Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-25 Thread Endi Sukma Dewata
Hi Michael, It took longer than expected, but I finally managed to create the build: https://edewata.fedorapeople.org/files/pki-common-9.0.3-39.el6_6.noarch.rpm Please install it and retry the operation. I have not tried this myself, but it should generate more useful information. Please

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-25 Thread Michael Pawlak
Endi, Due to time constraints, we turned up another IPA server, migrated all DNS and users and turned down this host. So, I think at this point installing the package would be moot. Thanks for your help anyways. *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com C:

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-24 Thread Michael Pawlak
Endi, Any word on the build? *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com C: 408.316.2154 http://www.colovore.com On Mon, Mar 23, 2015 at 2:55 PM, Michael Pawlak m...@colovore.com wrote: Endi, I could test that. *Michael Pawlak* Web Systems

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Rob Crittenden
Martin Kosek wrote: This may mean that Dogtag is not up. Can you please check with ipactl status that it (pki-ca) is up and running and that there are no related SELinux AVCs? The problem seems to be java-related: The self test plugin named selftests.container.logger.class contains a value

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Martin Kosek
This may mean that Dogtag is not up. Can you please check with ipactl status that it (pki-ca) is up and running and that there are no related SELinux AVCs? On 03/23/2015 04:52 AM, Michael Pawlak wrote: Does anybody have any thoughts on this? *Michael Pawlak* Web Systems Administrator |

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Michael Pawlak
Rob, Thanks. Any additional eyes would be greatly apprecated. *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com C: 408.316.2154 http://www.colovore.com On Mon, Mar 23, 2015 at 6:24 AM, Rob Crittenden rcrit...@redhat.com wrote: Martin Kosek wrote: This may mean

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Endi Sukma Dewata
On 3/23/2015 12:10 PM, Michael Pawlak wrote: Rob, Thanks. Any additional eyes would be greatly apprecated. *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com mailto:m...@colovore.com C: 408.316.2154 http://www.colovore.com On Mon, Mar 23, 2015 at 6:24 AM, Rob

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Michael Pawlak
Endi, I could test that. *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com C: 408.316.2154 http://www.colovore.com On Mon, Mar 23, 2015 at 1:36 PM, Endi Sukma Dewata edew...@redhat.com wrote: Thanks for the info. The transaction log doesn't indicate the cause of

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Endi Sukma Dewata
Thanks for the info. The transaction log doesn't indicate the cause of the problem either. I might need to provide a custom build that generates more useful information. Would you be able to test that? Thanks. -- Endi S. Dewata - Original Message - Endi, 1. I am currently using

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-23 Thread Michael Pawlak
Martin, The CA service definitely appears to be up and selinux is disabled on the host. - ipactl status - Directory Service: RUNNING KDC Service: RUNNING KPASSWD Service: RUNNING DNS Service: RUNNING MEMCACHE Service: RUNNING HTTP Service: RUNNING CA Service: RUNNING - service

[Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-22 Thread Michael Pawlak
I am not able to setup a replica using the 'ipa-replica-prepare' command. After some debugging this appears related to the certmonger/dogtag system that is incorporated with FreeIPA. I am including the output below of any relevant logs / commands. - ipa-replica-prepare -

Re: [Freeipa-users] Having Issues with Dogtag After Updating IPA and Rebooting

2015-03-22 Thread Michael Pawlak
Does anybody have any thoughts on this? *Michael Pawlak* Web Systems Administrator | Colovore LLC E: m...@colovore.com C: 408.316.2154 http://www.colovore.com On Sun, Mar 22, 2015 at 12:05 AM, Michael Pawlak m...@colovore.com wrote: I am not able to setup a replica using the