On 17.06.2016 18:29, Günther J. Niederwimmer wrote:

Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti:
On 17.06.2016 12:54, Günther J. Niederwimmer wrote:
Hello List,

Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek:
On 16.6.2016 21:51, Lukas Slebodnik wrote:
On (16/06/16 11:54), Günther J. Niederwimmer wrote:

on my system the ods-exporter i mean have a problem.

I have this in the logs
CentOS 7.(2) ipa 4.3.1

Jun 16 11:38:28 ipa ipa-ods-exporter: raise errors.ACIError(info=info)
Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError:
access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS
Minor code may provide more information (Ticket expired)

Here seems to be a reason why it failed.
                     But I can't help you more.
Lukas is right. Interesting, this should never happen :-)
this have I also found ;-)

Please enable debugging using procedure
s_n o_data and check logs after next ipa-ods-exporter restart.
Thank you!

I attache the messages log?

I mean this is a problem with my DNS ?
can you check kerberos status of ipa-ods-exporter service in webUI?

There should be kerberos status in right top corner in details view

I have a

with a "Kerberos Key Present, Service Provisioned"

but no Certificate ?

Can you try,

# kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab ipa-ods-exporter/$(hostname)

and do ldapsearch
# ldapsearch -Y GSSAPI

It should show us if keytab is okay

Certificate is not needed.

Manage your subscription for the Freeipa-users mailing list:
Go to http://freeipa.org for more info on the project

Reply via email to