[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-17 Thread lejeczek via FreeIPA-users
On 17/09/2021 13:35, pp via FreeIPA-users wrote: Could you check if your "requiredSecret" value matches the "secret" in "/etc/pki/pki-tomcat/server.xml"? I had two lines where they were different and the value has to match the secret in "/etc/httpd/conf.d/ipa-pki-proxy.conf". Once they all

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-17 Thread lejeczek via FreeIPA-users
On 17/09/2021 16:28, Rob Crittenden via FreeIPA-users wrote: Dirk Silkenbäumer via FreeIPA-users wrote: According to a different thread "tomcat pre-9.0.31.0 uses 'requiredSecret' and afterward uses 'secret'." https://tomcat.apache.org/migration-9.html#Tomcat_9.0.x_noteable_changes I am

[Freeipa-users] Re: IPA slapd parameter tuning

2021-09-17 Thread Kathy Zhu via FreeIPA-users
Thank you, Thierry! Thank you to explain. That makes sense. I will set nsslapd-db-deadlock-policy to 6 instead (it is 9 now). In this instance, I did notice that this ipa server's nsslapd-dncachememsize is 78MB, which is much less than 150MB. Shall I increase it? Or leave it as is? Kathy. On

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-17 Thread Rob Crittenden via FreeIPA-users
Dirk Silkenbäumer via FreeIPA-users wrote: >> According to a different thread "tomcat pre-9.0.31.0 uses 'requiredSecret' >> and afterward uses 'secret'." > https://tomcat.apache.org/migration-9.html#Tomcat_9.0.x_noteable_changes > >> I am running my FreeIPA server on CentOS 8 Stream which uses

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-17 Thread Dirk Silkenbäumer via FreeIPA-users
> According to a different thread "tomcat pre-9.0.31.0 uses 'requiredSecret' > and afterward uses 'secret'." https://tomcat.apache.org/migration-9.html#Tomcat_9.0.x_noteable_changes > I am running my FreeIPA server on CentOS 8 Stream which uses tomcat 9.0.30. > My uninformed > guess is the last

[Freeipa-users] Re: Unable to communicate with CMS (403)

2021-09-17 Thread pp via FreeIPA-users
Could you check if your "requiredSecret" value matches the "secret" in "/etc/pki/pki-tomcat/server.xml"? I had two lines where they were different and the value has to match the secret in "/etc/httpd/conf.d/ipa-pki-proxy.conf". Once they all matched I restarted pki-tomcatd@pki-tomcat.service

[Freeipa-users] Re: IPA slapd parameter tuning

2021-09-17 Thread Thierry Bordaz via FreeIPA-users
On 9/17/21 12:26 AM, Kathy Zhu via FreeIPA-users wrote: Hi Mark, If it helps, this is the same ipa server which I posted in subject "ipa_check_consistency alerts and ERR - slapd_poll - Timed out" yesterday. Hi Kathy, The slapd_poll message is likely not related to the DB_PANIC. Slap_poll