[Freeipa-users] Re: IPA slapd parameter tuning

2021-09-16 Thread Kathy Zhu via FreeIPA-users
Hi Mark, If it helps, this is the same ipa server which I posted in subject "ipa_check_consistency alerts and ERR - slapd_poll - Timed out" yesterday. Thanks. Kathy. On Thu, Sep 16, 2021 at 2:57 PM Kathy Zhu wrote: > Thanks, Mark, for your reply. > > The following repeats in

[Freeipa-users] Re: IPA slapd parameter tuning

2021-09-16 Thread Kathy Zhu via FreeIPA-users
Thanks, Mark, for your reply. The following repeats in /var/log/dirsrv/slapd-EXAMPLE-COM/errors: ... [16/Sep/2021:08:34:27.880349688 -0700] - CRIT - deadlock_threadmain - Serious Error---Failed in deadlock detect (aborted at 0x0), err=-30973 (BDB0087 DB_RUNRECOVERY: Fatal error, run database

[Freeipa-users] Re: IPA slapd parameter tuning

2021-09-16 Thread Mark Reynolds via FreeIPA-users
On 9/16/21 5:20 PM, Kathy Zhu via FreeIPA-users wrote: Hi List, One of my ipa server's database had issue and left many log entries like the following in messages and slapd errors log: *Sep 16 08*:34:28 ipa0 ns-slapd: [16/Sep/2021:08:34:28.886632992 -0700] - ERR - libdb - BDB0060 PANIC:

[Freeipa-users] IPA slapd parameter tuning

2021-09-16 Thread Kathy Zhu via FreeIPA-users
Hi List, One of my ipa server's database had issue and left many log entries like the following in messages and slapd errors log: *Sep 16 08*:34:28 ipa0 ns-slapd: [16/Sep/2021:08:34:28.886632992 -0700] - ERR - libdb - BDB0060 PANIC: fatal region error detected; run recovery *Sep 16 08*:34:29

[Freeipa-users] Re: CA errors after update, server.xml desync?

2021-09-16 Thread pp via FreeIPA-users
Thank you. Setting requiredSecret to the same value as secret in /etc/pki/pki-tomcat/server.xml fixed it for me on CentOS Stream 8. It stopped working after upgrading FreeIPA from 4.9.3 to 4.9.6. Seems I barely missed the version that uses "secret": java -cp catalina.jar

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-16 Thread Rob Crittenden via FreeIPA-users
lejeczek via FreeIPA-users wrote: > > > On 14/09/2021 20:00, Rob Crittenden wrote: >> lejeczek via FreeIPA-users wrote: >>> >>> On 14/09/2021 15:11, lejeczek via FreeIPA-users wrote: On 14/09/2021 14:13, Rob Crittenden wrote: > lejeczek via FreeIPA-users wrote: >> Hi guys.

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-16 Thread lejeczek via FreeIPA-users
On 14/09/2021 20:00, Rob Crittenden wrote: lejeczek via FreeIPA-users wrote: On 14/09/2021 15:11, lejeczek via FreeIPA-users wrote: On 14/09/2021 14:13, Rob Crittenden wrote: lejeczek via FreeIPA-users wrote: Hi guys. I get: -> $ ipa host-del c8kubernode1.private.lot ipa: ERROR:

[Freeipa-users] Re: Disabling ssh hostkey generation/caching

2021-09-16 Thread Dominik Vogt via FreeIPA-users
On Wed, Sep 15, 2021 at 10:57:55AM -0400, Rob Crittenden via FreeIPA-users wrote: > Dominik Vogt via FreeIPA-users wrote: > > However, host key files in rsa and ecdsa format keep reappearing. > > I'm not exactly sure when this happens. Does it have something to > > do with sssd? > > I believe

[Freeipa-users] Re: ipa-cert-fix failing

2021-09-16 Thread Florence Renaud via FreeIPA-users
Hi, what is the full output of *ipa-cert-fix -v* (verbose)? The command internally calls "*pki-server cert-fix*", and you will be able to find the exact arguments list provided in the logs. Retry the same "pki-server cert-fix" command with -v option and we will get more information about what is

[Freeipa-users] Re: [BUG?] Host Alias DNS

2021-09-16 Thread Florence Renaud via FreeIPA-users
Hi, re-adding the mailing list On Wed, Sep 15, 2021 at 6:31 PM Buckley Ross wrote: > Hi Flo, > > I think you misread my question. > Indeed. I interpreted "I found that on DNS records were provisioned..." as "I found that on DNS , records were provisioned" instead of "I found that *no* DNS