On 17.06.2016 18:29, Günther J. Niederwimmer wrote:
Hello,

Am Freitag, 17. Juni 2016, 14:13:55 CEST schrieb Martin Basti:
On 17.06.2016 12:54, Günther J. Niederwimmer wrote:
Hello List,

Am Freitag, 17. Juni 2016, 07:51:45 CEST schrieb Petr Spacek:
On 16.6.2016 21:51, Lukas Slebodnik wrote:
On (16/06/16 11:54), Günther J. Niederwimmer wrote:
Hello

on my system the ods-exporter i mean have a problem.

I have this in the logs
CentOS 7.(2) ipa 4.3.1

Jun 16 11:38:28 ipa ipa-ods-exporter: raise errors.ACIError(info=info)
Jun 16 11:38:28 ipa ipa-ods-exporter: ipalib.errors.ACIError:
Insufficient
access: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS
failure.
Minor code may provide more information (Ticket expired)

                                            ^^^^^^^^^^^^^^
Here seems to be a reason why it failed.
                     But I can't help you more.
Lukas is right. Interesting, this should never happen :-)
this have I also found ;-)

Please enable debugging using procedure
http://www.freeipa.org/page/Troubleshooting#ipa_command_crashes_or_return
s_n o_data and check logs after next ipa-ods-exporter restart.
Thank you!
OK,

I attache the messages log?

I mean this is a problem with my DNS ?
Hello,
can you check kerberos status of ipa-ods-exporter service in webUI?

identity/services/ipa-ods-exported/<hostname>
There should be kerberos status in right top corner in details view

I have a
identity/services/ipa-ods-exporter/..

with a "Kerberos Key Present, Service Provisioned"

but no Certificate ?




Can you try,

# kinit -kt /etc/ipa/dnssec/ipa-ods-exporter.keytab ipa-ods-exporter/$(hostname)

and do ldapsearch
# ldapsearch -Y GSSAPI

It should show us if keytab is okay

Certificate is not needed.

--
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Reply via email to