[Freeipa-users] Re: Major Server Failure

2018-05-09 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
SL7.5: 389-ds-base-snmp-1.3.6.1-28.el7_4.x86_64 389-ds-base-libs-1.3.6.1-28.el7_4.x86_64 389-ds-base-1.3.6.1-28.el7_4.x86_64 *Michael Rainey* Network Representative Naval Research Laboratory, Code 7320 Building 1009, Room C156 Stennis Space Center, MS 39529 On 05/09/2018 05:01 PM, Mark

[Freeipa-users] Re: Major Server Failure

2018-05-09 Thread Mark Reynolds via FreeIPA-users
On 05/09/2018 05:54 PM, Michael Rainey (Contractor, Code 7320) via FreeIPA-users wrote: > Along with the logs listed below, searching through the certificates > is not possible.  A message is returned: > >> Certificate operation cannot be completed: Unable to communicate with >> CMS (Internal

[Freeipa-users] Re: Major Server Failure

2018-05-09 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
Along with the logs listed below, searching through the certificates is not possible.  A message is returned: Certificate operation cannot be completed: Unable to communicate with CMS (Internal Server Error) Certmonger is running and pki-tomcatd is not.  "journalctl -u

[Freeipa-users] Re: CA install on replica fails - Clone URI does not match...

2018-05-09 Thread Ross Infinger via FreeIPA-users
There was no record in the CA list. I added one for the CA master with the ldapadd command. The ipa-ca-install command completed successfully this time! Thanks a million for your help! Thanks, Ross From: Fraser Tweedale [ftwee...@redhat.com] Sent:

[Freeipa-users] Re: attrlist_replace - attr_replace failed

2018-05-09 Thread Mark Reynolds via FreeIPA-users
On 05/09/2018 08:25 AM, Sandor Juhasz via FreeIPA-users wrote: > Hello, > > we have a 4 way master master replication. Which is finnaly > working, but we still see one error: > > [09/May/2018:14:21:27.882261986 +0200] attrlist_replace - attr_replace > (nsslapd-referral,

[Freeipa-users] Re: Major Server Failure

2018-05-09 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
Rob, A big thank you for showing me howto bringthe service back. You are correct the doesn't resolve the cause. I suspect I'm in a bit of certificate hades. The first sign of problems start with pki-tomcatd failing to start. Testing of the https: url says the connection is refused. I haven't

[Freeipa-users] Re: Major Server Failure

2018-05-09 Thread Rob Crittenden via FreeIPA-users
Michael Rainey (Contractor, Code 7320) via FreeIPA-users wrote: Greetings community, I'm having some major issues with my IPA servers and myself activating the bat signal seeking some help.  We recently upgraded this system to SL7.5 and ran the ipa-server-upgrade command.  During the upgrade

[Freeipa-users] Major Server Failure

2018-05-09 Thread Michael Rainey (Contractor, Code 7320) via FreeIPA-users
Greetings community, I'm having some major issues with my IPA servers and myself activating the bat signal seeking some help.  We recently upgraded this system to SL7.5 and ran the ipa-server-upgrade command.  During the upgrade the process failed and access to the LDAP service is nolonger

[Freeipa-users] Re: After using 3rd party certs (Let's Encrypt) : pki-tomcatd fails to restart

2018-05-09 Thread Joseph Flynn via FreeIPA-users
I restored the earlier image where it was working well with self-signed certs and just did the steps again. The pki-tomcatd restart was attempted at 10:47 local time and failed out several minutes later at 10:52. Your suggested debug steps reveal: root@prime prime.ipa.kkgpitt.org]#

[Freeipa-users] attrlist_replace - attr_replace failed

2018-05-09 Thread Sandor Juhasz via FreeIPA-users
Hello, we have a 4 way master master replication. Which is finnaly working, but we still see one error: [09/May/2018:14:21:27.882261986 +0200] attrlist_replace - attr_replace (nsslapd-referral, ldap://ipa34.bph.cxn:389/o%3Dipaca) failed. [09/May/2018:14:21:31.827746424 +0200] attrlist_replace -

[Freeipa-users] Re: DS server crashes regularly

2018-05-09 Thread Ludwig Krispenz via FreeIPA-users
On 05/09/2018 10:29 AM, Bart via FreeIPA-users wrote: As described in this issue: https://pagure.io/389-ds-base/issue/49660 I updated sssd and things started working again. thanks for confirmation ___ FreeIPA-users mailing list --

[Freeipa-users] Re: CA_UNREACHABLE during ipa-replica-install

2018-05-09 Thread Jan Gardian via FreeIPA-users
Hello, Were you able to find some useful information from provided pki logs? Thank you. On 05/04/2018 10:25 AM, Jan Gardian via FreeIPA-users wrote: Hello, I can see lot of warnings but for me most essentials are probably those: May 04 10:15:35 ipa2.example.com server[31620]: WARNING:

[Freeipa-users] Re: DS server crashes regularly

2018-05-09 Thread Bart via FreeIPA-users
As described in this issue: https://pagure.io/389-ds-base/issue/49660 I updated sssd and things started working again. ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: CA install on replica fails - Clone URI does not match...

2018-05-09 Thread Fraser Tweedale via FreeIPA-users
On Thu, May 03, 2018 at 02:25:34PM +, Ross Infinger wrote: > I assume the issue here is with the command... > https://pci-mgmt-ipa01.pci.xx.com:443/ca/admin/ca/getDomainXML > > Which returns... > domain info: standalone="no"?>IPA00 > > I notice that all the SubsystemCount values are