[Freeipa-users] Re: sssd suddenly throw system error on Mint 17.3 clients

2017-09-10 Thread Jakub Hrozek via FreeIPA-users

> On 10 Sep 2017, at 06:18, Jochen Hein via FreeIPA-users 
>  wrote:
> 
> Torsten Harenberg via FreeIPA-users
>  writes:
> 
>> Suddenly, our Linux Mint clients refrain from logging in users and
>> throw a system error. I increased the log level and the relevant lines
>> seem to be:
>> 
>> (Sun Sep 10 03:19:09 2017) [sssd[be[pleiades.uni-wuppertal.de]]] 
>> [hbac_eval_user_element] (0x0040): Parse error on [
>> cn=System: Manage Host
>> Principals+nsuniqueid=53120f31-41e811e7-b96dfa31-96759478,cn=permissions,cn=pbac,dc=pleiades,dc=uni-wuppertal,dc=de]:
>> Malformed cache entry
> 
> This looks like an entry created by a replication conflict. Do you use
> replicas? Then I'd check for replication conflicts:
> http://directory.fedoraproject.org/docs/389ds/design/managing-repl-conflict-entries.html
> 

Correct.

This should also not happen with a recent sssd version (where the replication 
conflicts would be just skipped, at worst you’d be denied access..)

> Jochen
> 
> -- 
> This space is intentionally left blank.
> ___
> FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
> To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
___
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org


[Freeipa-users] Re: sssd suddenly throw system error on Mint 17.3 clients

2017-09-09 Thread Jochen Hein via FreeIPA-users
Torsten Harenberg via FreeIPA-users
 writes:

> Suddenly, our Linux Mint clients refrain from logging in users and
> throw a system error. I increased the log level and the relevant lines
> seem to be:
>
> (Sun Sep 10 03:19:09 2017) [sssd[be[pleiades.uni-wuppertal.de]]] 
> [hbac_eval_user_element] (0x0040): Parse error on [
> cn=System: Manage Host
> Principals+nsuniqueid=53120f31-41e811e7-b96dfa31-96759478,cn=permissions,cn=pbac,dc=pleiades,dc=uni-wuppertal,dc=de]:
> Malformed cache entry

This looks like an entry created by a replication conflict. Do you use
replicas? Then I'd check for replication conflicts:
http://directory.fedoraproject.org/docs/389ds/design/managing-repl-conflict-entries.html

Jochen

-- 
This space is intentionally left blank.
___
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org