Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp



On 06/19/2015 11:12 AM, Christoph Kaminski wrote:


for this problem you can see the thread Haunted servers? here on ml. 
There is a solution from me for this but it doesnt work 100% :/


I would rather rerun the replication.

we have a Ticket @Red Hat for this problem, 
(https://access.redhat.com/support/cases/#/case/01429034if you have rh 
support)

But is really sad/silly how RH support works (read the whole ticket).


Unfortunately I don't have access there.


In fact we have a bigger issue here, but I don't know, if it's related.

The whole story is the following:

I migrated (ipa migrate-ds) about 150 users between two ldap databases. 
Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1).
After migrating users I switched off old servers and replaced centos 6.6 
machines with centos 7.1. Than replica servers was installed. One 
replicas had to be reinstalled one time, because the replica process was 
hanged up for some reason.
Now two servers (not the reinstalled one, but the original master and 
one other) crash quite frequently with sigsegv. It's like something is 
leaking.


I tuned the the nsslapd-cachememsize value of the following config entries:

dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config
dn: cn=config, cn=ldbm database, cn=plugins, cn=config
dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config

It helped a lot, but not enough.


I had seen this before years ago, when I started using ipa. It was on 
Fedora and the bleeding edge Freeipa version. At that time I switched to 
CentOS because I trusted more in the well tested enterprise distribution.

But now it's not an option:)


Any suggestion?



Thanks,
tamas
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Christoph Kaminski
 Unfortunately I don't have access there.
 
 
 In fact we have a bigger issue here, but I don't know, if it's related.
 
 The whole story is the following:
 
 I migrated (ipa migrate-ds) about 150 users between two ldap 
 databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 
7.1).
 After migrating users I switched off old servers and replaced centos
 6.6 machines with centos 7.1. Than replica servers was installed. 
 One replicas had to be reinstalled one time, because the replica 
 process was hanged up for some reason.
 Now two servers (not the reinstalled one, but the original master 
 and one other) crash quite frequently with sigsegv. It's like 
 something is leaking.
 
 I tuned the the nsslapd-cachememsize value of the following config 
entries:
 
 dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config
 dn: cn=config, cn=ldbm database, cn=plugins, cn=config
 dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config
 
 It helped a lot, but not enough.
 
 
 I had seen this before years ago, when I started using ipa. It was 
 on Fedora and the bleeding edge Freeipa version. At that time I 
 switched to CentOS because I trusted more in the well tested 
 enterprise distribution.
 But now it's not an option:)
 
 
 Any suggestion?
 
 

As I have mentioned above, see at the Haunted servers? thread here on 
list. There are solutions etc for a similiar problem. This is all there 
what I know about this problem.
(The RH Ticket has far less informations and not really a solution for it 
(sad :/ ))

Greetz

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread Tamas Papp



On 06/22/2015 10:31 AM, Christoph Kaminski wrote:

 Unfortunately I don't have access there.


 In fact we have a bigger issue here, but I don't know, if it's related.

 The whole story is the following:

 I migrated (ipa migrate-ds) about 150 users between two ldap
 databases. Old one was v3.0 (centos 6.6), the new one is v4.1 
(centos 7.1).

 After migrating users I switched off old servers and replaced centos
 6.6 machines with centos 7.1. Than replica servers was installed.
 One replicas had to be reinstalled one time, because the replica
 process was hanged up for some reason.
 Now two servers (not the reinstalled one, but the original master
 and one other) crash quite frequently with sigsegv. It's like
 something is leaking.

 I tuned the the nsslapd-cachememsize value of the following config 
entries:


 dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config
 dn: cn=config, cn=ldbm database, cn=plugins, cn=config
 dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config

 It helped a lot, but not enough.


 I had seen this before years ago, when I started using ipa. It was
 on Fedora and the bleeding edge Freeipa version. At that time I
 switched to CentOS because I trusted more in the well tested
 enterprise distribution.
 But now it's not an option:)


 Any suggestion?



As I have mentioned above, see at the Haunted servers? thread here 
on list. There are solutions etc for a similiar problem. This is all 
there what I know about this problem.
(The RH Ticket has far less informations and not really a solution for 
it (sad :/ ))


In my particular case I'm interested, whether it can crash servers.
Does it for you? I don't see it in that thread.

tamas
-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

Re: [Freeipa-users] Antwort: clean-run doesn't work

2015-06-22 Thread thierry bordaz

On 06/22/2015 10:22 AM, Tamas Papp wrote:



On 06/19/2015 11:12 AM, Christoph Kaminski wrote:


for this problem you can see the thread Haunted servers? here on 
ml. There is a solution from me for this but it doesnt work 100% :/


I would rather rerun the replication.

we have a Ticket @Red Hat for this problem, 
(https://access.redhat.com/support/cases/#/case/01429034if you have 
rh support)

But is really sad/silly how RH support works (read the whole ticket).


Unfortunately I don't have access there.


In fact we have a bigger issue here, but I don't know, if it's related.

The whole story is the following:

I migrated (ipa migrate-ds) about 150 users between two ldap 
databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 
7.1).
After migrating users I switched off old servers and replaced centos 
6.6 machines with centos 7.1. Than replica servers was installed. One 
replicas had to be reinstalled one time, because the replica process 
was hanged up for some reason.
Now two servers (not the reinstalled one, but the original master and 
one other) crash quite frequently with sigsegv. It's like something is 
leaking.


I tuned the the nsslapd-cachememsize value of the following config 
entries:


dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config
dn: cn=config, cn=ldbm database, cn=plugins, cn=config
dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config

It helped a lot, but not enough.


Hello Tamas,

You get some sigsegv and you may hit a real bug. Please try to capture a 
core (http://www.port389.org/docs/389ds/FAQ/faq.html#debugging-crashes) 
then you may attach a pstack of it.


thanks
thierry



I had seen this before years ago, when I started using ipa. It was on 
Fedora and the bleeding edge Freeipa version. At that time I switched 
to CentOS because I trusted more in the well tested enterprise 
distribution.

But now it's not an option:)


Any suggestion?



Thanks,
tamas




-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project

[Freeipa-users] Antwort: clean-run doesn't work

2015-06-19 Thread Christoph Kaminski
freeipa-users-boun...@redhat.com schrieb am 19.06.2015 11:02:48:

 Von: Tamas Papp tom...@martos.bme.hu
 An: freeipa-users@redhat.com
 Datum: 19.06.2015 11:04
 Betreff: [Freeipa-users] clean-run doesn't work
 Gesendet von: freeipa-users-boun...@redhat.com
 
 hi All,
 
 $ ipa-replica-manage list-ruv
 unable to decode: {replica 6} 55832e8e00030006 55832e8e00030006
 ipa31.bph.cxn:389: 8
 ipa12.bpo.cxn:389: 5
 ipa32.bph.cxn:389: 7
 ipa11.bpo.cxn:389: 3
 ipa.cxn.com:389: 4
 
 $ ipa-replica-manage clean-ruv 6
 unable to decode: {replica 6} 55832e8e00030006 55832e8e00030006
 Replica ID 6 not found
 
 
 
 Background: yesterday I deployed this ldap cluster and migrated users 
 to. Everything worked fine, except one time I had to recreate the 
 replication, because the process didn't finish successfully (due to a 
 closed firewall port). After the command 'ipa-server-install 
 --uninstall' it worked like a charm.
 But now I see the above on the replica master.
 
 
 in addition, I can see numerous and various errors on other replicas, 
eg:
 
 [19/Jun/2015:10:53:43 +0200] attrlist_replace - attr_replace 
 (nsslapd-referral, ldap://ipa.cxn.com:389/o%3Dipaca) failed.
 
 
 There is in the mailing list archives, that the solution is running 
 clean-run.
 
 
 
 Thanks,
 tamas
 

for this problem you can see the thread Haunted servers? here on ml. 
There is a solution from me for this but it doesnt work 100% :/

we have a Ticket @Red Hat for this problem, (
https://access.redhat.com/support/cases/#/case/01429034 if you have rh 
support)
But is really sad/silly how RH support works (read the whole ticket).

Greetz

-- 
Manage your subscription for the Freeipa-users mailing list:
https://www.redhat.com/mailman/listinfo/freeipa-users
Go to http://freeipa.org for more info on the project