[Freeipa] [Bug 1773843] Re: cannot upgrade freeipa-server

2019-01-28 Thread gianluca
I think I do not have this problem anymore. There are still problems in upgrading from pre-releases to 4.7.1 (see #1800631), but probably for different reasons. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1800631] Re: ipa-server-upgrade fail

2019-01-28 Thread gianluca
I had a very similar problem (with bionic). I was able to upgrade to FreeIPA 4.3.1 by installing version 3.36.1 of the package libnss3, from the cosmic repositories. There is a bug in the version 3.35 distributed with bionic (see https://bugzilla.redhat.com/show_bug.cgi?id=1568271) which prevents

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-11-17 Thread gianluca
Package version 1:9.11.3+dfsg-1ubuntu1.3 in -proposed also works for me. ** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu.

[Freeipa] [Bug 1769440] Re: freeipa server install fails - named-pkcs11 fails to run

2018-10-06 Thread gianluca
A new bind has been pushed to bionic (1:9.11.3+dfsg-1ubuntu1.2). This is newer than bind9 in ppa:freeipa/ppa, but does not contain the fix for this bug. Therefore, bind9 upgrade should be prevented by helding the ppa package, or bind9-pkcs11 will stop working. -- You received this bug

[Freeipa] [Bug 1793994] Re: freeipa server upgrade fails trying to switch to authselect

2018-10-06 Thread gianluca
I confirm that this works for me, too. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1793994 Title: freeipa server upgrade fails trying to switch to authselect Status in freeipa package in

[Freeipa] [Bug 1778236] [NEW] missing GZIP path in freeipa platform configuration

2018-06-22 Thread gianluca
Public bug reported: The file "/usr/lib/python2.7/dist-packages/ipaplatform/debian/paths.py" is missing the line GZIP = "/bin/gzip" Without this definition, the default incorrect value of "/usr/bin/gzip" is used. Among the others, this is required by the "ipa-backup" command. ** Affects:

[Freeipa] [Bug 1773843] [NEW] cannot upgrade freeipa-server

2018-05-28 Thread gianluca
Public bug reported: I am trying to upgrade from freeipa 4.7.0~pre1 to 4.7.0~pre2-0~ppa3 of the staging repository. The install fails with the following error: RemoteRetrieveError: Failed to authenticate to CA REST API In the past, I also tried upgrading freeipa 4.7.0~pre1 to 4.7.0~pre2-0~ppa2

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-25 Thread gianluca
Actually, on a second attempt, ~ppa3 works fine. Wierd.. both my attempts were clean installations. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa server -- problems

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-25 Thread gianluca
No, I cannot retry ~ppa2 since it seems not to be available anymore and I deleted my previous installation my mistake. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772450 Title: freeipa

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
I confirm that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772921 Title: freeipa web ui -- incorrect configuration for awesome fonts Status in freeipa package in Ubuntu: In

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-23 Thread gianluca
I confirm that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772205 Title: freeipa install does not correctly setup krb5-admin-server Status in freeipa package in Ubuntu: In

[Freeipa] [Bug 1772447] Re: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-23 Thread gianluca
Confirming that it works! -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772447 Title: freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache Status in freeipa

[Freeipa] [Bug 1772921] Re: freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
I tried installing with 4.7.0.pre2, but I get an exception KeyError: 'FONT_AWESOME_DIR' I think you should add FONT_AWESOME_DIR=paths.FONT_AWESOME_DIR in the create_instance function in httpinstance.py -- You received this bug notification because you are a member of FreeIPA, which is

[Freeipa] [Bug 1772450] Re: freeipa server -- problems with certificates

2018-05-23 Thread gianluca
In my case, with dogtag 10.6.1-0ubuntu0.1, giving the "pki cert-find" command returns tons of warning of the kind WARN: RESTEASY002145: NoClassDefFoundError: Unable to load builtin provider org.jboss.resteasy.plugins.providers.InputStreamProvider from

[Freeipa] [Bug 1772921] [NEW] freeipa web ui -- incorrect configuration for awesome fonts

2018-05-23 Thread gianluca
Public bug reported: Hi, another bug for FreeIPA, but this is quite trivial and not very important either. The file /usr/share/ipa/ipa.conf.template containw the line Alias /ipa/ui/fonts/fontawesome "${FONTS_DIR}/fontawesome" for providing the Awesome font to web browsers. $FONTS_DIR si

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-23 Thread gianluca
I think the my trick (copy /usr/sbin/named into /usr/sbin/named-pkcs11) works quite well. Not sure about the differences between named and named-pkcs11, but I think it is essentially the fact that named-pkcs11 supports cryptographic devices while plain named doesn't. In order to avoid

[Freeipa] [Bug 1772450] [NEW] freeipa server -- problems with certificates

2018-05-21 Thread gianluca
Public bug reported: After having installed FreeIPA server on Ubuntu 18.04 and having sorted out all the other bugs, I still have problems with certificates. In the web interface, every attempt to select the "Authentication -> Certificates" tab ends with the following error IPA Error 4301:

[Freeipa] [Bug 1772447] [NEW] freeipa installation - directory /var/lib/krb5kdc is not accessible by Apache

2018-05-21 Thread gianluca
Public bug reported: After having installed FreeIPA on Ubuntu 18.04, I cannot login by the web interface. I think the problem is that Apache uses the certificate in /var/lib/krb5kdc/kdc.crt to get Kerberos credentials. Although this file is readable by everyone, the directory /var/lib/krb5kdc is

[Freeipa] [Bug 1769440] Re: freeipa server install fails - Configuring the web interface, setting up ssl

2018-05-21 Thread gianluca
For some reason, I have /usr/sbin/named in enforce mode by default (I am sure I did not change anything manually). Ubuntu 18.04 installed with an alternate CD on a KVM virtual machine. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in

[Freeipa] [Bug 1772411] [NEW] opendnssec-common has an invalid config file

2018-05-21 Thread gianluca
Public bug reported: The package opendnssec-common has a configuration file in /usr/share/opendnssec/conf.xml. This file get copied into /etc/opendnssec/conf.xml but, since it is invalid (due to nested comments, I think), the services opendnssec-signer and opendnssec- enforcer do not start, and

[Freeipa] [Bug 1772405] [NEW] freeipa dns install does not correctly configure reverse zones due to systemd-resolved

2018-05-21 Thread gianluca
Public bug reported: In Ubuntu 18.04, ipa-dns-intall (or ipa-server-install when asking to configure BIND) does not create reverse DNS zones for my domain. Note that I already fixed (or more correctly, circumvented) other bugs involving BIND, such as

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-21 Thread gianluca
I added your line just before the case statement in ipa-httpd-pwdreader, and it works. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1769485 Title: freeipa install server fails - cannot

[Freeipa] [Bug 1772205] Re: freeipa install does not correctly setup krb5-admin-server

2018-05-19 Thread gianluca
Changed affected package. ** Package changed: tomcat8 (Ubuntu) => freeipa (Ubuntu) -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1772205 Title: freeipa install does not correctly setup

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-19 Thread gianluca
I tried with the Alternate ISO. The problem still occurs, but now I can change the hostname to my fully qualified domain name with hostnamectl in a reliable way. Still, ipa-server-install should work with a simple hostname, since this is the standard for Ubuntu sysems. -- You received this bug

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-19 Thread gianluca
I realized now that "hostnamectl set-hostname" is not deterministic. Most of the times, the new hostname is lost after reboot, sometimes, without any apparent reason, it is preserved. The problem is that I installed Ubuntu 18.04 with the Live image, which has some peculiarities (see

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-19 Thread gianluca
I was able to permanently change the host name with "hosnamectl --set- hostname". Nonetheless, I still thinks there is a bug here, because the Ubuntu 18.04 installer only allows me to set a unqualified host name, while "ipa-server-install" insists on a FQDN, and the two do not matches. -- You

[Freeipa] [Bug 1769485] Re: freeipa install server fails - cannot start apache server with SSL

2018-05-18 Thread gianluca
I made some progress. The problem is that the script /usr/lib/ipa/ipa- httpd-pwdreader, which reads the passphrase of the SSL key on behalf of Apache, checks that the hostname passed by Apache has the same value of the $HOSTNAME environment variable. In my case, the two are different: Apache uses

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-05-05 Thread gianluca
Right... it was a race condition. Also, increasing the number of CPU and amount of memory in my virtual machine solved the problem. -- You received this bug notification because you are a member of FreeIPA, which is subscribed to freeipa in Ubuntu. https://bugs.launchpad.net/bugs/1765616 Title:

[Freeipa] [Bug 1765616] Re: freeipa server install fails - RuntimeError: CA configuration failed.

2018-05-05 Thread gianluca
ipa-server-install still fails for me during step "[24/28]: migrating certificate profiles to LDAP". It gives me the following error: NetworkError: cannot connect to 'https://ipa.labeconomnia.unich.it:8443/ca/rest/account/login': [Errno 111] Connection refused The problem is that, when this