[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Ricardo Mendes via FreeIPA-users
Ok so I don't know what happened the server really did take a long time to come up but it did. Everything looks pretty much the same. The setup-le.sh command I ran that said > The ipa-certupdate command was successful But I can't see it. I have to start ipa services with

[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Ricardo Mendes via FreeIPA-users
Hi Rob, Thanks a lot for your reply. > It's because you are in the middle of an upgrade. You can add > --skip-version-check to not do the upgrade until after the certs are renewed. Amazing! So I turned back the clock and: # ipactl restart --ignore-service-failure --skip-version-check Skipping

[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Rob Crittenden via FreeIPA-users
Ricardo Mendes via FreeIPA-users wrote: > Hi Florence, > > Thank you so much for your reply. > > I have some questions regarding your instructions. > > 1. ipactl start --ignore-service-failures doesn't work, it leaves most > services down and I must use systemctl to bring them up. > > # sudo

[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Ricardo Mendes via FreeIPA-users
Hi Florence, Thank you so much for your reply. I have some questions regarding your instructions. 1. ipactl start --ignore-service-failures doesn't work, it leaves most services down and I must use systemctl to bring them up. # sudo ipactl restart --ignore-service-failures IPA version error:

[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Florence Blanc-Renaud via FreeIPA-users
On 6/10/20 4:13 PM, Ricardo Mendes via FreeIPA-users wrote: # certutil -d /etc/pki/pki-tomcat/alias -L Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI ocspSigningCert cert-pki-ca

[Freeipa-users] Re: Last FreeIPA master is failing

2020-06-10 Thread Ricardo Mendes via FreeIPA-users
# certutil -d /etc/pki/pki-tomcat/alias -L Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI ocspSigningCert cert-pki-ca u,u,u subsystemCert cert-pki-ca

[Freeipa-users] Last FreeIPA master is failing

2020-06-10 Thread Ricardo Mendes via FreeIPA-users
Hi all, I'm having serious issues with our FreeIPA setup and I need some direction. Our FreeIPA setup had two master-replicas. Late last month one of the hypervisors at OVH died, they replaced hardware but the server is having issues so hasn't come up yet. So for all matters, one

[Freeipa-users] Re: pam_unix(sshd:auth): authentication failure

2020-06-10 Thread Sumit Bose via FreeIPA-users
On Tue, Jun 09, 2020 at 09:57:19PM +0200, lune voo via FreeIPA-users wrote: > I stopped sshd server and I started it again with the -d option to get more > information. > > Here is what appear as error : > ### > debug1: userauth-request for user myuser service ssh-connection method > password