----- -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project