[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-15 Thread Stijn De Weirdt via FreeIPA-users
hi all, thanks to all for this thread. this is not for the faint of heart. i had similar issue with upgrade on el88 (ipa-server-4.9.11-7.module+el8.8.0+19639+24a8b95c.x86_64 -> ipa-server-4.9.11-9.module+el8.8.0+20825+52dd1628.x86_64; yes not even a subminor version change) my experience:

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-12 Thread Oliver Nixon via FreeIPA-users
Complete oversight by me sorry... There was a GID of a group set to 200. After changing that and running sidgen again all the users now have SIDs -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To unsubscribe send an email to

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-12 Thread Tomasz Torcz via FreeIPA-users
On Mon, Feb 12, 2024 at 10:53:33AM -, Oliver Nixon via FreeIPA-users wrote: > Hi Rob, > > Thanks for confirming. > > The strange thing is there aren't any users outside of the range that I can > find and there is definitely nothing with an ID of 200. It may be a GID of some group. --

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-12 Thread Marc Pearson | i-Neda Ltd via FreeIPA-users
Just to chime in on this. I'm not 100% this isn't a bug, as I've also hit the same issue after an update. In the end, I've had to re-create the effected accounts with the same UID and GID after deletion, which is resolving the issue for me as I wasn't able to find a solution using the

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-12 Thread Oliver Nixon via FreeIPA-users
Hi Rob, Thanks for confirming. The strange thing is there aren't any users outside of the range that I can find and there is definitely nothing with an ID of 200. -- ___ FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org To

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-08 Thread Rob Crittenden via FreeIPA-users
Oliver Nixon via FreeIPA-users wrote: > Hi Rob, > > Thanks for your reply. > > All I can find in the log is the following: > [08/Feb/2024:17:31:01.478681171 +] - ERR - sidgen_task_thread - [file > ipa_sidgen_task.c, line 194]: Sidgen task starts ... > [08/Feb/2024:17:31:01.667472180 +]

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-08 Thread Oliver Nixon via FreeIPA-users
Hi Rob, Thanks for your reply. All I can find in the log is the following: [08/Feb/2024:17:31:01.478681171 +] - ERR - sidgen_task_thread - [file ipa_sidgen_task.c, line 194]: Sidgen task starts ... [08/Feb/2024:17:31:01.667472180 +] - ERR - find_sid_for_ldap_entry - [file

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-08 Thread Oliver Nixon via FreeIPA-users
Hi, I'm encountering the same issue after upgrading to 4.9.12. I had previously imported users from another FreeIPA deployment and their UIDs were outside of the defined ID ranges. I've created a new ID range to encompass these and run the following but the SIDs still don't get generated: ]#

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-08 Thread Rob Crittenden via FreeIPA-users
Oliver Nixon via FreeIPA-users wrote: > Hi, > > I'm encountering the same issue after upgrading to 4.9.12. > I had previously imported users from another FreeIPA deployment and their > UIDs were outside of the defined ID ranges. > I've created a new ID range to encompass these and run the

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-02-08 Thread Oliver Nixon via FreeIPA-users
Hi, I'm encountering the same issue after upgrading to 4.9.12. I had previously imported users from another FreeIPA deployment and their UIDs were outside of the defined ID ranges. I've created a new ID range to encompass these and run the following but the SIDs still don't get generated: ]#

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-23 Thread Alexander Bokovoy via FreeIPA-users
On Аўт, 23 сту 2024, Dungan, Scott A. via FreeIPA-users wrote: I found the answer in this thread: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/5BUG3EVCRQKNF6BC74LA2CL3H2I2EV3P/ Following that, we used ldapmodify to apply the correct values for the

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-23 Thread Dungan, Scott A. via FreeIPA-users
I found the answer in this thread: https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org/thread/5BUG3EVCRQKNF6BC74LA2CL3H2I2EV3P/ Following that, we used ldapmodify to apply the correct values for the rid-base and secondary-rid-base in the new range. Afterwards,

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-23 Thread Dungan, Scott A. via FreeIPA-users
Thanks, Flo. I believe we now know what the correct values should be for the rid-base and secondary-rid-base, however, we can’t seem to modify the ID range with the missing values we created to cover the legacy NIS users: $ ipa idrange-mod ID.EXAMPLE.COM_legacy_range ipa: ERROR: This command

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-22 Thread Florence Blanc-Renaud via FreeIPA-users
Hi, On Tue, Jan 23, 2024 at 1:05 AM Dungan, Scott A. via FreeIPA-users < freeipa-users@lists.fedorahosted.org> wrote: > Thanks to Paul for all the leg work on this issue. Based on that, I can > confirm that we have the same problem after updating to 4.9.12-11 from > 4.9.11-7. Running the oddjob

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-22 Thread Dungan, Scott A. via FreeIPA-users
Thanks to Paul for all the leg work on this issue. Based on that, I can confirm that we have the same problem after updating to 4.9.12-11 from 4.9.11-7. Running the oddjob command to add SIDs to the user accounts fails after encountering UIDs outside of the default IPA range. It was able to get

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-18 Thread Rob Crittenden via FreeIPA-users
Paul Nickerson via FreeIPA-users wrote: > I confirmed that users who had an ipaNTSecurityIdentifier attribute could log > in to the web UI, and those that did not have the ipaNTSecurityIdentifier > attribute could not. > > I found the error in /var/log/dirsrv/slapd-SEMI-EXAMPLE-NET/errors like

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Paul Nickerson via FreeIPA-users
I confirmed that users who had an ipaNTSecurityIdentifier attribute could log in to the web UI, and those that did not have the ipaNTSecurityIdentifier attribute could not. I found the error in /var/log/dirsrv/slapd-SEMI-EXAMPLE-NET/errors like you said: [17/Jan/2024:20:28:09.571195828 +]

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Rob Crittenden via FreeIPA-users
Paul Nickerson via FreeIPA-users wrote: > Thank you for the assistance. I tried running the oddjob without specifying a > NetBIOS name, and it gave a return code of 1, no output, and didn't seem to > do anything. Then I saw your NetBIOS comment. > > First I checked to see if we already had a

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Paul Nickerson via FreeIPA-users
Thank you for the assistance. I tried running the oddjob without specifying a NetBIOS name, and it gave a return code of 1, no output, and didn't seem to do anything. Then I saw your NetBIOS comment. First I checked to see if we already had a NetBIOS name configured, and I didn't find anything

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-17 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 17 сту 2024, Alexander Bokovoy via FreeIPA-users wrote: On Срд, 17 сту 2024, Paul Nickerson via FreeIPA-users wrote: I have two FreeIPA servers in a cluster, both running on RHEL 8.9. They started on RHEL 8.0 I believe, and have been upgrading in-place since then. I recently restarted

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-16 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 17 сту 2024, Paul Nickerson via FreeIPA-users wrote: I have two FreeIPA servers in a cluster, both running on RHEL 8.9. They started on RHEL 8.0 I believe, and have been upgrading in-place since then. I recently restarted the FreeIPA services, which triggered an ipa-server-upgrade to

[Freeipa-users] Re: Upgrade to FreeIPA 4.9.12 on RHEL 8.9 caused web UI login and ipa command to stop working

2024-01-16 Thread Rob Crittenden via FreeIPA-users
Paul Nickerson via FreeIPA-users wrote: > I have two FreeIPA servers in a cluster, both running on RHEL 8.9. They > started on RHEL 8.0 I believe, and have been upgrading in-place since then. I > recently restarted the FreeIPA services, which triggered an > ipa-server-upgrade to upgrade from