[Freeipa-users] Using subdomains (or dots) in hostnames

2013-08-19 Thread Thomas Raehalme
Hi! We are in the process of deploying FreeIPA in our virtual environment. So far things are working smoothly and I am really impressed by the solution! One question has risen as we have added our first clients to the system. Because the total number of clients is 50 and going up, we have

[Freeipa-users] Replication woes

2013-08-19 Thread Bret Wortman
My replication situation has gotten a bit messed up. I have four replicas that are up and running and two that I'm trying to delete (one is not a replica any more, one didn't upgrade well during its fedup upgrade from F17-F18 and as such I had to do a clean OS install). # ipa-replica-manage list

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Rob Crittenden
Bret Wortman wrote: The software is actually gone from both boxes -- one is dead and the other was reinstalled when the upgrade failed. So I can't get at the database for either one. Safe to just --cleanup in that case? Assuming that none of the good servers have an agreement with bad* then

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Bret Wortman
Not according to my poll of the good ones, so here goes. Thanks, Rob. * * *Bret Wortman* http://damascusgrp.com/ http://about.me/wortmanbret On Mon, Aug 19, 2013 at 10:35 AM, Rob Crittenden rcrit...@redhat.comwrote: Bret Wortman wrote: The software is actually gone from both boxes -- one

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Rob Crittenden
Bret Wortman wrote: How can I tell if this is working? It's been 10 minutes and it hasn't returned; IPA response is sluggish and top doesn't show anything obviously running sucking up CPU. It should be nearly instantaneous. It doesn't actually do a lot. It deletes the master from cn=masters,

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Bret Wortman
Well, my master ground to a halt and wasn't responding. I rebooted the system and now I can't access the web UI or ssh to the master either. I have console access but that's it. The services all say they're running, but the web UI gives an Unknown Error dialog and ssh fails with

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Rob Crittenden
Bret Wortman wrote: Well, my master ground to a halt and wasn't responding. I rebooted the system and now I can't access the web UI or ssh to the master either. I have console access but that's it. The services all say they're running, but the web UI gives an Unknown Error dialog and ssh fails

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Rob Crittenden
Rob Crittenden wrote: Bret Wortman wrote: Well, my master ground to a halt and wasn't responding. I rebooted the system and now I can't access the web UI or ssh to the master either. I have console access but that's it. The services all say they're running, but the web UI gives an Unknown

Re: [Freeipa-users] Replication woes

2013-08-19 Thread Bret Wortman
Digging further, I think this log entry might be the problem between the two servers that aren't talking: slapd_ldap_sasl_interactive_bind - Error: could not perform interactive bind for id[] mech [GSSAPI]: LDAP error -2 (Local error) (SASL(-1): generic failure: GSSAPI Error: Unspecified GSS

[Freeipa-users] Fwd: Replication woes

2013-08-19 Thread Bret Wortman
On my master (where this error is occurring), I've got, in /etc/hosts: 127.0.0.1 localhost localhost.localdomain ::1 localhost localhost.localdomain 1.2.3.4ipamaster.foo.net ipamaster So that should be okay, right? # host ipamaster.foo.net ipamaster.foo.net has address 1.2.3.4 # host