Re: [Freeipa-users] Antwort: clean-run doesn't work
On 06/19/2015 11:12 AM, Christoph Kaminski wrote: for this problem you can see the thread Haunted servers? here on ml. There is a solution from me for this but it doesnt work 100% :/ I would rather rerun the replication. we have a Ticket @Red Hat for this problem, (https://access.redhat.com/support/cases/#/case/01429034if you have rh support) But is really sad/silly how RH support works (read the whole ticket). Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1). After migrating users I switched off old servers and replaced centos 6.6 machines with centos 7.1. Than replica servers was installed. One replicas had to be reinstalled one time, because the replica process was hanged up for some reason. Now two servers (not the reinstalled one, but the original master and one other) crash quite frequently with sigsegv. It's like something is leaking. I tuned the the nsslapd-cachememsize value of the following config entries: dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config dn: cn=config, cn=ldbm database, cn=plugins, cn=config dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config It helped a lot, but not enough. I had seen this before years ago, when I started using ipa. It was on Fedora and the bleeding edge Freeipa version. At that time I switched to CentOS because I trusted more in the well tested enterprise distribution. But now it's not an option:) Any suggestion? Thanks, tamas -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
Re: [Freeipa-users] Antwort: clean-run doesn't work
Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1). After migrating users I switched off old servers and replaced centos 6.6 machines with centos 7.1. Than replica servers was installed. One replicas had to be reinstalled one time, because the replica process was hanged up for some reason. Now two servers (not the reinstalled one, but the original master and one other) crash quite frequently with sigsegv. It's like something is leaking. I tuned the the nsslapd-cachememsize value of the following config entries: dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config dn: cn=config, cn=ldbm database, cn=plugins, cn=config dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config It helped a lot, but not enough. I had seen this before years ago, when I started using ipa. It was on Fedora and the bleeding edge Freeipa version. At that time I switched to CentOS because I trusted more in the well tested enterprise distribution. But now it's not an option:) Any suggestion? As I have mentioned above, see at the Haunted servers? thread here on list. There are solutions etc for a similiar problem. This is all there what I know about this problem. (The RH Ticket has far less informations and not really a solution for it (sad :/ )) Greetz -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
Re: [Freeipa-users] Antwort: clean-run doesn't work
On 06/22/2015 10:31 AM, Christoph Kaminski wrote: Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1). After migrating users I switched off old servers and replaced centos 6.6 machines with centos 7.1. Than replica servers was installed. One replicas had to be reinstalled one time, because the replica process was hanged up for some reason. Now two servers (not the reinstalled one, but the original master and one other) crash quite frequently with sigsegv. It's like something is leaking. I tuned the the nsslapd-cachememsize value of the following config entries: dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config dn: cn=config, cn=ldbm database, cn=plugins, cn=config dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config It helped a lot, but not enough. I had seen this before years ago, when I started using ipa. It was on Fedora and the bleeding edge Freeipa version. At that time I switched to CentOS because I trusted more in the well tested enterprise distribution. But now it's not an option:) Any suggestion? As I have mentioned above, see at the Haunted servers? thread here on list. There are solutions etc for a similiar problem. This is all there what I know about this problem. (The RH Ticket has far less informations and not really a solution for it (sad :/ )) In my particular case I'm interested, whether it can crash servers. Does it for you? I don't see it in that thread. tamas -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
Re: [Freeipa-users] Antwort: clean-run doesn't work
On 06/22/2015 10:22 AM, Tamas Papp wrote: On 06/19/2015 11:12 AM, Christoph Kaminski wrote: for this problem you can see the thread Haunted servers? here on ml. There is a solution from me for this but it doesnt work 100% :/ I would rather rerun the replication. we have a Ticket @Red Hat for this problem, (https://access.redhat.com/support/cases/#/case/01429034if you have rh support) But is really sad/silly how RH support works (read the whole ticket). Unfortunately I don't have access there. In fact we have a bigger issue here, but I don't know, if it's related. The whole story is the following: I migrated (ipa migrate-ds) about 150 users between two ldap databases. Old one was v3.0 (centos 6.6), the new one is v4.1 (centos 7.1). After migrating users I switched off old servers and replaced centos 6.6 machines with centos 7.1. Than replica servers was installed. One replicas had to be reinstalled one time, because the replica process was hanged up for some reason. Now two servers (not the reinstalled one, but the original master and one other) crash quite frequently with sigsegv. It's like something is leaking. I tuned the the nsslapd-cachememsize value of the following config entries: dn: cn=changelog,cn=ldbm database,cn=plugins,cn=config dn: cn=config, cn=ldbm database, cn=plugins, cn=config dn: cn=userRoot,cn=ldbm database,cn=plugins,cn=config It helped a lot, but not enough. Hello Tamas, You get some sigsegv and you may hit a real bug. Please try to capture a core (http://www.port389.org/docs/389ds/FAQ/faq.html#debugging-crashes) then you may attach a pstack of it. thanks thierry I had seen this before years ago, when I started using ipa. It was on Fedora and the bleeding edge Freeipa version. At that time I switched to CentOS because I trusted more in the well tested enterprise distribution. But now it's not an option:) Any suggestion? Thanks, tamas -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project
[Freeipa-users] Antwort: clean-run doesn't work
freeipa-users-boun...@redhat.com schrieb am 19.06.2015 11:02:48: Von: Tamas Papp tom...@martos.bme.hu An: freeipa-users@redhat.com Datum: 19.06.2015 11:04 Betreff: [Freeipa-users] clean-run doesn't work Gesendet von: freeipa-users-boun...@redhat.com hi All, $ ipa-replica-manage list-ruv unable to decode: {replica 6} 55832e8e00030006 55832e8e00030006 ipa31.bph.cxn:389: 8 ipa12.bpo.cxn:389: 5 ipa32.bph.cxn:389: 7 ipa11.bpo.cxn:389: 3 ipa.cxn.com:389: 4 $ ipa-replica-manage clean-ruv 6 unable to decode: {replica 6} 55832e8e00030006 55832e8e00030006 Replica ID 6 not found Background: yesterday I deployed this ldap cluster and migrated users to. Everything worked fine, except one time I had to recreate the replication, because the process didn't finish successfully (due to a closed firewall port). After the command 'ipa-server-install --uninstall' it worked like a charm. But now I see the above on the replica master. in addition, I can see numerous and various errors on other replicas, eg: [19/Jun/2015:10:53:43 +0200] attrlist_replace - attr_replace (nsslapd-referral, ldap://ipa.cxn.com:389/o%3Dipaca) failed. There is in the mailing list archives, that the solution is running clean-run. Thanks, tamas for this problem you can see the thread Haunted servers? here on ml. There is a solution from me for this but it doesnt work 100% :/ we have a Ticket @Red Hat for this problem, ( https://access.redhat.com/support/cases/#/case/01429034 if you have rh support) But is really sad/silly how RH support works (read the whole ticket). Greetz -- Manage your subscription for the Freeipa-users mailing list: https://www.redhat.com/mailman/listinfo/freeipa-users Go to http://freeipa.org for more info on the project