[Freeipa-users] I have installed kerberos , How can I install FreeIPA

2021-07-01 Thread ighack asdf via FreeIPA-users
I have install kerberos , How can I installed FreeIPA ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org Fedora Code of Conduct:

[Freeipa-users] Re: pki-tomcatd fails to start with LDAP error authentication failed (48)

2021-07-01 Thread Floyd Lorch via FreeIPA-users
I had this same problem. After the most recent update I was getting Authentication Failed (48) in the tomcat debug log during the database upgrade. Rolling back 389-ds-base from 1.4.3.16-16 to 1.4.3.16-13 resolved that issue. Thank you. On Thu, Jul 1, 2021, 1:02 PM Rob Crittenden via

[Freeipa-users] Re: bug in ldap_entry_reconstruct()

2021-07-01 Thread Kees Bakker via FreeIPA-users
Hi Flo, No there are none. All three servers report: search: 2 result: 0 Success On 01-07-2021 21:01, Florence Renaud wrote: Hi Kees, can you also check if there are replication conflict entries? On each server: export BASEDN= ldapsearch -D "cn=Directory Manager" -W -b $BASEDN

[Freeipa-users] Re: bug in ldap_entry_reconstruct()

2021-07-01 Thread Florence Renaud via FreeIPA-users
Hi Kees, can you also check if there are replication conflict entries? On each server: export BASEDN= ldapsearch -D "cn=Directory Manager" -W -b $BASEDN "(&(objectClass=ldapSubEntry)(nsds5ReplConflict=*))" \* nsds5ReplConflict flo On Thu, Jul 1, 2021 at 2:35 PM Rob Crittenden via FreeIPA-users <

[Freeipa-users] Re: pki-tomcatd fails to start with LDAP error authentication failed (48)

2021-07-01 Thread Rob Crittenden via FreeIPA-users
Tiemen Ruiten via FreeIPA-users wrote: > Hello, > > On a newly installed CentOS 8 IPA master (a few days ago), the > pki-tomcatd@pki-tomcat service fails to start and logs LDAP > authentication failed (48) in > /var/log/pki/pki-tomcat/ca/debug.2021-07-01.log. See below. This > happened after I

[Freeipa-users] Re: FreeIPA Upgrade F31 -> F32: usr/lib/api/apiutil.c Could not open /run/lock/opencryptoki/LCK..APIlock

2021-07-01 Thread Rafael Jeffman via FreeIPA-users
On Thu, Jul 1, 2021 at 9:34 AM lejeczek via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > > > > On 12/05/2021 08:03, Florence Renaud via FreeIPA-users wrote: > > Hi, > > this is a known selinux-policy issue, tracked at > > https://bugzilla.redhat.com/show_bug.cgi?id=1894132 > >

[Freeipa-users] pki-tomcatd fails to start with LDAP error authentication failed (48)

2021-07-01 Thread Tiemen Ruiten via FreeIPA-users
Hello, On a newly installed CentOS 8 IPA master (a few days ago), the pki-tomcatd@pki-tomcat service fails to start and logs LDAP authentication failed (48) in /var/log/pki/pki-tomcat/ca/debug.2021-07-01.log. See below. This happened after I dnf upgraded the master and replica at the same time,

[Freeipa-users] Re: IPA client + AD Trust + ID Override inconsistent lookup results

2021-07-01 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 30, 2021 at 07:39:44PM - schrieb iulian roman via FreeIPA-users: > I do not use ldap_group_name in IPA. I'll describe bellow an example > for an override , because probably it all has to do with the > 'sAMAccountName' : > > Example of user and group in AD: > > user: testuser -

[Freeipa-users] Re: Network I/O error when trying to resolve AD users

2021-07-01 Thread Sumit Bose via FreeIPA-users
Am Wed, Jun 30, 2021 at 01:29:48PM +0200 schrieb Ronald Wimmer via FreeIPA-users: > On 30.06.21 13:26, Sumit Bose via FreeIPA-users wrote: > > Am Wed, Jun 30, 2021 at 12:13:54PM +0200 schrieb Ronald Wimmer via > > FreeIPA-users: > > > Today I set up an IPA test web application in our IPA test

[Freeipa-users] Re: bug in ldap_entry_reconstruct()

2021-07-01 Thread Rob Crittenden via FreeIPA-users
Kees Bakker via FreeIPA-users wrote: > Hey, > > In two of my three masters I see these error messages. > > Jul 01 09:38:38 linge.ghs.nl named-pkcs11[6945]: bug in > ldap_entry_reconstruct(): protocol violation: attempt to reconstruct > non-existing entry > Jul 01 09:38:38 linge.ghs.nl

[Freeipa-users] Re: FreeIPA Upgrade F31 -> F32: usr/lib/api/apiutil.c Could not open /run/lock/opencryptoki/LCK..APIlock

2021-07-01 Thread lejeczek via FreeIPA-users
On 12/05/2021 08:03, Florence Renaud via FreeIPA-users wrote: Hi, this is a known selinux-policy issue, tracked at https://bugzilla.redhat.com/show_bug.cgi?id=1894132 flo On Mon, May 10, 2021 at 9:42 PM Harry G. Coin via FreeIPA-users

[Freeipa-users] Re: centos8 freeipa not starting anymore

2021-07-01 Thread Jelle de Jong via FreeIPA-users
On 7/1/21 10:41 AM, Jelle de Jong via FreeIPA-users wrote: Hello everybody, All my centos8 freeipa instances at different sites where down this morning. https://pastebin.com/vVfwrNqL I tried disabling firewalld, selinux, downgrade java version, can not get it to work. Did anyone

[Freeipa-users] centos8 freeipa not starting anymore

2021-07-01 Thread Jelle de Jong via FreeIPA-users
Hello everybody, All my centos8 freeipa instances at different sites where down this morning. https://pastebin.com/vVfwrNqL I tried disabling firewalld, selinux, downgrade java version, can not get it to work. Did anyone encountered this issue and found a workaround? Kind regards, Jelle

[Freeipa-users] bug in ldap_entry_reconstruct()

2021-07-01 Thread Kees Bakker via FreeIPA-users
Hey, In two of my three masters I see these error messages. Jul 01 09:38:38 linge.ghs.nl named-pkcs11[6945]: bug in ldap_entry_reconstruct(): protocol violation: attempt to reconstruct non-existing entry Jul 01 09:38:38 linge.ghs.nl named-pkcs11[6945]: ldap_sync_search_entry failed: not